What are our agents permitted to do?
Rules are configured per project and visible in one place, with every change written to a rule audit log.
Once an agent can move money, touch customer data, or speak on your behalf, the question stops being whether it works and becomes whether you can prove what it did.
1,284,410
Realtime Tool Calls Evaluated
Treasury-Reconciler
wire_transfer_execute
HR-Talent-Bot
export_pii_s3
SHA-256: 9f4c1ab...[VALIDATED_CHAIN]
Rules are configured per project and visible in one place, with every change written to a rule audit log.
Every intercepted action is recorded with its input, the rule evaluated, the verdict, and the timestamp.
Records are hash-chained. Compliance reports export mapped to the specific article or control they satisfy.
| Capability | Detail |
|---|---|
| Deployment choice | Gateplex Cloud, VPC and Docker Edition inside your AWS or Azure environment, or a self-contained on-premises install. |
| Data residency | EU, US, UK, or GCC and MENA. Data remains within the configured region. |
| Enterprise SSO | SAML and OIDC, including Okta, Microsoft Entra ID, and Google Workspace. |
| Human approval workflow | Held actions routed to named reviewers, with reviewer identity derived server side. |
| Compliance packs | EU AI Act Article 12, HIPAA Safety, and Financial Services rule sets, tailored during onboarding. |
| Evidence and reporting | Hash-chained audit trail, rule change history, and exportable compliance reports. |
| Procurement support | Security posture documentation under NDA, DPA on request, and architecture review with our team. |
For institutions that cannot let agent payloads leave their perimeter, Gateplex runs entirely inside your environment. Policy synchronisation uses an encrypted, outbound-only channel. Agent payloads, audit records, and governance decisions stay where your regulator expects them.
Two USPTO provisional patents are pending, covering the interception and audit mechanism and the split-plane VPC architecture.
Many institutions begin with a fixed-fee, 30-day Shadow Compliance Audit: passive observation, no enforcement, no code changes, and a signed report of what would have been blocked, flagged, or held.