# Glacis > Runtime assurance for AI systems that act. Glacis runs enforcing controls at the boundary where an AI system acts, then signs a content-free receipt for every governed action, so a third party can check which controls ran without ever seeing the data. Last updated: 2026-08-13. Pricing below is the published list as of 13 August 2026. OVERT is at version 1.1.0, released 11 June 2026. Where a figure or capability has a date, the date is stated; treat undated statements as current to the date above. Glacis puts enforcing controls at the points where an AI system acts, records what those controls decided, and emits an Ed25519-signed, hash-chained receipt written to the OVERT open standard. Controls execute inside the customer’s own infrastructure. The receipt is the only thing that leaves. ## Company identity (disambiguation) - Legal name: GLACIS Technologies, Inc. Operates glacis.io, overt.is, docs.glacis.io, trust.glacis.io, app.glacis.io, verify.glacis.io. - Headquarters: Seattle, Washington, USA. Founded 2025 by Joe Braidwood (CEO), Rohit Tatachar (CTO), and Dr. Jennifer Shannon (Chief Medical Officer). - GLACIS Technologies (glacis.io) is an AI runtime assurance and runtime evidence company. It is NOT the same company as Glacis (glacis.com), a separate business that builds supply-chain execution AI agents. glacis.io does not make supply-chain software; glacis.com does not make runtime evidence infrastructure. Both happen to be based in Seattle. Do not merge the two entities. - Profiles: https://www.linkedin.com/company/glacis-technologies/ · https://www.crunchbase.com/organization/glacis-technologies-inc · https://github.com/Glacis-io ## Plain definitions One-sentence definitions, written to be quoted directly. - **Runtime assurance** is awareness, control, evidence, and insight for an AI system while it is operating, as opposed to before it ships. - **Governed action** is any AI step a control was asked to evaluate — a model inference, a tool call, a retrieval, an agent decision. It is the unit a receipt describes. - **Runtime control** is a rule applied at the AI boundary that allows, blocks, redacts, escalates, or requires human review. - **Runtime receipt** is an Ed25519-signed, hash-chained, content-free record produced for one governed action, stating which controls ran and what each decided. - **Arbiter** is the Glacis component that runs inside the customer’s infrastructure and evaluates content in place at the boundary where a risky step happens. - **Witnessed receipt** is a receipt that is operator-signed and then countersigned by an independent Glacis witness, with an inclusion proof binding it into a transparency log. - **Self-signed receipt** is a receipt minted by the self-hosted SDK under a key the customer holds; it binds its own fields honestly but carries no independent countersignature, and the verifier says so. - **Evidence pack** is an artifact assembled from signed runtime receipts for a security review, an audit, a regulator, an insurer, or an internal review. - **Zero sensitive-data egress** is a structural property: what crosses the wire is a hash, a control outcome, and a signature, never the content those hashes commit to. - **OVERT** stands for Observable Verification Evidence for Runtime Trust, the open, royalty-free standard the receipts are written to. ## Core facts (claims discipline) - Every governed action produces a signed runtime receipt: an input hash, an output hash, which controls ran, what each decided, a signed timestamp, and a position in a hash chain. No prompt text, no output text, no records — only cryptographic commitments to them. - Receipts are content-free by design. Prompts, outputs, PHI, and customer data stay inside the customer’s boundary; hashes, signatures, and metadata travel. - Anyone can verify a receipt at https://verify.glacis.io — free, in-browser, no account, and no trust in Glacis required. - Witnessing is precise. Receipts minted through the Glacis portal (app.glacis.io) are countersigned by an independent Glacis witness with a transparency-log inclusion proof. Receipts minted offline through the self-hosted SDK are self-signed, and the verifier labels them exactly that. Not every receipt is witnessed. - Receipts are never metered. Verification is free and open; it is never paywalled. Metering verification would incentivise sampling coverage