AI runtime security · governance tools

Manage AI risk with every action.

A managed runtime governance layer holds each AI action it governs to your controls and signs a record of each decision—one buyers, auditors and insurers can check without trusting a dashboard.

The record

What you hand over when a reviewer asks.

The record is written for the people who sign off: a customer’s security team, an auditor, an underwriter. They can check it in a browser, with no Glacis account and nothing from your logs.

Mutate a field and verification fails. Restore it and the checks pass. That is the property a reviewer relies on.

OVERT 1.1, published 11 June 2026 under a royalty‑free patent covenant.

Demonstration sampleAs signedOVERT 1.1
Workflow
ambient-scribe-draft-note
Rule
PHI egress check · pass
Control
14 rules evaluated · 0 triggered
Decision
Allow · policy mode enforce
Record ID
glc_receip…f135
Recorded
2026-06-11 09:14:02 UTC
Output hash
157cf56f01…a161
Operator key
9c8eb1b83a…23d8
Witness key
7c038b40b8…39a5

Demonstration workflow data. The cryptography is real: every signature and hash in this record verifies in your browser.

    Open the full verifier

    Allow Hold Deny

    Claim boundary

    What a record is not.

    A signed record is a checkable account of what a configured control path reported for one governed action. It is not a certificate, and it does not finish anyone’s compliance programme.

    • Not a compliance certification or audit opinion
    • Not proof that every action was captured
    • Not “EU AI Act done” or ISO 42001 complete
    • Not a substitute for Vanta, Drata or a SOC 2 report
    • Not an insurer’s coverage decision

    Evidence hop

    The same record, four readers.

    One governed action leaves one signed record. It travels without the payload, so each reader checks integrity in their own context.

    1. 01

      Seller

      Runs the control at the point of action and keeps the signed record.

    2. 02

      Buyer security

      Opens the record in a browser during diligence—no vendor dashboard.

    3. 03

      Auditor

      Compares the record to scope, exclusions and corroborating evidence.

    4. 04

      Insurer

      Uses the count of governed actions as a denominator for how often a control ran.

    How it works

    Every action gated, every decision signed, every record open to inspection.

    Between the application and the models it calls. Every governed action is held to the agreed controls before it runs. All of them, not a sample.

    The gate

    Allowed, held for a person, or denied—before the action runs.

    The signature

    Each decision leaves a signed record: controls, outcome, time, policy version. Hashes, not the payload.

    The check

    Anyone holding a record can verify it against the open standard. No Glacis account, no dashboard.

    Straight answers

    Objections we hear on the first call.

    Does this make us EU AI Act compliant?
    No. Signed records may support part of Article 12 logging when fields and coverage are relevant. They do not classify a system or establish compliance. FAQ
    We already have Vanta / Drata / SOC 2.
    Those manage programs and questionnaires. A record answers a narrower question: what a configured control reported for one AI action. Answers
    Can a vendor skip or alter records?
    Missing or altered records are detectable. Records are numbered and linked; a gap shows, and a changed record fails verification. FAQ
    Do reviewers need a Glacis account?
    No. Anyone holding a record can check it at verify.glacis.io in a browser. It stays verifiable after you leave. Verify
    What about PHI in the record?
    The record carries hashes rather than prompts, notes or patient data, so a reviewer can check integrity without receiving PHI.

    OVERT

    OVERT is moving to shared stewardship under CHAI and the AIGovOps Foundation, with Glacis Technologies as non-voting editor.

    A record you hold stays checkable against the open spec.

    Ambient clinical documentation

    Where AI already acts on a patient’s behalf.

    nVoq builds ambient documentation for clinicians and is our first customer and design partner. Its head of product, on what Glacis adds to that workflow:

    “Glacis enables proactive AI trust and assurance, embedding consent validation, human‑in‑the‑loop oversight, and robust guardrails directly into ambient workflows.”
    Chad Hiner Chad HinerSenior Vice President of Product, nVoq nVoq

    For reviewers

    Twelve questions for an AI vendor.

    A print-ready checklist for health-system and enterprise security teams. Free. No form, no email.

    Dated, checkable

    Facts already on the record.

    • 11 Jun 2026OVERT 1.1 published under a royalty-free patent covenant.
    • Sep 2026Selected for Lloyd’s Lab Cohort 17—selection, not an endorsement of coverage terms.
    • 1 Jan 2027Colorado’s automated-decision rules take effect for covered deployments.

    Let’s start where the questions are.

    What is it doing? What can it reach? Did the controls run? Can you prove it? We take on a small number of managed deployments each quarter and reply within a business day.

    FAQ·Answers·Verify·Evidence pack