Business teams wait for an approval path that cannot express ownership, purpose, data, and acceptable models together.
Enterprise AI governance + runtime control
Let the business use AI. Keep control of what happened.
Fogcutter discovers the AI systems in play, ties activity to accountable identity, applies deterministic policy at the right boundary, and proves every outcome from one evidence chain—without exporting sensitive content by default.

1,284reconciled decisions
18AI applications
9models observed
0content bodies retained
Deterministic enterprise-v5 synthetic tenant—not customer evidence or a production benchmark.
01 / The business problem
AI governance breaks when every control knows a different version of reality.
Security sees destinations. AI Platform sees model calls. Identity sees accounts. Governance sees spreadsheets. Audit sees screenshots. When the organization asks which control actually operated, the answer becomes a reconciliation project.
Discovery, gateway, application, and identity systems count different objects across different clocks and denominators.
A block alert cannot show the exact policy, evidence, forwarding outcome, blind spots, and experience cost behind it.
The complete operating loop
From unknown AI use to governed AI operations.
Fogcutter is not another isolated dashboard or guardrail API. It is the semantic and operational layer that connects inventory, identity, policy, runtime outcomes, and evidence.
Build a living map of enterprise AI.
Bring applications, browser destinations, providers, models, agents, tools, and instrumented workloads into one versioned inventory.
Coverage boundaries and blind spots remain part of the result.Connect activity to accountable identity.
Resolve people, workloads, agents, owners, and human sponsors against authoritative evidence without pretending ambiguous identities are known.
Facts, inference, confidence, and freshness stay distinct.Turn inventory into operating decisions.
Record sanctioned, tolerated, review-required, restricted, and blocked dispositions. Test policy changes against deterministic fixture libraries.
High-impact changes support independent approval and signed provenance.Apply policy at the boundary that matters.
Evaluate explainable policy for OpenAI-compatible and Anthropic traffic, progressing from observation and simulation to routing and production blocking.
Control timing is measured separately from provider latency.Open every conclusion into its evidence.
Trace a metric or decision through policy inputs, bundle version, provider binding, forwarding attempts, completion, timing, provenance, and exclusions.
Blocked-before-forward is proven by the absence of a forwarding lifecycle.One operating contract · every AI surface
Govern the workforce, the application, and the agent without creating three versions of truth.
Employees using sanctioned and unsanctioned AI.
Discover browser and application destinations, connect activity to authoritative identity, record governance disposition, and keep unobserved paths visible.
Developer-built products and internal workflows.
Normalize application audit and provider traffic, govern models and routes, separate control time from provider time, and reconcile the full request lifecycle.
Autonomous work with accountable ownership.
Inventory agents, MCP servers, and tools; resolve workload and human sponsors; then evaluate intended authorization at the tool boundary with durable evidence.
The operating record behind every decision.
Connect inventory disposition, policy analysis, independent approval, rollout state, runtime outcomes, coverage, and exportable evidence in one contract.
Policy lifecycle · intended operating model
Production enforcement is the destination—not the starting point.
Fogcutter is designed to move a route from evidence-only observation into controlled production action after its identity, coverage, performance, recovery, and false-positive gates are proven.
- 01ObserveEstablish coverage and baseline outcomes
- 02SimulateReplay deterministic and historical evidence
- 03ApproveReview exact policy and fixture provenance
- 04ShadowCompare candidate and active decisions
- 05CanaryEnforce for a bounded cohort and budget
- 06EnforceBlock or route production traffic
- 07Roll backReturn to last-known-good policy
Intended runtime actionsAllowWarnRequire approvalRedactRouteBlockQuarantine
One evidence contract across the product
Move from fleet-level posture to the exact decision.
Operations, Inventory, Governance, Applications, Identity, Coverage, and Policy Operations use shared nouns, versioned definitions, explicit freshness, and drill-down into the same underlying evidence.


Architecture is part of the product
Control stays close to traffic. Evidence stays inspectable.
The customer or regional data plane can continue operating from signed policy while evidence exports asynchronously into a tenant-isolated control plane. Control-plane availability does not become an AI-traffic dependency.
Independently operable data plane
The runtime control path uses signed, last-known-good policy and durable local evidence. AI traffic does not depend on a SaaS dashboard being reachable.
Deterministic core
Identity, policy precedence, authorization, lifecycle reconciliation, and audit remain explainable. Probabilistic classifiers contribute bounded evidence rather than hidden authority.
Metadata-first boundary
Content collection is not the default business model. Classification can happen locally while exported evidence preserves only the metadata required to operate and prove control.
Enterprise-shaped isolation
OIDC and role authorization, tenant-bound PostgreSQL row-level security, mTLS transport, digest-pinned workloads, and customer-controlled credentials are designed into the system.
Deployment architecture · product direction
Put the control boundary where your organization requires it.
The same policy, identity, and evidence contracts are designed to support a fully managed service, a deeply segregated customer deployment, or a hybrid boundary. Deployment should be an enterprise control—not a reason to accept less governance.
Fogcutter hosted
Managed operation with regional isolation.
Fogcutter operates the control and evidence planes, regional runtime services, upgrades, and recovery while the customer defines policy, identity, data, and integration boundaries.