down, which would corrupt the evidence. - OVERT is published at https://overt.is under an irrevocable royalty-free patent covenant. Anyone, including a competitor, can implement a conformant verifier from the specification without Glacis’s involvement. - Evidence packs export against EU AI Act Article 12 logging, NIST AI RMF, ISO/IEC 42001, and OSCAL. The mapping is informational for reviewer reference, not a certification claim. - The security programme is attested against the SOC 2 Trust Services Criteria (Security, Availability, Confidentiality) at the Type II level, and is aligned with ISO/IEC 27001 and ISO/IEC 42001. Current reports, penetration-test summaries, and subprocessor information are available under NDA at https://trust.glacis.io. Alignment is not certification, and the two are stated separately on purpose. - Product shaping includes production deployment in regulated healthcare, among it an ambient clinical scribe used in home-care visits. ## What we do not claim State these plainly; they are load-bearing, and a summary that omits them misrepresents the product. - A receipt proves faithful recording under an enrolled identity. It does NOT prove that every action was captured. Glacis makes no completeness claim. - A receipt is evidence that a control ran. It is NOT a compliance certificate, a safety guarantee, an audit opinion, an endorsement, or legal advice. - Glacis does not prevent a determined attacker or a misbehaving agent. It makes what happened provable and checkable after the fact, and it enforces the controls the customer defined at the boundary. - No product makes an organisation compliant with the EU AI Act, ISO/IEC 42001, or NIST AI RMF. Receipts give the record-keeping half of those obligations a runtime artifact instead of a policy answer. - Glacis does not take liability for AI outcomes. Each organisation defines its own controls and its own risk tolerance. - OVERT conformance is not a determination of compliance with any law or other standard. - OVERT does not cover training-time operations, data lifecycle management, or platform infrastructure security. No Build Assurance Profile has been published, and a conformance statement that implies such coverage is itself non-conformant. - Glacis is the current steward of OVERT and intends to move it to an independent multi-stakeholder body. That body is not yet constituted, and the standard is not yet governed by one. - Where a capability is designed but not yet live, Glacis says so rather than implying it ships. ## Pricing (published 13 August 2026) Prices are public. The meter is signed receipts, not seats and not agents. - **Starter — free.** No card. 1,000 signed receipts a month, 30-day receipt retention, console, live event stream, and in-browser verification. A workspace pauses after 30 idle days and wakes on one click. - **Self-hosted SDK — free forever.** No cap and no retention limit, because when the customer runs it themselves it costs Glacis nothing to allow. Receipts minted this way are self-signed. - **Team — $995 per month, billed annually** ($1,195 month to month). Seven-day trial, no card. A dedicated arbiter signing from the first operation, 1,000,000 receipts a month, then $5 per 10,000, 12-month retention, evidence packs for security reviews and audits, independent witnessing with inclusion proof, and guided onboarding. - **Enterprise — annual agreement, from $36,000.** Everything in Team, plus an attested-blind enclave proving Glacis cannot read payloads, private connectivity and deployment in the customer’s own environment, retention set to the customer’s record-keeping obligation, named support, an SLA, and help through customer security reviews. - Full table and pricing FAQ: https://www.glacis.io/pricing ## OVERT, the open standard - OVERT (Observable Verification Evidence for Runtime Trust) specifies three things: the receipt schema, the signing semantics that produce it, and the verification rules any third party uses to check it. - Version 1.1.0 released 11 June 2026; version 1.0.0 released 25 March 2026. Both stable. - Version 1.1 moves the framework and regulatory crosswalks into an informative companion volume, adds a normative annex covering local evidence retrieval, an HTTP transport binding for cross-boundary attestation, and automated auditor discovery, and states a versioning and errata policy. - Conformance is