AI agent governance

Agents query tokenized data. Every call is proven.

DataShield is the governance layer for AI agents in regulated environments: PII/PHI tokenized at ingest, authorization enforced on every governed tool call with mid-session revocation, and tamper-evident audit evidence — from an independent vendor that isn't owned by your firewall company.

Anatomy of a governed tool call An AI agent's tool call passes through the Auth dispatch pipeline — token scope ceiling, authority tier, mid-session revocation re-check, metered dispatch — reaches a dataset tokenized at ingest, and every stage is sealed into a hash-chained audit log with Ed25519-signed checkpoints. YOUR IDP — ENTRA / OKTA ("who it is") AI Agent (any MCP client) AUTH DISPATCH PIPELINE MCP token scope ceiling ≤ ceiling? Authority tier Revocation re-check every call, mid-session Metered dispatch agent_id=agt_7f21 Tool handler Ontology MCP server Dataset tokenized at ingest name → TOK_a3f9… deterministic · join-preserving Vault detokenize = privileged op tokenized answer EVIDENCE LANE Ed25519 checkpoint verify_chain → VALID signed checkpoints — deletion detectable

Three mechanisms, one evidence plane

Tokenize: PII tokenization at ingest

Datasets are tokenized at ingest — deterministic, join-preserving, vault-reversible. Agents query tokenized data over MCP; analytics and joins still work. Detokenization is a privileged, audited operation. Erasure is crypto-shred — and the audit chain survives it.

Authorize: per-tool-call agent authorization

Every governed tool call passes a real dispatch pipeline: token scope ceiling, declared authority tier, mid-session revocation re-check, metered dispatch. Break-glass emergency access auto-revokes and can't be quietly deleted from the log.

Prove: a tamper-evident audit trail

A SHA-256 hash chain with Ed25519-signed checkpoints. Verification distinguishes tampering, insertion, deletion, and truncation — run it yourself. Designed to map to EU AI Act Art. 12/26 and HIPAA §164.312(b).

What happens without MCP security

Real incidents, one root cause: nothing sat between agent and data. Asana — a tenant-isolation bug exposed cross-customer data for 34 days. GitHub MCP — prompt injection exfiltrated private repositories. Supabase MCP — SQL exfiltration through a support ticket. The NSA published an MCP security advisory.

Three questions to ask any agent-security vendor

Including us. Each answer below names the mechanism — and you can check it.

Can you cryptographically prove your logs weren't altered?

Ours is a SHA-256 hash chain with Ed25519-signed checkpoints that are themselves chained, so checkpoint deletion is detectable. Verification distinguishes tampering, insertion, deletion, and truncation. Verify a sample chain yourself — no signup.

What happens to a revoked agent mid-session?

Authority is re-checked on every governed tool call. Revoke or suspend an agent and its next call is downgraded — not its next login, not its token expiry. The Asana exposure ran 34 days; here it would have been one call. See the dispatch pipeline.

How does GDPR erasure interact with your audit trail?

Erasure is crypto-shred: the subject's key is destroyed, raw re-identification becomes impossible, and the audit chain still verifies — actor identities are HMAC-committed, so evidence integrity survives erasure. Consent receipts follow ISO 27560.

The independent AI agent security layer

Lakera → Check Point. Portkey → Palo Alto. Prompt Security → SentinelOne. CalypsoAI → F5. The independent governance layer is disappearing into platform vendors.

DataShield runs alongside your Entra or Okta identity, your LiteLLM or Kong gateway, and your detection layer. We're the evidence and data-governance layer they all assume someone else provides — and we're not for sale to your firewall vendor.

Agent identity is solved upstream. Authorization evidence is ours.

Bring your IdP. Entra or Okta tells you who the agent is — DataShield proves what it did was allowed.

Video by Microsoft Mechanics. DataShield federates to your IdP over SAML/OIDC and adds the authorization and evidence layers.

The stack

Auth

Authorization and evidence for AI agents: scope-ceiling MCP tool tokens, break-glass, hash-chained audit. v1.1.8, in production. Explore Auth

Ontology

The governed data plane: PII/PHI classification, tokenization at ingest, k-anonymity, DataShield Analytical DB via MCP. v0.24.1, in production. Explore Ontology

Guardian

The daemon that keeps the evidence plane alive: phased boot, health gates, restart circuit breakers. v0.9.4, in production since April 2026. Explore Guardian

Lighthouse

Signed, verifiable fleet state: heartbeats, DELS-signed licensing, controlled patch distribution. v0.8.2, in production. Explore Lighthouse

Corpus — the agent MCP server for documentation, agents & skills — is shipped. Read about it.

Built for regulated deployments

Get a scoped quote in minutes — from an agent governed by the stack it's quoting.

Get an instant quote

You've seen the proof

Ready for a number? Scope your deployment and we'll price it against your own economics.

Get your quote →