The model-agnostic agent control plane

Give your agents the authority to act.

ArtzAIn checks every agent action against policy before it runs, signs it into a tamper-evident ledger, and keeps it answerable to any auditor later, so your CFO, CISO, and General Counsel can finally say yes to agents that touch money, customers, and contracts.

Free & entry-level tiers, self-serve · Customized VPC pilots · SOC 2 roadmap

Specialist agent crew Cryptographic provenance Policy-grade governance Sub-second decisioning

The real reason AI agents are stuck

Your agents demo well. They never ship.

It's not the model. It's the missing trust infrastructure.

Across Fortune 1000s, agents pass proof-of-concept and stall at the trust boundary. Compliance, security, and finance won't let them touch money, customers, or contractual obligations without three things they've never had: an enforceable policy layer, a verifiable audit trail, and context grounded in the company's actual data and rules.

Without those, autonomy is a liability. With them, autonomy compounds.

  • Models can decide. They can't be governed.
  • RAG can retrieve. It can't enforce policy.
  • Logs can record. They can't be cryptographically trusted.
“Permission is the unlock. Speed, cost, revenue, and scale all follow.” Jean de Rubens, Co-Founder, CEO / CTO

What we built

Four checks between intent and action.

Skip one and the agent is a liability. Run all four and it can be trusted with money, customers, and contracts.

01 · Policy

Whose rules apply

Your financial controls, regulatory obligations, contractual commitments, and internal SOPs compiled into versioned, enforceable bundles.

02 · Context

What the agent knows

Context assembled from your systems of record at decision time (CRM, contracts, policy docs, service logs), with a redaction boundary at ingestion.

03 · Decision

allow, deny, or review

Specialist agents vote inline. Sub-second resolution, with escalation to a human wherever your risk tolerance demands it.

04 · Receipt

Proof, not logs

Every decision sealed into a hash-chained, Ed25519-signed leaf: the policy applied, the context retrieved, the action taken. Auditor-ready.

How it works

From intent to action, governed every step.

One governed path: your agent asks, the control plane checks, and the action runs with a receipt.

AI agent
intent
ArtzAIn control plane
184ms median, end-to-end · pre-flight
policy
context
decision
receipt
Governed action
allow
The control plane sits between the agent's intent and the action it takes. Every request flows through policy, context, decision, and receipt: checked before it runs, not audited after the damage.
intent
arrives from the agent: any vendor, any framework.
policy
check resolves whose rules apply and what's allowed.
context
retrieval grounds the decision in your real data.
decision
resolves to allow, deny, or review, with an escalation path.
receipt
is signed and hash-chained into the ledger, tamper-evident.
action
executes inside your perimeter, against your systems.

The platform

ArtzAIn: the model-agnostic agent control plane

The control plane sits on your data and policies and governs the action, never the model, so it sits in front of any vendor, any framework, any in-house agent. The context engine is the substrate inside it: multi-tower retrieval, specialist agents, and receipts on every path. Its own inference is self-hosted inside your perimeter (a Gemma-family model stack chosen on measured evidence), and the control plane calls no hosted LLM APIs: zero vendor egress.

Policy & permissions

Your real policies (financial controls, regulatory frameworks, contractual obligations, internal SOPs) compiled into machine-enforceable bundles like eu-ai-act@v3. Agents check before they act, every time. Version-controlled, attributable, reviewable.

Context engine

The substrate underneath every decision. A multi-tower architecture organizes your CRM, contracts, policy docs, service logs, and communications into semantic domains agents can reason across. Agentic retrieval keeps context current.

Decisioning

Median end-to-end resolution in 184ms, with confidence scoring and human-escalation paths. Agents don't produce opinions. They produce a verdict backed by policy, context, and a confidence interval your team calibrates.

Provenance & receipts

Every decision generates a cryptographic receipt: sha256:9f2a…, hash-chained and Ed25519-signed. Tamper-evident. Auditor-ready. Court-defensible.

