AI runtime security · governance tools
Manage AI risk with every action.
Glacis is managed runtime governance: we run the gate and sign the record, so your AI ships with the controls enforced and the evidence already written—and a customer’s security team, an auditor or an underwriter can check any governed decision for themselves.
Where you stand
Three places to start, one managed layer.
01
Vendors
AI you sell
An answer ready before the questionnaire arrives. A customer’s security team reads how your AI is controlled, in a signed record they check in their own browser.
Evidence pack02
Health systems & enterprises
AI you oversee
Vendor assurances you can check yourself. Your team reads what a vendor’s controls actually did in the live workflow.
For reviewers03
Operators & agent teams
AI in production
Enforcement you don’t have to build. The AI you run is supervised at the point of action, with a record others can verify without a Glacis account.
For operatorsHow it works
Every action gated, every decision signed, every record open to inspection.
Between the application and the models it calls. Every governed action is held to the agreed controls before it runs—all of them, not a sample. Glacis runs that layer; you don’t staff it.
The gate
Allowed, held for a person, or denied—before the action runs.
The signature
Each decision leaves a signed record: controls, outcome, time, policy version. Hashes, not the payload.
The check
Anyone holding a record can verify it against the open standard. No Glacis account, no dashboard.
The record
Audit-ready while you ship.
Every governed action leaves one signed record as it happens, so there is nothing to assemble under deadline. The record travels without the payload: a customer’s security team, an auditor or an underwriter checks it in a browser, with no Glacis account and nothing from your logs.
Mutate a field and verification fails. Restore it and the checks pass. Nobody has to take your word for it.
Open the verifier·Read the primer
OVERT 1.1, published 11 June 2026 under a royalty‑free patent covenant.
Demonstration workflow data. The cryptography is real: every signature and hash in this record verifies in your browser.
What a record is not
- A compliance certification or audit opinion
- Proof that every action was captured
- “EU AI Act done” or ISO 42001 complete
- A substitute for Vanta, Drata or a SOC 2 report
- An insurer’s coverage decision
A clinical customer, an open standard, and the Lloyd’s Lab.
nVoq builds ambient documentation for clinicians and is our first customer and design partner. Its senior vice president of product, on what Glacis adds to that workflow:
“Glacis enables proactive AI trust and assurance, embedding consent validation, human‑in‑the‑loop oversight, and robust guardrails directly into ambient workflows.”
Chad HinerSenior Vice President of Product, nVoq
- 11 Jun 2026OVERT 1.1 published under a royalty-free patent covenant.
- Sep 2026Selected for Lloyd’s Lab Cohort 17—selection, not an endorsement of coverage terms.
- 1 Jan 2027Colorado’s automated-decision rules take effect for covered deployments.
OVERT is moving to shared stewardship under CHAI and the AIGovOps Foundation, with Glacis Technologies as non-voting editor.
A record you hold stays checkable against the open spec.Let’s talk about what you’re shipping.
Your AI goes live with the control and the record already in place, and we keep running them. We reply within a business day.
