AI agent governance

Agents query tokenized data. Every call is proven.

DataShield is the governance layer for AI agents in regulated work. PII and PHI are tokenized at ingest. Every governed tool call is checked, and you can revoke an agent mid-session. Each call leaves tamper-evident audit evidence. We are an independent vendor. Your firewall company does not own us. That is the whole pitch.

Anatomy of a governed tool call An AI agent's tool call passes through the Auth dispatch pipeline — token scope ceiling, authority tier, mid-session revocation re-check, metered dispatch — reaches a dataset tokenized at ingest, and every stage is sealed into a hash-chained audit log with Ed25519-signed checkpoints. YOUR IDP — ENTRA / OKTA ("who it is") AI Agent (any MCP client) AUTH DISPATCH PIPELINE MCP token scope ceiling ≤ ceiling? Authority tier Revocation re-check every call, mid-session Metered dispatch agent_id=agt_7f21 Tool handler Ontology MCP server Dataset tokenized at ingest name → TOK_a3f9… deterministic · join-preserving Vault detokenize = privileged op tokenized answer EVIDENCE LANE Ed25519 checkpoint verify_chain → VALID signed checkpoints — deletion detectable
HIPAA§164.312(b) aligned
EU AI ActArt. 12 / 26 mapped
GDPRArt. 17 crypto-shred
SOC 2Type II planned
ISO 27001on the roadmap
Customer-held keysKMS / HSM

Three mechanisms, one evidence plane

Tokenize: PII tokenization at ingest

Data is tokenized at ingest. A value maps to the same token every time, so your joins hold. The vault can turn the token back. Agents query tokenized data over MCP. Your joins and charts still work. To detokenize you need the right, and the act is logged. Erasure is crypto-shred. The audit chain lives through it.

Authorize: per-tool-call agent authorization

Every governed tool call runs a real dispatch pipeline: token scope ceiling, declared authority tier, mid-session revocation re-check, metered dispatch. That is per-call authorization. Not a check at login. Break-glass emergency access auto-revokes. No one can quietly drop it from the log.

Prove: a tamper-evident audit trail

A SHA-256 hash chain, with Ed25519-signed checkpoints. The check tells tampering, insertion, deletion and truncation apart. So you learn what was done, not just that something was. Run it yourself. It maps by design to EU AI Act Art. 12/26 and HIPAA §164.312(b).

What happens without MCP security

Real cases, one root cause: nothing sat between the agent and the data. Asana: a tenant-isolation bug exposed cross-customer data for 34 days. GitHub MCP: prompt injection pulled out private repositories. Supabase MCP: SQL exfiltration through a support ticket. The NSA put out an MCP security advisory. None of it needed a clever attacker.

Three questions to ask any agent-security vendor

Ask us too. Each answer below names the part that does the work, and you can go check it.

Can you cryptographically prove your logs weren't altered?

Ours is a SHA-256 hash chain. The Ed25519-signed checkpoints are chained too, so a dropped checkpoint shows up. The check tells tampering, insertion, deletion and truncation apart. You do not have to take our word for it. Verify a sample chain yourself. No signup.

What happens to a revoked agent mid-session?

Authority is re-checked on every governed tool call. Revoke or suspend an agent and its very next call is cut down. Not its next login. Not its token expiry. The Asana exposure ran 34 days. Here it would have been one call. See the dispatch pipeline.

How does GDPR erasure interact with your audit trail?

Erasure is crypto-shred. We destroy the subject's key, so no one can work back to the raw person. The audit chain still verifies. That is because actor identities are HMAC-committed. Your evidence lives through erasure. Consent receipts follow ISO 27560.

The independent AI agent security layer

Lakera went to Check Point. Portkey went to Palo Alto. Prompt Security went to SentinelOne. CalypsoAI went to F5. The independent governance layer is vanishing into platform vendors.

DataShield runs next to your Entra or Okta identity, your LiteLLM or Kong gateway, and your detection layer. We are the evidence and data-governance layer they all assume someone else brings. And we are not for sale to your firewall vendor.

The independent AI agent security layer is consolidating into platform vendors The independent AI-agent security layer is being acquired into platform vendors: Lakera into Check Point, Portkey into Palo Alto, Prompt Security into SentinelOne, and CalypsoAI into F5. DataShield is the evidence and data-governance layer they all assume someone else provides, and it is not for sale to your firewall vendor. THE INDEPENDENT LAYER IS DISAPPEARING Lakera Check Point Portkey Palo Alto Prompt Security SentinelOne CalypsoAI F5 DataShield: the evidence and data- governance layer. Not for sale to your firewall vendor.

Agent identity is solved upstream. Authorization evidence is ours.

Bring your own IdP. Entra or Okta says who the agent is. DataShield proves that what it did was allowed.

Video by Microsoft Mechanics. DataShield federates to your IdP over SAML/OIDC, then adds the authorization and evidence layers.

The stack

Auth

Authorization and evidence for AI agents. It brings scope-ceiling MCP tool tokens, break-glass, and a hash-chained audit. v2.4.1, in production. Explore Auth

Ontology

The governed data plane. It is where PII/PHI classification, tokenization at ingest and quasi-identifier generalization live. Agents reach the DataShield Analytical DB over MCP. v2.2.0, in production. Explore Ontology

Commander

The cockpit for coding agents. Run many Claude Code sessions per project, with personas that boot from governed prompts. Ship up a dev-to-test-to-prod promotion ladder, with an audited override. v3.0.15, in production. Explore Commander

Corpus

Docs, agent definitions and skills, served to agents over MCP. Vendor, customer and copy catalogs stack in layers, with drift detection. Every request is metered and hash-chained. v1.3.2, in production. Explore Corpus

Corpus has shipped. It is the agent MCP server for docs, agents and skills. Read about it.

Built for regulated deployments

Get a scoped quote in minutes, from an agent governed by the stack it is quoting.

Get an instant quote

You've seen the proof

Ready for a number? Scope your deployment and we'll price it against your own economics.

Get your quote →