Specialist agent crew

Purpose-built identities for security, legal, compliance, privacy, fraud, and context: each holding a narrow capability contract, each in the registry, all governed by the same control plane.

Continuous learning

Every confirmed decision, override, and outcome compounds the context engine. Your governance gets sharper the more your agents act.

Works with your stack

Governs the agents you already run, wherever they run.

ArtzAIn governs the action, never the model. So it meets your teams where they already build: in their code, in the orchestrators running your agents today, in the business apps those agents touch, and on the infrastructure you choose.

2SDKs, 2 APIs

SDKs & APIs

Build it in

Put a governed decision inside your agent loop in an afternoon. Free to install, and the same API carries you to production in your VPC.

  • Python artzain
  • TypeScript @cognexuslabs/artzain
  • Decision API
  • Governance envelope

12discovery sources

Orchestrators

Govern what already runs

The Agent Catalog finds the agents already working across your estate, including the ones nobody registered, and brings them under one control plane.

  • Claude & Claude Code
  • Microsoft Foundry
  • Copilot Studio
  • M365 Copilot
  • Entra Agent ID
  • Salesforce Agentforce
  • LangGraph
  • n8n
  • OpenClaw
  • MCP servers
  • Kubernetes
  • CI/CD pipelines

23connectors live

Business connectors

Context from your systems

Your agents decide with the facts your business runs on. Tokens are encrypted at rest, refreshed for you, and shareable at the team level.

  • Salesforce
  • HubSpot
  • Dynamics 365
  • ServiceNow
  • Workday
  • Slack
  • Microsoft Teams
  • Gmail
  • Outlook
  • Google Drive
  • GitHub
  • DocuSign
  • +11 more

4ways to deploy

Environments

Runs inside your perimeter

Start on our managed control plane, then move to production in your own boundary. In your VPC, the signing keys and the ledger stay on your hosts.

  • Managed control plane
  • Your VPC
  • On-prem
  • Air-gapped
  • Docker Compose
  • Kubernetes (Helm)
  • Terraform on AWS
  • NVIDIA OpenShell New

New Runtime integration · NVIDIA OpenShell

OpenShell fences the sandbox. ArtzAIn decides what the fence may change.

Before an OpenShell gateway commits a policy change, it asks ArtzAIn first. Your signed ArtzAIn policy bundle stays the source of governance, and OpenShell stays the enforcer inside the sandbox. You can run OpenClaw agents inside an OpenShell sandbox, governed end to end.

  • Fail-closed. No decision, no change. Every approved change is sealed to your ledger before it commits.
  • Secrets out of reach. Your agents never see the ArtzAIn key. OpenShell injects it only on the way to ArtzAIn.
  • Sovereign-ready. Runs inside the same boundary as an air-gapped gateway, with telemetry off.
  1. Proposed OpenShell gateway A sandbox policy change is requested
  2. Decided ArtzAIn Checked against your signed bundle allowreviewdeny
  3. Committed or held Your sandbox allow commits. Anything else, including no answer, leaves the sandbox unchanged.

openshell v0.1.2 · artzain 0.6.32 · governs sandbox create, policy update, draft approval, provider attach

Coverage

A specialist for every kind of risk.

The ArtzAIn crew: each identity holds a narrow capability contract, and every one of them is in the registry.

Security
security-sentinel · code_bastion
Compliance
compliance-warden
Legal
legal-watch
Privacy
privacy-guardian
Financial
fraud-sentry
Context
context-keeper · context-steward
Governance
governance-marshal · registry-scout "Agent Wrangler"
Your own
register any agent via the SDK

Use cases

Agents that act, governed end to end.

These aren't dashboards. These are agents executing within your policies, leaving a receipt for every action.

B2B commerce

Agent-mediated B2B commerce

Autonomous agents transacting on behalf of buyers and sellers, governed end to end by the control plane: catalog terms, credit limits, and contractual commitments all checked before the order is placed.

