AI agent governance
Agents query tokenized data. Every call is proven.
DataShield is the governance layer for AI agents in regulated work. PII and PHI are tokenized at ingest. Every governed tool call is checked, and you can revoke an agent mid-session. Each call leaves tamper-evident audit evidence. We are an independent vendor. Your firewall company does not own us. That is the whole pitch.
- Breached through an AI app? 97% of those firms had no proper AI access controls — IBM Cost of a Data Breach Report 2025
- A lot of shadow AI adds $670K to the cost of a breach, next to low use or none — IBM Cost of a Data Breach Report 2025
- EU regulators name pseudonymization as a way to cut GDPR risk — EDPB Opinion 28/2024
- EU AI Act Art. 12 asks for lifetime event logs. Commission fining powers began Aug 2, 2026 — EU AI Act
Three mechanisms, one evidence plane
Tokenize: PII tokenization at ingest
Data is tokenized at ingest. A value maps to the same token every time, so your joins hold. The vault can turn the token back. Agents query tokenized data over MCP. Your joins and charts still work. To detokenize you need the right, and the act is logged. Erasure is crypto-shred. The audit chain lives through it.
Authorize: per-tool-call agent authorization
Every governed tool call runs a real dispatch pipeline: token scope ceiling, declared authority tier, mid-session revocation re-check, metered dispatch. That is per-call authorization. Not a check at login. Break-glass emergency access auto-revokes. No one can quietly drop it from the log.
Prove: a tamper-evident audit trail
A SHA-256 hash chain, with Ed25519-signed checkpoints. The check tells tampering, insertion, deletion and truncation apart. So you learn what was done, not just that something was. Run it yourself. It maps by design to EU AI Act Art. 12/26 and HIPAA §164.312(b).
What happens without MCP security
Real cases, one root cause: nothing sat between the agent and the data. Asana: a tenant-isolation bug exposed cross-customer data for 34 days. GitHub MCP: prompt injection pulled out private repositories. Supabase MCP: SQL exfiltration through a support ticket. The NSA put out an MCP security advisory. None of it needed a clever attacker.
None of these had per-call authorization or tamper-evident logs between agent and data. Gartner's Market Guide for Guardian Agents (2026) expects at least 80% of unauthorized agent transactions through 2028 to be internal policy violations or misguided AI behavior, not malicious attacks. Governance is the control.
Three questions to ask any agent-security vendor
Ask us too. Each answer below names the part that does the work, and you can go check it.
Can you cryptographically prove your logs weren't altered?
Ours is a SHA-256 hash chain. The Ed25519-signed checkpoints are chained too, so a dropped checkpoint shows up. The check tells tampering, insertion, deletion and truncation apart. You do not have to take our word for it. Verify a sample chain yourself. No signup.
What happens to a revoked agent mid-session?
Authority is re-checked on every governed tool call. Revoke or suspend an agent and its very next call is cut down. Not its next login. Not its token expiry. The Asana exposure ran 34 days. Here it would have been one call. See the dispatch pipeline.
How does GDPR erasure interact with your audit trail?
Erasure is crypto-shred. We destroy the subject's key, so no one can work back to the raw person. The audit chain still verifies. That is because actor identities are HMAC-committed. Your evidence lives through erasure. Consent receipts follow ISO 27560.
The independent AI agent security layer
Lakera went to Check Point. Portkey went to Palo Alto. Prompt Security went to SentinelOne. CalypsoAI went to F5. The independent governance layer is vanishing into platform vendors.
DataShield runs next to your Entra or Okta identity, your LiteLLM or Kong gateway, and your detection layer. We are the evidence and data-governance layer they all assume someone else brings. And we are not for sale to your firewall vendor.
Agent identity is solved upstream. Authorization evidence is ours.
Bring your own IdP. Entra or Okta says who the agent is. DataShield proves that what it did was allowed.
Video by Microsoft Mechanics. DataShield federates to your IdP over SAML/OIDC, then adds the authorization and evidence layers.
The stack
Auth
Authorization and evidence for AI agents. It brings scope-ceiling MCP tool tokens, break-glass, and a hash-chained audit. v2.4.1, in production. Explore Auth
Ontology
The governed data plane. It is where PII/PHI classification, tokenization at ingest and quasi-identifier generalization live. Agents reach the DataShield Analytical DB over MCP. v2.2.0, in production. Explore Ontology
Commander
The cockpit for coding agents. Run many Claude Code sessions per project, with personas that boot from governed prompts. Ship up a dev-to-test-to-prod promotion ladder, with an audited override. v3.0.15, in production. Explore Commander
Corpus
Docs, agent definitions and skills, served to agents over MCP. Vendor, customer and copy catalogs stack in layers, with drift detection. Every request is metered and hash-chained. v1.3.2, in production. Explore Corpus
Corpus has shipped. It is the agent MCP server for docs, agents and skills. Read about it.
Built for regulated deployments
- Self-hosted or dedicated single-tenant: your own kit, your own keys (KMS/HSM)
- BAA conversation welcome: health care is why the data plane exists
- Design-partner program: with a source-escrow option
- Honest limitations: we post them on the architecture page, so you do not find them during your trial
Get a scoped quote in minutes, from an agent governed by the stack it is quoting.
Get an instant quoteYou've seen the proof
Ready for a number? Scope your deployment and we'll price it against your own economics.
Get your quote →