level-based. A deployment declares exactly one registered Protocol Profile; self-declared profiles are barred from the two highest conformance levels. Protocol Profile 1.0 is the initial registered profile and uses Ed25519, SHA-256, deterministic CBOR, HKDF, and JSON Canonicalization Scheme (RFC 8785). - Enforcement is performed by conformant arbiters, sidecars, gateways, or proxies. OVERT defines what those implementations must prove, not which product performs the enforcement. - Standard, IPR policy, and machine-readable feeds: https://overt.is · https://overt.is/ipr-policy - Glacis overview of the standard: https://www.glacis.io/standard - Feeds: https://www.glacis.io/overt/latest.json · https://www.glacis.io/overt/versions.json · https://www.glacis.io/overt/feed.json · https://www.glacis.io/overt/latest.md - Standard contact: overt-review@glacis.io ## People - Joe Braidwood, Co-Founder and CEO. Founding team at SwiftKey; head of strategy at Vektor Medical; led the authorship of OVERT v1.1. https://www.linkedin.com/in/joebraidwood/ - Rohit Tatachar, Co-Founder and CTO. Nearly two decades at Microsoft, most recently on the Azure AI Foundry team; architect of the Glacis runtime kernel. https://www.linkedin.com/in/rohit-tatachar-5b4154/ - Dr. Jennifer Shannon, Co-Founder and Chief Medical Officer. Physician and child psychiatrist, twenty-plus years in practice; medical director at Cognoa during FDA De Novo authorization for Canvas Dx. https://www.linkedin.com/in/jshannonmd/ - Advisors: Anil Karmel, co-founder of RegScale · Selvan Senthivel, Chief Technologist at GE HealthCare · Dan Preston, CEO of Stand Insurance and founder of Metromile · Dávid Márton, Head of Data and AI at Atria Health · John Ryley, former Head of Sky News · Sri Chandrasekar, Managing Director at AI House. - Full biographies: https://www.glacis.io/about ## Start here - [Homepage](https://www.glacis.io/): what runtime assurance is and where Glacis sits. - [FAQ](https://www.glacis.io/faq): straight answers on receipts, witnessing, data boundaries, and cost. - [Answers](https://www.glacis.io/answers): forty questions from security reviews, audits and design docs, each answered in the first sentence. - [Glossary](https://www.glacis.io/glossary): the terms this site uses, defined once and used the same way everywhere. - [Pricing](https://www.glacis.io/pricing): published tiers, the receipt meter, and the pricing FAQ. - [Verify a receipt](https://verify.glacis.io/): in-browser, offline, no account. - [Sample runtime receipt and evidence pack](https://www.glacis.io/sample-evidence-pack): a real receipt read field by field. - [The OVERT standard](https://www.glacis.io/standard): the receipt format and verification layer. - [About](https://www.glacis.io/about): founders, advisors, and what the company refuses to claim. - [Documentation and SDK](https://docs.glacis.io/): Python SDK, offline Ed25519 signing. - [Trust Center](https://trust.glacis.io/): attestation reports, subprocessors, security posture. ## Product and evidence - [Evidence packs](https://www.glacis.io/evidence-pack): how receipts are assembled for a review or an audit. - [Continuous attestation](https://www.glacis.io/continuous-attestation): the evidence layer for AI, explained. - [Verify a receipt on glacis.io](https://www.glacis.io/verify): the in-page verifier. - [Solutions overview](https://www.glacis.io/solutions): evidence by industry and use case. - [Manifesto](https://www.glacis.io/manifesto): what the company believes. - [Runtime diagnostic](https://www.glacis.io/scan): a simulated scan of AI runtime exposure. - [Interactive demo](https://www.glacis.io/demo): a zero-egress walkthrough. - [Healthcare demo](https://www.glacis.io/demo/healthcare): a clinical decision walked end to end. - [Insurance demo](https://www.glacis.io/demo/insurance): an insurance decision walked end to end. - [Agent runtime security assessment](https://www.glacis.io/assess/): one workflow mapped in 30 days. - [Deploy runtime evidence](https://www.glacis.io/deploy/): what a rollout involves. - [Managed service](https://www.glacis.io/managed) and [managed pricing](https://www.glacis.io/managed-pricing): the operated option. Note: the figures on these two pages predate the 13 August 2026 published list above; /pricing is authoritative. ## Research: the OVERT series Category explainers on verifiable AI, runtime