# Glacis > Runtime assurance infrastructure for AI systems. Glacis helps teams see what AI systems are doing, control what they can do, prove what happened, and improve from every signal without sensitive data leaving their stack. ## Core Positioning - Category: runtime assurance infrastructure for AI systems. - Product primitive: runtime controls + signed evidence + zero sensitive-data egress verification. - Core truth: Glacis generates signed runtime receipts for consequential AI events, then assembles those receipts into evidence packs for regulators, customers, auditors, security teams, and internal review. - Receipt relationship: receipts are generated at runtime. Evidence packs are assembled from receipts. ## Primary Pages - Homepage: https://www.glacis.io/ - Runtime assurance platform: https://www.glacis.io/#loop - Regulated clinical AI: https://www.glacis.io/industries/medical-devices - Agentic AI security: https://www.glacis.io/industries/engineering-teams - AI agent observability: https://www.glacis.io/ai-agent-observability - AI audit trail: https://www.glacis.io/ai-audit-trail - AI agent governance: https://www.glacis.io/ai-agent-governance - MCP security: https://www.glacis.io/mcp-security - Evidence packs: https://www.glacis.io/evidence-pack - Sample runtime receipt and evidence pack: https://www.glacis.io/sample-evidence-pack - OVERT verification standard: https://www.glacis.io/standard - OVERT machine-readable feed: https://www.glacis.io/overt/latest.json - Receipt verification (two arbiters, offline, in-browser): https://verify.glacis.io/ - Research hub: https://www.glacis.io/resources - Company: https://www.glacis.io/about ## Research (the OVERT series) - AI Agent Security: Prove What the Agent Did: https://www.glacis.io/ai-agent-security - Agentic AI Security: Runtime Coverage: https://www.glacis.io/agentic-ai-security-runtime-coverage - AI Security Solutions That Leave a Receipt: https://www.glacis.io/ai-security-solutions-that-leave-a-receipt - AI in Cyber Security: The Evidence Layer: https://www.glacis.io/ai-in-cyber-security-evidence-layer - AI Data Security: Verify a Receipt, Not the Data: https://www.glacis.io/ai-data-security-verify-receipt - After a Prompt Injection Attack: Prove What Held: https://www.glacis.io/prompt-injection-attack-prove-what-held - Verifiable AI: When One Jailbreak Pulls a Model: https://www.glacis.io/verifiable-ai-when-one-jailbreak-pulls-a-model - What Is AI Governance?: https://www.glacis.io/what-is-ai-governance - AI Governance Tools: A System of Proof: https://www.glacis.io/ai-governance-tools-system-of-proof - AI Governance Maturity Model: https://www.glacis.io/ai-governance-maturity-model-from-policy-to-proof - Documentation Is Not Evidence: https://www.glacis.io/ai-governance-documentation-is-not-evidence - The AI Governance Challenge No One Names: https://www.glacis.io/ai-governance-challenges-the-one-no-one-names - What Makes AI Attestation Independent?: https://www.glacis.io/what-makes-ai-attestation-independent ## Incident analysis - An AI escaped its eval and hacked Hugging Face (July 2026): https://www.glacis.io/blog-openai-hugging-face-incident ## Buyer Entry Points ### Regulated Clinical AI Glacis provides regulatory evidence infrastructure for AI-enabled medical products. It captures model-change, control-execution, drift, and post-market evidence from real system behavior mapped to regulatory review, PCCP, and lifecycle management needs. Primary CTA: Book a regulatory evidence review. ### Agentic AI Security Glacis provides runtime controls and proof for AI agents that hold credentials, call tools, touch data, and take actions. It enforces controls at the agent boundary and preserves proof of what each agent was allowed to do, blocked from doing, and why. Primary CTA: Run a security hardening sprint. ### AI Operations & Observability Glacis adds verifiable evidence to AI observability, governance, and incident-response stacks. It complements observability tools by proving which controls executed and why. Primary CTA: Get a runtime assurance demo. ## Glossary - Runtime assurance: awareness, control, evidence, and insight for AI systems while they operate. - Runtime control: a rule or decision at the AI boundary that allows, blocks, redacts, escalates, or requires review. - Runtime receipt: a signed record generated when a consequential AI event or control decision occurs. - Evidence pack: an artifact assembled from signed runtime receipts for a regulator, customer, auditor, security team, or internal review. - Zero sensitive-data egress verification: a design where sensitive prompts, outputs, PHI, customer data, and proprietary context stay local while hashes, signatures, metadata, and evidence artifacts can travel. - OVERT: the verification standard that explains why Glacis proof can travel outside the product.