Permit, block, or escalate runtime events inside your environment. Each important decision can produce a signed receipt, so reviewers can verify controls ran without seeing sensitive payloads.
Get runtime coveragepolicy.fsi.credit_match
policy.phi.exfil_guard
policy.agent.scope_exceeded
How it works
GLACIS deploys control points next to the AI workflow. It evaluates requests, responses, tool calls, and escalations using local policy logic, then permits, blocks, or routes to review. No sensitive data leaves your environment.
Not a filter. A control plane.
Capabilities
Sub-millisecond overhead. Single binary, no runtime dependencies. Deploys anywhere containers run.
A local small language model scores every request for policy compliance—no data leaves your perimeter.
Continuous monitoring of model behavior against your baseline. Alerts when outputs shift outside policy bounds.
Observe and log without blocking. Deploy Enforce in shadow mode first, then flip to active enforcement when you’re ready.
See every AI system in your organization. Policy status, violation rates, drift trends—one view.
Define policies in YAML. Version them in Git. Roll out across your fleet with CI/CD integration.
Three-outcome verdicts on every request. Clean outputs pass. Violations block. Edge cases route to human review.
Every consequential verdict, policy evaluation, and escalation can be tied to a signed receipt and evidence hash.
Who this is for
Ready to start
Runtime coverage maps one workflow, places controls, instruments receipts, and assembles the first evidence pack.
Start narrow. Prove deeply. Reuse the pattern.
Get runtime coverageFAQ
Also from GLACIS
Diagnostic
Identify attack paths, data boundaries, tool-call risks, control gaps, and the first receipts that need to exist.
View diagnosticEvidence
OVERT-format receipts. Tamper-evident, independently verifiable, zero sensitive-data egress. Every consequential control decision can generate signed proof — by default, not by upgrade.
Learn about signed receipts