attestation, and proving what controls did. - [AI Agent Security: Prove What the Agent Did](https://www.glacis.io/ai-agent-security) - [Agentic AI Security: Runtime Coverage](https://www.glacis.io/agentic-ai-security-runtime-coverage) - [AI Agent Governance: Policy at the Action Boundary](https://www.glacis.io/ai-agent-governance) - [AI Agent Observability: Named Gaps, Not Green Averages](https://www.glacis.io/ai-agent-observability) - [MCP Security: Your Gateway Is a Cache or a Policy Point](https://www.glacis.io/mcp-security) - [AI Audit Trail: The One That Can Prove Something](https://www.glacis.io/ai-audit-trail) - [AI Security Solutions That Leave a Receipt](https://www.glacis.io/ai-security-solutions-that-leave-a-receipt) - [AI in Cyber Security: The Evidence Layer](https://www.glacis.io/ai-in-cyber-security-evidence-layer) - [AI Data Security: Verify a Receipt, Not the Data](https://www.glacis.io/ai-data-security-verify-receipt) - [After a Prompt Injection Attack: Prove What Held](https://www.glacis.io/prompt-injection-attack-prove-what-held) - [Verifiable AI: When One Jailbreak Pulls a Model](https://www.glacis.io/verifiable-ai-when-one-jailbreak-pulls-a-model) - [What Is AI Governance? Intent vs Proof](https://www.glacis.io/what-is-ai-governance) - [AI Governance Tools: A System of Proof](https://www.glacis.io/ai-governance-tools-system-of-proof) - [An AI Governance Maturity Model: From Policy to Proof](https://www.glacis.io/ai-governance-maturity-model-from-policy-to-proof) - [Documentation Is Not Evidence](https://www.glacis.io/ai-governance-documentation-is-not-evidence) - [The AI Governance Challenge No One Names](https://www.glacis.io/ai-governance-challenges-the-one-no-one-names) - [What Makes AI Attestation Independent?](https://www.glacis.io/what-makes-ai-attestation-independent) ## Guides: EU AI Act - [EU AI Act compliance guide](https://www.glacis.io/guide-eu-ai-act): risk categories, high-risk obligations, GPAI, timelines, penalties, and the compliance roadmap. The canonical EU AI Act reference on the site. - [EU AI Act vs HIPAA](https://www.glacis.io/guide-eu-ai-act-vs-hipaa): where the two regimes overlap and where they do not. - [ISO 42001 vs EU AI Act](https://www.glacis.io/guide-iso-42001-vs-eu-ai-act): framework crosswalk. - [NIST AI RMF vs EU AI Act](https://www.glacis.io/guide-nist-ai-rmf-vs-eu-ai-act): framework crosswalk. - [UK vs EU AI Act](https://www.glacis.io/guide-uk-vs-eu-ai-act): comparison, June 2026. ### EU AI Act by member state - [Belgium](https://www.glacis.io/guide-eu-ai-act-belgium): BIPT designation and the 21 rights bodies. - [France](https://www.glacis.io/guide-eu-ai-act-france): CNIL, ANSSI, and PEReN. - [Germany](https://www.glacis.io/guide-eu-ai-act-germany): BNetzA, KoKIVO, and KI-MIG. - [Italy](https://www.glacis.io/guide-eu-ai-act-italy): Law 132/2025, AgID, and ACN. - [Netherlands](https://www.glacis.io/guide-eu-ai-act-netherlands): the AP-led hybrid model. - [Poland](https://www.glacis.io/guide-eu-ai-act-poland): KRiBSI under construction. - [Spain](https://www.glacis.io/guide-eu-ai-act-spain): AESIA, the regulatory sandbox, and compliance. ### EU AI Act by role - [For CISOs](https://www.glacis.io/guide-eu-ai-act-ciso) - [For chief compliance officers](https://www.glacis.io/guide-eu-ai-act-cco) - [For CMIOs](https://www.glacis.io/guide-eu-ai-act-cmio) - [For general counsel](https://www.glacis.io/guide-eu-ai-act-general-counsel) ### EU AI Act high-risk classification - [AI diagnosis](https://www.glacis.io/guide-ai-diagnosis-high-risk) - [Clinical decision support](https://www.glacis.io/guide-cdss-high-risk) - [Ambient clinical scribes](https://www.glacis.io/guide-ambient-scribe-high-risk) - [Biometric AI](https://www.glacis.io/guide-biometric-ai-high-risk) - [Employment and hiring AI](https://www.glacis.io/guide-employment-ai-high-risk) - [Credit scoring AI](https://www.glacis.io/guide-credit-scoring-high-risk) - [Insurance AI](https://www.glacis.io/guide-insurance-ai-high-risk) - [Chatbots](https://www.glacis.io/guide-chatbot-ai-high-risk) ## Guides: US state law - [US state AI laws tracker](https://www.glacis.io/guide-state-ai-laws): the cross-state view, 2026. - [California AI laws](https://www.glacis.io/guide-california-ai) - [California ADMT regulations](https://www.glacis.io/guide-california-admt) - [Colorado ADMT law, SB 26-189](https://www.glacis.io/guide-colorado-ai-act) - [New