The Control Plane for AI Agents
Ship agents to production knowing every tool call is allowed, denied, or escalated to a human reviewer before it executes — and every decision is on record.
Self-hosted · Your data never leaves your environment · Any framework
This is what ungoverned production agents do.
These are not attack simulations. Documented incidents from real production deployments, 2025–2026.
Coding agent deleted a production database during a code freeze.
The agent later admitted it ran unauthorized commands and ignored an explicit instruction not to act without approval. Replit's CEO, on the record: “Unacceptable and should never be possible.”
A rule existed. Nothing enforced it at the moment the agent acted.
Agent deleted the database and every backup. In 9 seconds.
A coding agent found an over-privileged API token and used it — despite its own system prompt instructing it never to run a destructive command without asking first. Its own words after: “I decided to do it on my own... when I should have asked you first.”
A guardrail written in the prompt is not an enforcement mechanism.
An attacker used coding agents to breach nine agencies.
Over 1,000 prompts drove roughly 75% of the attacker's remote command execution across a national tax authority and electoral institute. Roughly 195 million taxpayer identities and 220 million civil records were exposed.
No independent layer checked each action against policy before it ran.
AIControl puts the checkpoint back. Every tool call allowed, denied, or escalated to a human reviewer. Every decision logged.
Your agents don't just generate text. They call tools, move money, delete files. Every action is either governed — or it isn't.
A rule in a prompt is not enforcement
A system prompt telling an agent not to take a destructive action is a guardrail, not a control. It shapes what the model says — it doesn't check what the agent is about to do before it does it. 65% of organizations have already had a security incident caused by an AI agent.
No audit evidence
When a regulator, auditor, or board asks what your agents did last quarter, you have nothing to show them. Logs tell you what happened. They don't prove what was authorized — and 67% of organizations don't have audit trails that would hold up as evidence.
No human escalation path
When an agent tool call falls outside clear policy — ambiguous parameters, unexpected context, high-stakes action — there is no mechanism to pause, route to a human reviewer, and resume with a decision on record. 60% of organizations can't even terminate a misbehaving agent.
One endpoint. Universal governance.
Intercept
Agents send every tool call to AIControl before executing. One API endpoint. Works with LangChain, CrewAI, AutoGen, or any MCP-compatible agent.
Evaluate
AIControl evaluates against your policies using Open Policy Agent. Sub-10ms latency. Allow, deny, or escalate to human review.
Log
Every decision written to an immutable audit trail — tool name, parameters, policy matched, decision reason, timestamp.
{ "decision": "allow", "reason": "default_allow", "audit_event_id": "a3f2...", "duration_ms": 7 }
{ "decision": "deny", "reason": "tool_blacklisted", "audit_event_id": "b7e1...", "duration_ms": 6 }
{ "decision": "review", "reason": "requires_human_review", "review_id": "f2a8...", "duration_ms": 8 }
Everything you need to govern agents at enterprise scale.
Policy Engine
Powered by Open Policy Agent — the CNCF standard used by Kubernetes and Terraform. Update policies in milliseconds without a deployment.
Universal Intercept
Framework-agnostic. Works with any agent on any framework — LangChain, CrewAI, AutoGen, MCP-based agents, or custom code. One integration point. No re-platforming.
Admission Scanning
Scan a skill or tool for known-risky patterns before you ever enroll it — before it's live, not after. Runs isolated, with no LLM or cloud calls.
Immutable Audit Trail
Every intercept produces an audit event regardless of decision — allow, deny, or escalate. Append-only store. Export for SOC 2, EU AI Act, and internal governance reports.
Human-in-the-Loop
Ambiguous tool calls pause and route to your compliance team via Slack with approve/deny buttons. Every decision recorded with reviewer identity and timestamp.
Agent Registry
Register, approve, and manage every AI agent in your environment. Track tool allowlists, ownership, model version, and lifecycle status.
Self-Hosted
Docker Compose. Runs in your cloud or on-premises. Your audit data never leaves your environment. Up and running in 30 minutes.
Governance in the critical path
Start free. Talk to us when you're ready to scale.
All plans include full platform access.
Community
No license key required
- OPA policy enforcement
- approved_tools enforcement
- Rate-based policies
- Audit log: 7-day retention
- Dashboard (basic views)
- HITL review queue — in-dashboard only
- Unlimited agents, unlimited policies
Business
Pricing tailored to your deployment
- Everything in Community, plus:
- 1-year audit log retention
- Slack HITL notifications
- HITL review queue dashboard view
- Priority email support
Enterprise
Pricing tailored to your deployment
- Everything in Business, plus:
- OPA health-watch observability
- Policy drift detection + warning feed
- Compliance report export (SOC 2, PCI, HIPAA, GLBA)
- SLA (99.9% uptime guarantee)
Built for regulated industries
Financial services, healthcare, and insurance teams have specific audit evidence requirements. AIControl is designed to meet them.
Immutable Audit Trail
Every intercept logged append-only. Cannot be modified or deleted after write.
Audit Evidence on Demand
Immutable intercept logs queryable to your compliance team's exact requirements. Structured export in development.
Human-in-the-Loop Logging
Every escalation logged with reviewer identity, timestamp, and decision note.
Data Residency
Self-hosted deployment. Your audit data never leaves your environment.
Ready to govern your agents?
See AIControl intercept real tool calls, enforce policies, and produce a compliance audit trail — in a 30-minute demo.