Output: Live transactions with full policy attribution, context provenance, and a cryptographic receipt per action.
Renewal & expansion

Autonomous renewal & expansion

Agents read the contract, the usage data, the engagement signals, and the renewal calendar, and execute renewal motions inside sales policy. The CRO gets pipeline coverage. The CFO gets margin discipline. The GC gets a receipt for every commitment.

Output: Renewal motions executed within sales policy, with per-action receipts and CRM-grade attribution.
Procurement

Procurement & vendor decisioning

Agents evaluate vendor proposals against your SLAs, security policies, and budget envelopes, then make or recommend procurement decisions inside guardrails. The CFO sets spend caps. The CISO sets the security floor. Agents move at machine speed inside the perimeter.

Output: Vendor decisions with policy-traceable rationale, ready for procurement and audit.
Customer operations

Compliance-bounded customer operations

Service agents resolve tickets, issue credits, and escalate disputes: all bounded by policy, all sealed with provenance. Customers get speed. Auditors get the record.

Output: Resolved cases with policy-attributed actions and a tamper-evident audit trail per case.

Governance

Built for the people who sign off.

Your CFO, your CISO, and your General Counsel each get the controls they have been asking for.

For the CFO

  • Spend caps and approval thresholds enforced at the policy layer
  • P&L attribution per agent action
  • Cost visibility across the agent fleet
  • Override and escalation paths your finance team controls

Your agents have a budget and a boss.

For the CISO

  • VPC deployment: data never leaves your perimeter
  • Self-hosted models: no hosted LLM APIs, zero vendor egress
  • Identity, secrets, and access controls integrated with your IdP
  • Cryptographic provenance on every decision
  • SOC 2 roadmap; encryption in transit and at rest

Your agents operate inside the perimeter you already trust.

For the General Counsel

  • Policy-to-rule mapping with version control
  • Tamper-evident audit log per action
  • Regulatory traceability: EU AI Act, SOX, GDPR, and HIPAA bundles
  • Court-defensible receipts on every decision

Your agents leave a trail your regulators accept.

Why now

The trust window is open. It will not stay open.

Three shifts are converging, and every one of them rewards moving early.

  1. 01Agents can finally act. Frontier model capability crossed the threshold for autonomous action in regulated workflows in the last 18 months. The model isn't the bottleneck anymore.
  2. 02Regulators are watching. The EU AI Act, US state-level frameworks, and SOX-adjacent guidance are converging on a single demand: provable governance over automated decisions.
  3. 03First movers compound. Every governed decision sharpens the context engine. Late entrants don't retrofit trust. They earn it from zero, with their first auditor already in the room.

For developers & consultants

Build on the control plane.

Everything you need to integrate ArtzAIn lives in the developer hub: the SDK surface and key capabilities, AWS insertion points, the downloadable reference, and an interactive architecture where you trace a real request through the stack to an allow, deny, or review verdict. A kill-switch event is a distinct object (trip_global() → AgentKilledError), not a fourth verdict.

PyPI Trusted Publisher (OIDC) · npm provenance attestation · Apache-2.0 source

Self-serve

Explore ArtzAIn today.

Create an account, register an agent, and watch the control plane issue its first governed decisions. There's a free tier to start on and entry-level plans you can subscribe to in-app. No sales call required.

Free tier Entry-level plans Subscribe in-app Upgrade any time

Need your VPC, your policies, and a team accountable for the rules? Request a customized pilot below.

Customized enterprise pilots

Bring us the workflow Legal keeps blocking.

When self-serve isn't enough: one workflow, your data, your policies, inside your VPC, stood up in four weeks with the team accountable for the rules.

Request a pilot

6 answers · one business day to a reply1 min

All six fields are required.

Which workflow is blocked?

No newsletter. No sequence. A human replies.

Request logged.

A human replies within one business day with two call times.

·queued for scoping
Deployment
Your VPC, your keys
Certification
SOC 2 roadmap
Policy
eu-ai-act@v3
Receipts
Ed25519, hash-chained

01 · scoping call, day 002 · policy bundle, week 103 · live in your VPC, week 4