NewAIUC-1, the insurance-grade standard for AI agents, is here — now audited by Schellman. We map to it.
Runtime governance for what AI agents do

Govern every AI agent —
anywhere it runs.

Traditional GenAI firewalls only filter model outputs. Aigentical intercepts the tool calls, API integrations, and system actions in the execution path — and blocks the unauthorized ones before they run.

11
provisional patents filed
22
governance layers
4
enforcement tiers
256-bit
HITL nonce
Any
cloud · on-prem · air-gapped
governance · decision record live
09:42:07svc-billing-worker · issue_refund $38Allowrefund-per-action-cap · within limit
09:42:09svc-terraform-executor · delete_resources prod-04Holdpolicy-infra-prod-boundary · awaiting HITL token
09:42:11svc-doc-retriever · read_objects design-specsDenydlp-mosaic-session-limit · >45 read ops/session
09:42:12svc-billing-worker · wire_payment $50,000Holdpayment-approval-threshold · agent can't forge the token
every decision written to a tamper-evident chain · nothing here can be quietly edited
We map to the frameworks your program answers to
EU AI Act · Art. 12 & 14AIUC-1SOC 2 · CC6 / CC7 ISO 42001NIST AI RMFMITRE ATLAS HIPAA §164.312PCI-DSS Req. 10GDPR Art. 30 & 32
See it run

Two minutes, end to end — the enforcement, the approval, the record.

Deny-by-default stopping an ungoverned tool call, a destructive action held for cryptographic human approval, and the tamper-evident record that maps to the EU AI Act, NIST AI RMF, and AIUC-1 — the standard insurers underwrite AI agents against.

The shift

Agentic workflows execute code, query databases, and call APIs — with active system credentials.

Unlike a chatbot, an agent doesn't just answer questions; it takes actions against your systems — refunds, deletes, production changes, one agent delegating to another. Aigentical decouples the policy decision from the agent runtime: a zero-trust architecture for the non-human identities already running across your environment, enforced at every call.

CyberArk · 2025
80:1
outnumbered

Non-human identities already outnumber humans (CyberArk, 2025). AI agents are the fastest-growing class, and the only one that takes actions.

public incidents
9s
to delete a production database

A startup watched an agent delete its production database in nine seconds. An attacker planted system-wiping commands in Amazon's own coding agent. Amazon shipped them in a public release. This isn't hypothetical anymore.

every platform
Everywhere
and increasingly third-party

They run on Copilot Studio, LangChain, CrewAI, Bedrock, and Vertex, across every cloud — and as agent marketplaces emerge, you'll increasingly run agents you didn't write.

today's tooling
0
shared control planes

Every platform ships its own half-answer to "governance." Approvals, allowlists, and audit splinter across tools, and no one can say what any single agent actually did.

EU AI Act · AIUC-1
Required
regulation + insurance

The EU AI Act requires logging and human oversight. AIUC-1 — the AI-agent insurance standard, now with its first accredited auditor — is what insurers grade you on. Both come down to one thing: govern the action, keep the record.

One control plane across every agent, platform, and cloud: govern what they do, prove every call, and produce the evidence your auditors and insurers ask for.
Aigentical provides that control plane. Enforcement and evidence in the path of the action, not reconstructed after the fact.
What you get

Continuous evidence that your agent controls are working.

Enforcement is the mechanism; these are the outcomes it produces — the ones your security, compliance, and finance teams each need to see.

Compliant by design

The evidence writes itself

Proof for SOC 2, the EU AI Act, and ISO 42001 accrues as your agents run. No screenshots, no scramble the week before an audit.

Audit-ready, every day

One record, in plain language

Every action lands in one place your board and your auditors can actually read, not a pile of gateway logs to reconcile.

Insurable

Kept true between audits

AI-agent insurers grade you on controls like these. We hold that grade every day, not just on the morning of the review.

Aigentical isn't software you watch run. It's the layer that lets you prove your AI did only what it was allowed to do.

Discovery

See every AI call, including the ones nobody set up.

