AI agent governance
Agents query tokenized data. Every call is proven.
DataShield is the governance layer for AI agents in regulated environments: PII/PHI tokenized at ingest, authorization enforced on every governed tool call with mid-session revocation, and tamper-evident audit evidence — from an independent vendor that isn't owned by your firewall company.
- 97% of organizations breached through AI apps lacked AI access controls — IBM 2025
- Shadow AI adds $670K to the average breach — IBM Cost of a Data Breach 2025
- EU regulators name pseudonymization as a GDPR mitigation — EDPB Opinion 28/2024
- EU AI Act Art. 12: lifetime event logging. Commission fining powers began Aug 2, 2026 — EU AI Act
Three mechanisms, one evidence plane
Tokenize: PII tokenization at ingest
Datasets are tokenized at ingest — deterministic, join-preserving, vault-reversible. Agents query tokenized data over MCP; analytics and joins still work. Detokenization is a privileged, audited operation. Erasure is crypto-shred — and the audit chain survives it.
Authorize: per-tool-call agent authorization
Every governed tool call passes a real dispatch pipeline: token scope ceiling, declared authority tier, mid-session revocation re-check, metered dispatch. Break-glass emergency access auto-revokes and can't be quietly deleted from the log.
Prove: a tamper-evident audit trail
A SHA-256 hash chain with Ed25519-signed checkpoints. Verification distinguishes tampering, insertion, deletion, and truncation — run it yourself. Designed to map to EU AI Act Art. 12/26 and HIPAA §164.312(b).
What happens without MCP security
Real incidents, one root cause: nothing sat between agent and data. Asana — a tenant-isolation bug exposed cross-customer data for 34 days. GitHub MCP — prompt injection exfiltrated private repositories. Supabase MCP — SQL exfiltration through a support ticket. The NSA published an MCP security advisory.
None of these systems had per-call authorization or tamper-evident logs between agent and data. Gartner expects at least 80% of unauthorized agent transactions through 2028 to be internal policy violations, not attacks. Governance is the control.
Three questions to ask any agent-security vendor
Including us. Each answer below names the mechanism — and you can check it.
Can you cryptographically prove your logs weren't altered?
Ours is a SHA-256 hash chain with Ed25519-signed checkpoints that are themselves chained, so checkpoint deletion is detectable. Verification distinguishes tampering, insertion, deletion, and truncation. Verify a sample chain yourself — no signup.
What happens to a revoked agent mid-session?
Authority is re-checked on every governed tool call. Revoke or suspend an agent and its next call is downgraded — not its next login, not its token expiry. The Asana exposure ran 34 days; here it would have been one call. See the dispatch pipeline.
How does GDPR erasure interact with your audit trail?
Erasure is crypto-shred: the subject's key is destroyed, raw re-identification becomes impossible, and the audit chain still verifies — actor identities are HMAC-committed, so evidence integrity survives erasure. Consent receipts follow ISO 27560.
The independent AI agent security layer
Lakera → Check Point. Portkey → Palo Alto. Prompt Security → SentinelOne. CalypsoAI → F5. The independent governance layer is disappearing into platform vendors.
DataShield runs alongside your Entra or Okta identity, your LiteLLM or Kong gateway, and your detection layer. We're the evidence and data-governance layer they all assume someone else provides — and we're not for sale to your firewall vendor.
Agent identity is solved upstream. Authorization evidence is ours.
Bring your IdP. Entra or Okta tells you who the agent is — DataShield proves what it did was allowed.
Video by Microsoft Mechanics. DataShield federates to your IdP over SAML/OIDC and adds the authorization and evidence layers.
The stack
Auth
Authorization and evidence for AI agents: scope-ceiling MCP tool tokens, break-glass, hash-chained audit. v1.1.8, in production. Explore Auth
Ontology
The governed data plane: PII/PHI classification, tokenization at ingest, k-anonymity, DataShield Analytical DB via MCP. v0.24.1, in production. Explore Ontology
Guardian
The daemon that keeps the evidence plane alive: phased boot, health gates, restart circuit breakers. v0.9.4, in production since April 2026. Explore Guardian
Lighthouse
Signed, verifiable fleet state: heartbeats, DELS-signed licensing, controlled patch distribution. v0.8.2, in production. Explore Lighthouse
Corpus — the agent MCP server for documentation, agents & skills — is shipped. Read about it.
Built for regulated deployments
- Self-hosted or VPC — your infrastructure, your keys (KMS/HSM)
- BAA conversation welcome — healthcare deployments are why the data plane exists
- Design-partner program — with a source-escrow option
- Honest limitations — published on the architecture page, not discovered in your evaluation
Get a scoped quote in minutes — from an agent governed by the stack it's quoting.
Get an instant quoteYou've seen the proof
Ready for a number? Scope your deployment and we'll price it against your own economics.
Get your quote →