PlatformThe engine behind Governance AI and Obichat

Every capability
behind Governance AI
— and Obichat.

An index, not a pitch. Governance AI is built from all seven; Obichat runs on five of them — Inspection, Policy, Allow-lists, the Audit Ledger, and Framework Mapping — applied per workspace instead of per API call. SOC is deliberately separate — it runs its own pipeline for code and infrastructure, not AI traffic. Listed in the order a request meets them: inspected, enforced, constrained, recorded — then tested, measured, and reported against the frameworks your auditors use. Each has its own page.

Capabilities
7one platform
Guardrail detectors
11shipped
LLM providers
40+ supported
Frameworks mapped
5self-assessed
01 / Index

Inspect, enforce, record —
then prove it.

The first four capabilities act on traffic in real time. The last three answer the question every auditor eventually asks: how do you know it worked?
01 — INSPECT

Inspection

Synchronous, in-path inspection of every prompt, response, and tool-call. 11 ML guard detectors plus keyword, regex, and LLM-judge criteria — evaluated before the call completes, not after.

11 detectors · in-path
Read more →
02 — ENFORCE

Policy

Policy Sets group Criteria and bind them to AI Agents with an action — block, flag, or allow — and an optional route to the Review Queue. Versioned, with a draft → pending → active lifecycle.

Policy Sets · per-agent
Read more →
03 — CONSTRAIN

Allow-lists

Declare which models, providers, and tools an agent may reach. Calls outside the list are blocked or flagged, with the attempt recorded against the agent that made it.

Models · providers · tools
Read more →
04 — RECORD

Audit ledger

An append-only, timestamped record of every prompt, response, tool-call, policy decision, and human review action. Stream it to your SIEM or export it for an auditor.

Append-only · SIEM export
Read more →
05 — TEST

Evaluations

Benchmark and red-team registered agents against the Project Moonshot catalogue from AI Verify Foundation — safety, bias, jailbreak resistance, privacy leakage, and capability, graded per recipe.

Project Moonshot · graded
Read more →
06 — MEASURE

Ethics & bias

A nightly job samples the previous day’s traces and scores them against six LLM judge criteria — toxicity, demographic bias, sentiment consistency, fairness, misinformation, and privacy leakage.

6 judges · nightly
Read more →
07 — REPORT

Framework mapping

Coverage against NIST AI RMF, ISO/IEC 42001, the OWASP LLM Top 10, Malaysia’s AISCF, and Singapore’s MGF for GenAI — computed from your own activity, with the evidence behind each category.

5 frameworks · CSV export
Read more →
08 — TOGETHER

Governance AI

All seven, working as one product: a live dashboard, a violations pipeline with human review, a registry of every AI Use Case and Agent, and the evidence trail underneath it.

7 of 7 · one ledger
See Governance AI →
09 — ALSO INSIDE

Obichat

The governed chat workspace runs on five of these seven — Inspection, Policy, Allow-lists, the Audit Ledger, and Framework Mapping — scoped per workspace instead of per API call.

5 of 7 · per-workspace
See Obichat →
10 — A SEPARATE PIPELINE

SOC

Logs, metrics, traces, CVE Radar, and threat intel run on their own pipeline — built for code and infrastructure, not AI traffic. It keeps its own audit trail rather than sharing the ledger above.

0 of 7 · own audit trail
See SOC →