Most teams can name maybe half the AI running inside them. Aigentical finds the rest before a single policy runs, surfacing every agent and AI call on your network or under your provider accounts, including the shadow AI nobody set up.

Six sources · one reconciled inventory · nothing to pre-register
01 · live trafficThe calls agents make. Agents and tools materialize from real traffic as they run, no manual registration.
02 · provider usageDirect-to-provider calls. Usage pulled straight from your OpenAI and Anthropic accounts, even when it skips the proxy.
03 · network egressAI endpoints in your flow logs. Cloud egress that reaches an AI provider, read from AWS, GCP, and Azure flow logs.
04 · identity providerNon-human identities. Service accounts and app registrations enumerated from Entra and Okta.
05 · source codeAI in your repos. Agent frameworks and LLM SDKs found in a scan of your GitHub org.
06 · dependenciesAI in your supply chain. AI libraries buried in requirements, pyproject, and package.json, surfaced from the SBOM.

Six angles, one reconciled inventory. Start in monitor mode and watch first, then turn governance on per agent, per tool, per risk tier. Total visibility, selective enforcement.

How it works

Content security stops at the prompt. We govern what happens next.

Chat-era tools were built for text in, text out. The real risk now lives in what an agent does after the model speaks: the tool calls, the deletes, the refunds, the handoffs. That is the layer Aigentical runs on.

Chat-era security

Reads what the model writes

  • Built for text in, text out.
  • A GenAI gateway with in-context content classifiers.
  • Catches jailbreaks, PII leaks, and toxic output.
  • But it never reaches the tool calls, deletes, refunds, and handoffs. The things an agent actually does.
Agentic-era governance

Governs what the agent does

  • Sees tool calls, MCP, agent-to-agent delegation, and blast radius.
  • Freezes the high-risk ones for a human, with an approval that can't be forged.
  • Stops delete-prod, refund fraud, RAG poisoning, and slow-drip exfiltration.
  • A new layer that complements the guardrails you already run.
Three verdicts, enforced in the execution path
Allow

Automated execution

Low-risk actions run in-path. Policy evaluation adds microseconds.

Hold

Cryptographic gate

Sensitive actions freeze until authorized by a signed, single-use human token, verified server-side.

Record

Immutable audit

Every action is logged with a cryptographic receipt in a tamper-evident chain.

In one frame — the agent flows through the proxy, the rules live out of band
agent relationship map live
every call calls uses reads writes delegates to verdict · allow / hold / deny every decision recorded AGENT non-human identity LangChain · CrewAI · Cursor PROXY · PEP thin · in-path · enforces POLICY · PDP out of band LLMs tools MCP data RAG · DB systems APIs · infra peer A2A ◆ THE RECORD tamper-evident chain
every decision written to the tamper-evident chain · allow / hold / deny, with the reason
the PDP holds your policies · per-agent boundaries · reputation · approval secrets — out of band, beyond the agent's reach
How the Zero Trust split works
The evaluation engine — the Policy Decision Point — evaluates every request against this control plane, out of band. The thin proxy — the Policy Enforcement Point — applies only the returned verdict in the execution path. The agent can't reach, alter, or bypass the policy engine — a Zero Trust split, by design.
Twenty-two governance layers in five stages · 19 on the LLM proxy · 18 on MCP · 17 on the SDK — then the proxy enforces the verdict
the pipeline · one call, five gates live
  1. Stage 1 · 5 layersIdentity & context
  2. Stage 2 · 2 layersInput & injection shielding
  3. Stage 3 · 5 layersPolicy & authorizationdeny → stopped here · still recorded
  4. Stage 4 · 5 layersBlast radius & boundaries
  5. Stage 5 · 5 layersData, DLP & the record
Stage 1Claim-pinned identity · agent discovery from traffic · approved-system gate · env-scope · data residency
Stage 2Jailbreak and prompt-injection scanning, de-obfuscated first · per-call keyword floor on MCP and the SDK
Stage 3CEL policy engine · deny-by-default tool allowlist · just-in-time grants · verified A2A delegation · per-agent reputation floor
Stage 4Per-agent prohibited actions · runaway-loop breaker · budget ceilings · session-trajectory drift · outbound egress control
Stage 5Sensitivity ceiling · PII & credential output shield · RAG / vector-DB firewall · retrieved-document scan · tamper-evident audit
a call that clears every gate runs · a deny stops it at the gate, and the decision is still written to the record

An attacker has to beat every layer that runs on the surface they are on.