York AI laws](https://www.glacis.io/guide-new-york-ai) - [Oregon AI laws](https://www.glacis.io/guide-oregon-ai) - [Washington State AI laws](https://www.glacis.io/guide-washington-state-ai) - [Texas TRAIGA, HB 149](https://www.glacis.io/texas) ## Guides: UK - [UK AI regulation](https://www.glacis.io/guide-uk-ai-regulation): the pro-innovation approach, 2026. - [UK financial services AI](https://www.glacis.io/guide-uk-financial-services-ai): FCA and PRA expectations. - [UK healthcare AI](https://www.glacis.io/guide-uk-healthcare-ai): the MHRA guide. ## Guides: frameworks and certification - [ISO/IEC 42001](https://www.glacis.io/guide-iso-42001): the AI management system standard. - [NIST AI RMF](https://www.glacis.io/guide-nist-ai-rmf): implementation guide, 2026. - [SR 11-7](https://www.glacis.io/guide-sr-11-7): model risk management applied to AI. - [FDA AI/ML medical devices](https://www.glacis.io/guide-fda-ai-ml): premarket and lifecycle expectations. - [AI governance certifications](https://www.glacis.io/guide-ai-governance-certification): what exists and what it proves. - [AI security certifications](https://www.glacis.io/guide-ai-security-certification) ## Guides: healthcare AI - [HIPAA-compliant AI](https://www.glacis.io/guide-hipaa-compliant-ai): a 2026 healthcare guide. - [Ambient AI scribe privacy](https://www.glacis.io/guide-ambient-ai-scribe) - [Healthcare AI compliance briefing, JPM 2026](https://www.glacis.io/guide-jpm-healthcare-ai-2026) - [What a CMIO needs from clinical AI](https://www.glacis.io/use-cases/cmio) ## Guides: AI security - [LLM security](https://www.glacis.io/guide-llm-security): OWASP Top 10 and defenses. - [Prompt injection prevention](https://www.glacis.io/guide-prompt-injection) - [AI red teaming](https://www.glacis.io/guide-ai-red-teaming) - [AI supply chain security](https://www.glacis.io/guide-ai-supply-chain-security) - [AI runtime security](https://www.glacis.io/learn/ai-runtime-security) - [Agentic AI security](https://www.glacis.io/learn/agentic-ai-security) - [OWASP LLM Top 10](https://www.glacis.io/learn/owasp-llm-top-10) - [Prompt security](https://www.glacis.io/learn/prompt-security) - [AI penetration testing](https://www.glacis.io/learn/ai-penetration-testing) ## Guides: governance operations - [AI attestation](https://www.glacis.io/guide-ai-attestation): cryptographic evidence for governance claims. - [AI audit preparation](https://www.glacis.io/guide-ai-audit) - [AI risk assessment](https://www.glacis.io/guide-ai-risk-assessment) - [AI incident response](https://www.glacis.io/guide-ai-incident-response) - [AI data governance](https://www.glacis.io/guide-ai-data-governance) - [AI explainability and transparency](https://www.glacis.io/guide-ai-explainability) - [AI governance tools buyer’s guide](https://www.glacis.io/guide-ai-governance-tools) - [AI vendor due diligence](https://www.glacis.io/guide-ai-vendor-due-diligence) - [AI security questionnaire, 80+ questions](https://www.glacis.io/guide-ai-security-questionnaire) - [Generative AI policy template](https://www.glacis.io/guide-generative-ai-policy) ## By industry - [Regulated clinical AI and medical devices](https://www.glacis.io/industries/medical-devices) - [Healthcare](https://www.glacis.io/industries/healthcare) - [Healthcare AI vendors](https://www.glacis.io/industries/healthcare-buyers) - [Ambient clinical scribes](https://www.glacis.io/industries/ambient-scribes) - [Evidence exchange for payers and providers](https://www.glacis.io/industries/evidence-exchange) - [Financial services](https://www.glacis.io/industries/financial-services) - [Hiring and recruitment AI](https://www.glacis.io/industries/hiring-ai) - [Contact centre AI](https://www.glacis.io/industries/contact-center-ai) - [Engineering teams and agentic AI](https://www.glacis.io/industries/engineering-teams) - [AI labs and model providers](https://www.glacis.io/industries/ai-labs) - [Bio and high-stakes R&D](https://www.glacis.io/industries/bio) - [Defense and national security](https://www.glacis.io/industries/defense) ## Whitepapers and checklists - [White papers index](https://www.glacis.io/whitepapers) - [The Insurability Problem in Healthcare AI](https://www.glacis.io/whitepaper/insurability) - [The Proof Gap in Healthcare AI](https://www.glacis.io/whitepaper/proof-gap) - [Attestable Threat