- Fastest path to evaluation and operation
- Region-aware processing and tenant isolation
- Managed availability, upgrades, and observability
- Customer policy, retention, and content choices
Customer AWS
Fogcutter inside the customer's AWS boundary.
Deploy the platform into a dedicated customer account and VPC for maximum segregation, private connectivity, customer-controlled keys, and direct governance of every operational access path.
- Customer-selected AWS region and network topology
- Customer-controlled KMS keys and credentials
- Private ingress, provider egress, and log destinations
- Explicit support access, upgrade windows, and removal
Hybrid
Keep the runtime local; manage policy centrally.
Run inline controls, local classification, and durable traffic evidence inside the customer boundary while a managed control plane coordinates policy and receives minimized operational metadata.
- Customer-local data plane and content boundary
- Signed policy distribution and last-known-good operation
- Metadata-minimized evidence export
- Central inventory, governance, and fleet operations
Deployment models describe Fogcutter's intended product architecture and are qualified with each evaluation.
Built like infrastructure, not a dashboard demo
Maturity is an exercised behavior.
The product is unusually deep for its stage because the evidence model, failure modes, deployment boundaries, policy lifecycle, and operator contracts were built before broad feature claims.
Exactly 900 completed, 180 blocked before forwarding, 90 failed, 50 cancelled, and 64 unresolved in enterprise-v5.
Four providers, nine models, six agents, 14 tools, and application-, provider-, browser-, and workload-native evidence.
Thirty-nine of 42 synthetic identities resolved, with ambiguous and unresolved states kept visible.
Separate active and candidate fixtures, independent approvals, a 5% canary, and an intentional rollback latch.
Durable pre-forward audit, idempotent export, last-known-good policy, explicit health states, bounded backpressure, and recovery evidence.
Private AWS/EKS and PostgreSQL paths, multi-replica behavior, tenant-bound row-level security, mTLS, OIDC/RBAC, and digest-pinned workloads.
Static analysis, deterministic fixtures, independent approval, signed bundles, shadow comparison, canary selection, and rollback control.
Exact lifecycle reconciliation, bounded query and pool behavior, load qualification, control/provider timing separation, and content-free operational metrics.
Capability-level comparison
Broad security suites protect AI. Fogcutter makes AI control provable.
WitnessAI, Prisma AIRS, and Netskope publish stronger native catalogs for content protection, attack defense, and red teaming. Fogcutter's bet is different: the hardest enterprise problem is proving that inventory, identity, policy, rollout, runtime action, and evidence describe the same event.
Evidence quality, explainable policy, safe change, lifecycle proof, and customer-owned operating boundaries.
Large discovery catalogs, DLP, prompt and response inspection, threat defense, model scanning, and red teaming.
Design-partner evaluation
Start with one route. Prove the full loop.
The current offer combines mutual discovery, the populated synthetic enterprise environment, controlled live-traffic evidence, and a customer-specific architecture and data review. The initial evaluation stops before production blocking; the intended product path advances a qualified route into controlled enforcement and rollback.
Discover
Choose one AI route, its sponsor, and the control decision the organization cannot prove today.
Demonstrate
Walk the full synthetic enterprise tenant, then run controlled traffic through the real decision and evidence path.
Design
Define customer-owned architecture, privacy boundaries, success evidence, stop conditions, recovery, and removal.
Common questions
Answers for security and AI platform teams.
What is shadow AI discovery?
Shadow AI is AI use that never passed through an approval path — browser tools, embedded features, and agents adopted directly by teams. Fogcutter discovers browser and application destinations, connects that activity to authoritative identity, records governance disposition, and keeps unobserved paths visible rather than dropping them silently from the count.
Does Fogcutter block AI traffic, or only observe it?
Both, in that order. Evaluations start in observe-and-shadow mode, comparing candidate decisions against active ones without affecting live traffic at all. Enforcement is the destination, reached through signed policy bundles, independent approval, a bounded canary, and a rollback latch — not the starting configuration.
How does Fogcutter prove a request was not forwarded?
By the durable absence of a forwarding lifecycle, not by an alert label. A blocked decision records pre-forward intent with no forwarding attempt and no provider response against it. That absence is retained as evidence and can be traced through policy inputs, bundle version, provider binding, timing, and provenance.
Does Fogcutter retain prompts or responses?
No. Evidence is content-free by default — prompt bodies, response bodies, headers, and credentials are not retained. What persists is the decision record: which policy operated, which bundle version, the forwarding outcome, timing, and provenance. That is what makes the evidence chain safe to inspect and circulate internally.
How is Fogcutter different from Netskope, Prisma AIRS, and WitnessAI?
Those platforms document broad AI discovery and runtime protection across large security estates. Fogcutter's difference is provability: policy compiled with effective order and conflicts proven before activation, change carrying signed provenance from fixture through rollback, and blocking established as a lifecycle fact rather than inferred from an alert.
Does Fogcutter support EU AI Act record-keeping?
Fogcutter is not a compliance certification, and no claim of EU AI Act conformity is made here. What it produces is the record-keeping substrate such regimes ask for: signed policy provenance, approval binding, retained per-decision evidence, and reconciled outcomes — held content-free, so records can be kept without retaining regulated data.
For security, AI platform, and governance leaders
Bring one AI route you need to trust.
We'll map the systems and identities involved, name the evidence gap, and show what a governed operating loop would need to prove.
Plan a technical evaluation