Which layers run where
Twenty-two layers, grouped into five stages so the path stays fast. Not all twenty-two run on every surface: nineteen on the LLM proxy, eighteen on MCP, seventeen on the SDK, six on retrieval. Above them sits the primitive that makes a verdict stick — cryptographic human approval the agent cannot forge.
One pipeline, every surface an agent touches · 4 enforcement tiers
T1 · network
Proxy
Point a base_url. Every LLM and MCP call routes through it.
T2 · library
SDK
@govern gates functions in-process. Python and TypeScript.
T3 · protocol
MCP Intercept
Tool calls governed inside the protocol, with the nonce gate.
T4 · runtime
Wasm Sandbox ROADMAP
Capability-scoped runtime. Denies any ungranted call.

Six insertion surfaces, one stateful pipeline: SDK · decorator · proxy · MCP · K8s admission webhook · sidecar. Add a surface, not a rewrite.

The obvious question: can't an agent just go around the proxy?
route around it
Enforcement follows the agent. The proxy is one insertion surface, not the control. The SDK gates functions in-process, MCP Intercept governs inside the tool protocol, and the K8s webhook governs at admission. The same pipeline runs at every one.
skip the check
High-risk actions fail closed. Gated execution stays blocked until a single-use token verifies server-side. An agent that avoided governance has no token to present. Nothing runs by default.
stay hidden
Off-path calls still surface. Provider usage, egress flow logs, identity providers, repos, and the SBOM reconcile the calls that never touched the proxy — into the same inventory, flagged until they're brought under policy.
tamper with policy
The decision engine is out of reach. Policy evaluates out of band on the decision point; the enforcement point applies only cryptographically signed, expiring verdicts. The agent can't reach the engine, forge a verdict, or replay an old one.
And you can make the proxy the only road.
Allow provider egress only from the proxy's subnet, so a direct call fails at the network layer — and surfaces in flow-log discovery when it's tried. Pin the proxy's base_url in your SDK config and fail the build in CI when a repo points anywhere else; the source-code scan shows you exactly where to look. Product enforcement composed with your network and CI controls. Defense in depth, not a single hop.
A new discipline

Bridging identity governance and runtime tool execution.

Firewalls, IAM, and DLP were built for people and packets. None of them hold a non-human identity's reputation, weigh the weakest link in a chain of delegations, or issue an approval a fast, automated process can't forge. These are the primitives that do. The evolutionary step between IAM and what agents actually do at runtime.

01unforgeable approval
A human "yes" that can't be fakedThe agent has no material to compute the approval, and the secret never leaves the server. Single-use, time-boxed, consumed on first verify.
02behavioral trust
Reputation that decaysTrust isn't granted once at the door. It rises and falls with behavior, and a sinking score gates the agent's very next call.
03delegation
Trust flows to the weakest linkIn a chain of agents handing work to each other, effective trust equals the lowest link, so privilege can't launder through a hop.
04runtime identity
Identity pinned to its environmentThe environment is baked into the credential. A dev token can't act in prod, even if every header claims otherwise.
05cumulative risk
Session risk that adds upA slow-drip exfiltration no single request would trip is caught by scoring the whole session, not one call at a time.
06the record
A log that can't be quietly rewrittenEvery action is HMAC-chained and keyed in your own KMS. Alter one entry and the next verify-on-read gives it away.
The flagship · cryptographic human-in-the-loop

Human authorization as a cryptographic primitive.

Standard human-in-the-loop workflows are decoupled from execution, leaving them open to state manipulation. Aigentical treats human authorization as a strict cryptographic primitive: high-risk tool execution is physically blocked until a single-use, time-bound authorization token is verified server-side. The agent has no material to forge it.

