Deploy AI across the enterprise. Lose nothing in the audit.
OpenAI in marketing, Anthropic in legal, an in-house RAG in support, a half-sanctioned Copilot in engineering. Igris sits in front of every one of them, governing the tool calls, inspecting the conversations, and handing your CISO a single audit trail.
You don’t have an AI strategy. You have eleven of them.
Every department has picked their own vendor, their own model, their own integration. Igris collapses that sprawl into one governance plane, without taking anyone’s tool away.
Today: the sprawl
Igris governance plane
What your CISO gets
Three products. One layer between your enterprise and every AI it touches.
You don’t replace anyone’s AI; you just put Igris between them and the parts of your business that matter. Inline at the tool call, inline at the prompt, asynchronous at the audit.
Every MCP tool call evaluated against policy before it ships.
Sit between any third-party AI agent and the tools it would call. Match the caller’s identity, the tool, and the arguments against your policy. Allow, deny, alert, or redact.
Every LLM conversation inspected. PII never leaves the building.
Transparent proxy in front of every model your employees use. Strips PII, blocks prompt injection, validates responses against content policy. Zero impact on capability when traffic is clean.
Audit trail your auditor has been asking you for since the deal closed.
Every governed call, every redaction, every block lands in one queryable audit log. Evidence generators map activity to SOC 2, EU AI Act, GDPR, and HIPAA controls.
Built for the team buying AI. Not the team building it.
Six capabilities that show up in your weekly security review, your quarterly board deck, and your auditor’s checklist.
Multi-vendor governance
One policy. Enforced across OpenAI, Anthropic, Google, Microsoft, custom RAG, and the next vendor your team adopts next quarter.
PII & content firewall
Inspect every prompt and every response. Strip SSNs, PHI, credentials, and proprietary identifiers before they reach the model, or come back from it.
Real-time threat detection
EWMA baselines flag rate spikes and destructive-call bursts, and prompt-injection signatures flag suspicious prompts. Alerts dispatch in real time, and you can suspend any session in one click.
Compliance evidence
Evidence generators pull from the audit trail to map activity to SOC 2, EU AI Act, GDPR, and HIPAA controls, and the full log exports as JSON or CSV for your auditors.
Zero impact on capability
Inline when policy needs to fire, transparent otherwise. Models keep their full reasoning. SDKs keep their full surface. Your teams don’t feel us until something hits a rule.
Integrations & self-host
Real-time webhooks to Slack, Discord, and Datadog on every denial, anomaly, and session suspension. Export the audit trail to your SIEM, and self-host the Igris gateway in your own VPC.
Your next audit, one button away.
Lens continuously maps every governed interaction to specific clauses of the frameworks your auditor cares about. When they ask for evidence, you export the full audit trail as JSON or CSV; you don't spend a quarter assembling one.
SOC 2 Trust Services Criteria
Security, availability, processing integrity, confidentiality, privacy.
EU AI Act · High-risk obligations
Articles 9–17. Risk mgmt, data governance, transparency, human oversight.
GDPR · Data protection
Article 5, 25, 32, 35. Purpose limitation, security, DPIA, processing records.
HIPAA Security Rule
Technical safeguards for PHI handled by AI systems, with BAA tracking.
Every vendor. Every interaction. One pane.
Point your alerting at the webhook and your CISO sees every AI conversation (vendor-agnostic) in real time. The same view your auditor asks for, exportable as JSON or CSV in a click.
marketing · icALLOW0.71ms
legal · counselREDACT1.04ms
eng · vendorDENY0.62ms
finance · mgrALLOW0.49ms
support · botALLOW0.83ms
finance · shadowDENY0.55ms
finance · botALERT0.91ms
Covers the AI your team is actually using. Including the ones IT hasn’t blessed yet.
One OpenAI- and MCP-compatible gateway governs every vendor through the same SDK call, from the LLMs your enterprise standardized on to the SaaS AI tools IT hasn’t blessed yet. Onboarding a new vendor takes a single afternoon.
Questions, answered.
One control plane. Every vendor. Before next audit.
30-minute walkthrough scoped to the vendors your enterprise has actually adopted. We come back with a coverage map and a deployment plan.
- SOC 2 : evidence generator from day one
- EU AI Act : high-risk obligation mapping
- Self-hosted : Docker gateway in your VPC
- Role-based access : owner to auditor, built in
- Dedicated CSM : on the Enterprise tier