Runtime governance & proof
Decide what your AI is allowed to do. Prove it.
Policies, sovereignty, budgets and defensible proof for every AI call — one runtime layer, zero rewrites.
- Designed for the EU AI Act
- Hash-chained journal
- EU residency
- France 2030 · candidate
- Data policy — no forbidden categories
- Sovereignty — EU destination confirmed
- Connector — admin-approved
- Weekly budget — team cap reached
a1f4c09e7b2d8f60Every decision — granted or refused — is traced, sealed, defensible.
The problem
Your agents act. Nothing stops them, nothing proves it.
Observability tells you what your AI did — after the fact. A regulator, a CFO or a customer asks something else: what it was allowed to do, and proof the rule held.
Your agents spend before asking
Budgets get observed at month-end. They don't apply at call time.
The AI Act demands evidence, not logs
A log can be edited. Evidence can be defended. Your current tools produce logs.
Sovereignty is promised, not enforced
Nothing technically stops an EU agent from calling a US endpoint.
Nobody can say what was refused
The history of what was blocked — and why — lives nowhere. It's exactly what the auditor asks for.
The four questions
When an agent makes a bad call, can you answer these four questions?
Not after a month of forensics — right now, from a single sealed record.
Which model made the decision?
The selected model is sealed into the decision trace.
On what data?
The data policy applied is recorded on every call.
At what cost?
Real cost and the budget check, captured before the spend.
Under what authorization?
Sovereignty, connector and cap — validated, or the call is refused.
How it works
One line to change. Three acts.
OpenAI-compatible. Your SDKs, your frameworks, your code — unchanged.
- client = OpenAI(base_url="https://api.openai.com/v1")
+ client = OpenAI(base_url="https://gateway.azothos.ai/v1")Point your existing client at the gateway. That's all.
policy: "support-bot-guardrails"
rules:
- budget: 250 € / week / team # blocks, doesn't alert
- residency: eu-only # refuses outside EU
- data: deny(pii.health)Declare the rule once. It applies to every request, before spend.
$ curl gateway.azothos.ai/v1/journal/export?period=Q2Export the signed evidence. Verifiable by anyone — no need to take our word.
The architecture
A gateway routes. Azoth filters.
Between your applications and the providers, every call is evaluated. What passes is optimized. What doesn't is refused — with proof.
- Policy engine
- Sovereignty
- Budgets that block at the cap
- Sealed journal
- Exportable proof
request refused → signed evidence · nothing sent, nothing spent
Positioning
What Azoth OS is — and isn't.
Azoth OS is
- an orchestration layer for your models and agents
- a governance and policy-enforcement layer
- an observability, traceability and optimization tool
- production infrastructure, not a demo
Azoth OS is not
- a new AI model
- a chatbot
- a dashboard bolted on after deployment
- an abstract compliance promise
Five minutes, zero refactor