  • Can't forge. The agent has no material to compute the approval. The secret never leaves the server.
  • Can't reuse. Single-use, 60-second TTL, consumed on first verify.
  • Can't wait it out. The approval window and the execution window are independent.
  • Attributable. Every approval lands in the tamper-evident chain.
# agent requests a sensitive action
wire_payment(amount=50000)
 
# policy → require approval
decision: REQUIRE_APPROVAL
 
# frozen — waiting on a human
status: PENDING_APPROVAL
→ human clicks Approve
 
# released as a single-use, time-boxed
# token the agent has no way to forge
execution_token: issued ✓
 
# approval is bound to the authenticated (OIDC/SSO) operator
# no signing material is ever exposed to the agent environment

Eleven of these are patent-pending. The controls agent governance needs that IAM, DLP, and network firewalls were never built to provide.

Non-human identity

Your IAM lets the agent in the door. We govern everything it does after.

Authentication is the front door. The risk is the action. Aigentical consumes the identity signal you already issue and makes it enforceable at every single call.

We consume

Your identity stack, unchanged

No rip-and-replace. We sit on top of the IAM you already run and make it enforceable at every agent action.

  • SPIFFE / SPIRE · mTLS · OIDC & SAML SSO (Okta, Entra, Keycloak)
  • SCIM provisioning · bring-your-own key custody (your KEK or HashiCorp Vault)
  • Additive to Okta / CyberArk / SailPoint, not a replacement
We add

Runtime authorization

  • Every call gets a verdict and a reason.
  • Least agency: the intersection of blast-radius, allowlist, and live reputation.
  • Delegation inherits the lowest trust in the chain, so privilege can't launder.
We pin

Claim-pinned identity

  • A strongest-signal-wins resolver chain settles who the agent is.
  • Tokens are environment-pinned, so a dev token can't act in prod.
  • Header-only and anonymous identity are rejected. Every action needs a cryptographic credential.

The IAM model you know, enforced at every agent action

Human IAM authenticates once at the door. We compute the agent's effective permission per action, layered on top of the identity you already issue.

Human IAM · the door
Agent-native governance · every action
Identity · login
AgentIdentity — resolver chain (mTLS → SPIFFE → agt_ token → header), canonicalized into one record
Role / group membership
AgentProfile — a resource-constrained execution profile: allowlist ∩ blast-radius ∩ reputation floor ∩ sensitivity ceiling
Entitlements / permissions
EffectiveEntitlements — evaluated per action (ABAC) from caller identity, tool target, and session attributes → Allow / Approve / Deny, with a reason
no human analog
Reputation — behavioral trust that decays on misbehavior and gates the next call
no human analog
A2A delegation — effective trust = min(chain); privilege can't launder through hops
Consumes SPIFFE SVIDs, env-pinned agt_ tokens, and SAML / OIDC operator identity. We don't replace IAM, we make the agent's identity enforceable at every action.
Where we fit

The centralized Policy Decision Point.

You already run guardrails, and probably a gateway or two. We don't replace them. We're the single Policy Decision Point (PDP) they all report into, so nothing you've bought goes to waste, and nothing about governance fragments across them.

Bring your own guardrails

Detectors feed in

  • NeMo, Lakera, provider refusals, your own classifiers.
  • They all report to one endpoint, trust-weighted.
  • Their detection compounds inside one decision point.

We catch directly

  • We catch tool calls, MCP, A2A, and blast radius ourselves.
  • Cryptographic HITL gates the high-risk actions.
  • The things content guardrails were never built for.

The closed loop

  • A tamper-evident audit entry and a reputation drop.
  • Mosaic session risk rises and the pattern is captured.
  • A real-time SOC alert fires across every detector.

Self-hardening: every catch, yours or a detector's, feeds reputation, mosaic, and pattern capture, so the system gets harder to attack the longer it runs. Inside your tenant, never shared.