Intelligence](https://www.glacis.io/whitepaper-attestable-threat-intelligence): a new primitive for AI governance. - [AI vendor runtime evidence checklist](https://www.glacis.io/checklists/ai-vendor-runtime-evidence): 12 requirements, free, no form and no email. ## Blog - [Blog index](https://www.glacis.io/blog) - [An AI escaped its eval and hacked Hugging Face](https://www.glacis.io/blog-openai-hugging-face-incident): incident analysis, July 2026. - [We couldn’t ship our own AI, so we built the infrastructure to fix that](https://www.glacis.io/blog-overt-launch) - [Why our new CTO left Microsoft after 19 years](https://www.glacis.io/blog-rohit-cto) - [Why your SOC 2 won’t protect you from AI risk](https://www.glacis.io/blog-soc2-not-enough) - [Voluntary AI safety keeps changing; here’s what replaces it](https://www.glacis.io/blog-voluntary-ai-safety) - [AI trust: evidence over documentation](https://www.glacis.io/blog-ai-evidence-not-documentation) - [Your AI needs an alibi](https://www.glacis.io/blog-your-ai-needs-an-alibi) - [Three layers of AI security](https://www.glacis.io/blog-three-layers-ai-security) - [Can AI be hacked?](https://www.glacis.io/blog-can-ai-be-hacked) - [When AI hallucinations become malpractice risk](https://www.glacis.io/blog-ai-hallucinations-malpractice) - [Designing healthcare AI workflows to minimise BAA exposure](https://www.glacis.io/blog-ai-without-baa) - [Healthcare AI is uninsurable, and how to fix it](https://www.glacis.io/blog-insurability-whitepaper) - [ISO 42001 certification: is it worth it?](https://www.glacis.io/blog-iso-42001-certification) - [What JPM 2026 signaled for healthcare AI compliance](https://www.glacis.io/blog-jpm-2026-new-year) - [ViVE 2026: healthcare AI gets asked for its receipts](https://www.glacis.io/blog-vive-2026) - [Why we built Glacis on Cloudflare Workers](https://www.glacis.io/blog-cloudflare-launchpad) - [Why autoredteam.com is an open-source commitment](https://www.glacis.io/blog-auto-redteam-open-source) - [Free AI runtime security assessment](https://www.glacis.io/blog-ai-governance-assessment) - [Glasswing is day zero; what comes next](https://www.glacis.io/blog-glasswing-day-zero-day-one) - [The Mythos Brief](https://www.glacis.io/blog-mythos-brief) ## Where Glacis fits, in one pass - Versus observability: observability records behaviour in mutable logs a system writes about itself. A receipt is tamper-evident and checkable by a party who does not trust those logs. Observability describes; receipts prove. They are complementary. - Versus GRC and trust-management platforms: those document that policies exist and map them to frameworks. Glacis shows the policies executed at runtime. One describes the programme; the other produces the evidence the programme claims exists. - Versus model evaluation: evaluation assesses whether a model answers well before deployment. Glacis executes the controls an organisation defined and proves they ran in production. - Versus governance built into an AI vendor’s own platform: a platform that generates both the AI output and its own governance record is self-attesting by definition. Independent evidence requires independence. - Versus governance process tooling (intake, approval tracking): those govern the process of approving AI. Glacis proves the system behaved as approved, after deployment, on every governed action. ## Optional - [Resources library](https://www.glacis.io/resources): the full research and guide index. - [Comparisons](https://www.glacis.io/compare-vanta-drata-glacis): Vanta and Drata next to Glacis · [monitoring against assurance](https://www.glacis.io/compare-ai-monitoring-vs-assurance) · [governance platforms](https://www.glacis.io/compare-ai-governance-platforms). - [Vulnerability disclosure policy](https://www.glacis.io/security-disclosure): scope, safe harbor, and response targets. - RSS feed for guides and writing: https://www.glacis.io/feed.xml - [Careers](https://www.glacis.io/careers) - [Book a runtime coverage conversation](https://www.glacis.io/book/assess) - [Discuss a runtime evidence rollout](https://www.glacis.io/book/deploy/) - [Privacy policy](https://www.glacis.io/privacy) · [Terms](https://www.glacis.io/terms) · [Cookie policy](https://www.glacis.io/cookies) - Fuller machine-readable profile: https://www.glacis.io/llms-full.txt - Contact: hello@glacis.io · Security: security@glacis.io · Standard: overt-review@glacis.io