AI’s zero trust moment

Manage AI risk with every action.

A managed runtime governance layer holds each AI action it governs to your controls and signs a record of each decision, one that buyers, auditors and insurers can check without trusting a dashboard.

The record

What you hand over when a reviewer asks.

The record is written for the people who sign off: a customer’s security team, an auditor, an underwriter. They can check it in a browser, with no Glacis account and nothing from your logs.

Every decision Glacis makes is written in OVERT, an open format we published so nobody has to trust us to read it. One record is one governed action. Not a token, not a request, not a seat.

This is a real one. It verifies in this browser, and it stays verifiable whether or not you’re still a customer.

OVERT 1.1, published 11 June 2026 under a royalty‑free patent covenant.

OVERT is moving to shared stewardship under CHAI and the AIGovOps Foundation, with Glacis Technologies as non-voting editor.

Demonstration sampleAs signedOVERT 1.1
Workflow
ambient-scribe-draft-note
Rule
PHI egress check · pass
Control
14 rules evaluated · 0 triggered
Decision
Allow · policy mode enforce
Record ID
glc_receip…f135
Recorded
2026-06-11 09:14:02 UTC
Output hash
157cf56f01…a161
Operator key
9c8eb1b83a…23d8
Witness key
7c038b40b8…39a5

Demonstration workflow data. The cryptography is real: every signature and hash in this record verifies in your browser.

    Open the full verifier

    Allow Constrain Hold Deny

    Ambient clinical documentation

    Where AI already acts on a patient’s behalf.

    nVoq builds ambient documentation for clinicians. Its head of product, on what Glacis adds to that workflow:

    “Glacis enables proactive AI trust and assurance, embedding consent validation, human‑in‑the‑loop oversight, and robust guardrails directly into ambient workflows.”
    Chad Hiner Chad HinerSenior Vice President of Product, nVoq nVoq

    How it works

    Every action gated, every decision signed, every record open to inspection.

    Every action passes through the layer, and every one is on the record. All of them, not a sample. That’s the denominator when an auditor or an underwriter asks how often a control ran.

    The gate

    Every action is held to the agreed controls before it runs: allowed, constrained, held for a person, or denied.

    The signature

    Each decision leaves a signed record: what was asked, which controls ran, what was decided, and when. Hashes, not the payload.

    The check

    Anyone holding a record can verify it against the open standard. No Glacis account, no dashboard, nothing from the application or its logs.

    Managed runtime governance

    Placed, agreed and run for you.

    We place the layer between the application and the models it calls, agree the controls with your team, and run it from there. You ship. The record keeps itself.

    Integration
    One call at the point of action, inside your own environment. Payloads stay where they are. The record carries hashes.
    Controls
    Written with you as policy and enforced on every action: approvals, guardrails, consent checks.
    Records
    Every decision signed and kept in an open format, readable by the people who sign off.

    Why now

    AI assurance is becoming a market. We build the part that can be checked.

    AI is acting inside real businesses, and the people who sign off on it want more than a policy and a dashboard. This summer showed why: agents inside a frontier lab’s own evaluation forged their tool calls, and the transcript said one thing while the action did another. Glacis closes that gap at runtime, with a record nobody has to take on faith.

    Where we fit

    Observability, guardrails, GRC. None of them shows which controls ran.

    Observability shows what the model did. Guardrails try to stop what it shouldn’t. Governance, risk and compliance answers for it on paper. Glacis sits in the path of the action and produces the one thing none of them does alone: a signed record of which controls ran and what they decided.

    Risk you can’t evidence stays yours. A record signed at the time and checkable after is what an auditor can review, a regulator can examine and an insurer can weigh.

    Fig. I. The accountability overlap Three overlapping circles: observability, which shows what the model did; guardrails, which try to stop what it should not; and GRC, governance, risk and compliance, which answers for it on paper. Where only two overlap the gap reads stopped but not signed, governed but not seen, or logged but not enforced. Glacis sits where all three meet, in the path of the action, and records which controls ran.
    Fig. IThe accountability overlap. Any two of the three leave a gap. Glacis sits where all three meet, in the path of the action, and records which controls ran.
    Working with
    • PACT AI
    • Digital Medicine Society
    • Coalition for Health AI
    • ScaleHealth
    • EisnerAmper
    • Cloudflare

    Let’s start where the questions are.

    What is it doing? What can it reach? Did the controls run? Can you prove it? For one team that’s organization-wide monitoring, to see every AI action before deciding what to gate. For another it’s one high-risk use case that needs an audit trail a regulator will accept. We take on a small number of managed deployments each quarter and reply within a business day.

    Platform·For agent teams·Healthcare