Many gateways, one decision plane
Gatewayrouting · streaming
Gatewayfailover · cost caps
Gatewayedge · virtual keys
MCP / directtool calls
pre/post hook · plugin · webhook · MCP intercept
Aigentical · the decision plane
one agent-identity model · one policy set · one HITL flow · one tamper-evident audit chain, across every gateway you run
one decision plane · every gateway reports in
Gateway Gateway Gateway MCP / direct identity policy HITL audit chain AIGENTICAL decision plane
one agent-identity model · one policy set · one HITL flow · one tamper-evident audit chain
Identity fragments
Each gateway knows its own keys. None resolves the actual agent behind the call.
Policy drifts
Allowlists and approval rules get re-implemented per gateway and silently diverge.
Audit splits
Three gateways means three partial logs. No single record of what an agent did.
HITL forks
Approval flows differ per gateway, or simply don't exist on some of them.

Works alongside LiteLLM · Kong · Bifrost · Portkey · Gravitee, or whatever you run. The textbook pattern: many enforcement points, one decision point (NIST 800-207).

Every action an agent takes is recorded before it runs — allowed, held, or denied, with the reason.
the audit trail is built in, not bolted on
How you run it

Discover. Register. Govern. Audit. Prove.

One operating loop, from the first scan to audit-ready evidence your board can read.

01
Discover

Surface every agent and AI call from real traffic.

02
Register

Connect tool sources; bind policies to the tools that matter.

03
Govern

Enforce in-path: allow, approve, or deny, every action.

04
Audit

Every decision lands in a tamper-evident chain, streamed to your SIEM.

05
Prove

Map the evidence to SOC 2, EU AI Act, TRiSM, AEGIS, AIUC-1, and more.

↻ one continuous loop
The proof

Built for the frameworks your program already answers to.

AI-agent assurance is now a standard, not a slide. AIUC-1 — the insurance-grade standard for AI agents from AIUC, developed with Anthropic and MITRE and now audited by Schellman — sets the bar for governing what agents do. Aigentical maps to it.

Below, the obligations your program is measured against, each paired with the specific Aigentical control that satisfies it: the runtime-governance model analysts describe (Gartner AI TRiSM, Forrester AEGIS), stated as controls, not positioning.

SOC 2 · EU AI Act

Enforce in the moment

detect & respond

The control auditors look for is enforcement as the action happens — allow, hold, or deny in the execution path — not a review after the fact.

Every call gets a verdict, in-path.
EU AI Act Art. 12 · SOC 2 CC7

Produce the record on demand

record-keeping

Every decision — allowed, held, denied — is written to an HMAC-chained, tamper-evident log and streamed to your SIEM.

Immutable, attributable, exportable.
EU AI Act Art. 14 · AIUC-1

Human oversight, enforced

oversight & containment

Cryptographic human-in-the-loop on high-risk actions, per-agent blast radius, and least-privilege allowlists. The controls behind AI-agent insurability.

Enforced continuously, not just at audit.
Mapped to the standards your auditors already know
SOC 2CC6 / CC7
EU AI ActArt. 12 & 14
NISTAI RMF
ISO42001
HIPAA§164.312
PCI-DSSReq. 10
GDPRArt. 30 & 32
MITREATLAS

TRiSM, AEGIS, and AIUC-1 are frameworks and standards of their respective owners. Mappings shown are Aigentical's own and do not imply review, endorsement, or certification by Gartner, Forrester, or AIUC.

From the founder

I built Aigentical after watching teams wire AI agents into production with real credentials and no way to say no at the moment an action fires. Every “governance” answer I found reviewed things after the fact, or trusted the agent to behave. So we built the part that decides in-line — and keeps a record you can hand to an auditor. If you're putting agents anywhere near systems that matter, I'd genuinely like to hear what you're up against.

— SANGEET RAJAN · FOUNDER, AIGENTICAL

Get started

Start in monitor mode, on your own traffic.

Map your agent inventory, point the proxy at staging with no code changes, and watch governance run on your own traffic before you commit to anything. We deploy it with you and hand you the evidence, not a login and a wiki.