GLACIS Managed · Per-tenant arbiter

Put one consequential AI workflow under supervision.

A managed Glacis deployment applies the intended rule where an AI takes action: allow, block, or escalate. Each covered decision leaves a signed operational record that can be checked independently. The deployment plan states what is—and is not—in scope.

Defined coverage · Explicit fail posture · Signed records you can verify

Runtime event stream simulation · arbiter-01 · us-east
  • 14:02:31agent-billingtool.invoke · stripe.refundallow
  • 14:02:31arbitersigned · 4f2c…a081witnessed
  • 14:02:33agent-supportmail.send · external recipientwitnessed
  • 14:02:36agent-opsdb.drop_table · prodblocked
  • 14:02:36arbitersigned · b3d9…07e2witnessed
Action
tool.invoke · stripe.refund
Policy
spend-limit-v3 · allow
Witness
witness.glacis.io
Hash chain
4f2c…a0819d17…33c5
canonicalize (RFC 8785) SHA-256 Ed25519 chain

✓ VERIFIED

Simulated for illustration · the cryptographic verification below runs locally in your browser.

Observability sees. GRC documents. Guardrails filter. Platform logs are the platform's word. Glacis leaves evidence another party can check.

The demo

From governed action to verifiable record.

The whole loop fits in one breath. The same four beats run live on every sales call.

  1. 0:00

    One command

    The connector brings up a WireGuard tunnel. Your agents now reach their arbiter over a private WAN.

  2. 0:02

    One line

    Change the agent's base URL. It doesn't know anything happened.

  3. 0:04

    Arbitrated inline

    Each configured in-scope operation can be allowed, witnessed, or blocked — with a signed record created for the covered event.

  4. 0:07

    Verify it yourself

    Drop the receipt into the browser verifier. Don't take it on trust. Check it.

tenant-arbiter · demo capture
$ glacis connect
wg0 up · tenant arbiter reachable · private WAN

# agent config — one line
- base_url: https://api.provider.example
+ base_url: https://arbiter-01.tenant.glacis

# event stream
14:02:31  agent-billing  tool.invoke      allow
14:02:33  agent-support  mail.send        witnessed
14:02:36  agent-ops      db.drop_table    blocked

# receipt 4f2c…a081
canonicalize (RFC 8785)   SHA-256   Ed25519   chain 
✓ VERIFIED IN YOUR BROWSER — local cryptographic check complete

Simulated for illustration · the verification is real — run it on a real signed receipt below.

Verify it yourself

Check the record yourself.

This is a real signed sample record. The verifier processes the record locally in your browser—Ed25519 over SHA-256, canonicalized under RFC 8785—and does not submit it as verification input. A valid signature establishes integrity and signer identity for the fields shown; it does not establish completeness, safety, or compliance.

Why teams point agents at us

Not another log. Evidence.

EVIDENCE

End the finger-pointing.

When an agent does something wrong, "we think it was the model" is not an answer. A Glacis record links the governed action, the intended rule, and the control decision in a signed, hash-chained artifact. An outside party can verify its integrity while still examining coverage, configuration, key custody, and whether the control was appropriate.

ISOLATION

Choose a private transport path for the governed workflow.

A dedicated per-tenant arbiter can be reached over WireGuard, Twingate ZTNA, or AWS PrivateLink, depending on configuration. The transport and payload boundary must be assessed for the actual deployment.

SPEED

Start with one bounded workflow.

Start by mapping one workflow to the supported integration path and confirming the network, identity, and control configuration. The meter is the signed-receipt count — the same operational unit the Console records — so usage stays legible as a workflow moves into production.

Private WAN · Assurance ladder

Private transport, with an explicit boundary.

GLACIS Managed can provide a dedicated per-tenant arbiter reached over WireGuard, Twingate ZTNA, or AWS PrivateLink. That can reduce public routing and multi-tenant mixing, but the exact network path depends on the selected transport and surrounding customer architecture.

The honest boundary: Managed means Glacis operates the arbiter. Dedicated infrastructure and private transport are evidence about isolation and routing; they are not proof that an operator cannot access payloads. Stronger confidentiality claims require additional controls and their own evidence.

RungThe claimHow you check it
Managed Operational isolation. Private WAN, dedicated per-tenant instance. Receipts + the connector config you control
+ Nitro Enclave-backed. Hardware attestation can identify the enclave image and configuration that ran. Check the attestation document and its stated measurements
PrivateLink / your VPC PrivateLink can keep configured service traffic on AWS network paths; a customer-VPC deployment can keep the configured data plane inside the account, subject to actual routing and surrounding services. Your own VPC console
Self-hosted / airgap The data plane can remain within the customer-operated boundary. Inspect your host, routing, and deployment configuration

Each rung makes a different claim. The supporting evidence and exclusions should travel with it.

Pricing

One commercial path from exploration to production.

Start free. Move a live workflow to Production at $995 a month billed annually, or talk to us about a consequential Enterprise deployment.

TierPriceWhat you getReceipt meter
Explore Free · no card Prove the integration works with the hosted workspace or self-hosted SDK. 1,000 / month
Production $995/mo · billed annually A dedicated arbiter, 12-month retention, independent witnessing, evidence packs, and an onboarding working session for the first workflow. 1,000,000 / month, then $5 / 10,000
Enterprise from $36k/yr Private connectivity, customer-environment deployment, extended retention, named support, and an SLA. By agreement

One meter: signed receipts. No seats, agent counts, or token arithmetic. The canonical allowances and billing options live on /pricing.

See pricing, billing & FAQ →

Design partners

Design partnerships.

Design partnerships are scoped case by case. Ask whether one is currently available and what evidence, permissions, and working boundaries would apply.

Managed deployment

Start with one consequential AI workflow.

Show us the action the AI can take and the rule that matters. We will map the managed deployment, private connectivity, and operational evidence your reviewers need.

Private deployment · regulated workflows · evidence an outside party can verify