AI governance · Early access

Stop your AI from saying what it can’t back up — and prove it.

Other platforms stop an agent from doing the wrong thing. ZTZK also stops a system from asserting something it can’t substantiate — and turns what it declined to answer into a signed, auditable record your risk officer, auditor or examiner can check.

The gap

Governing what AI does isn’t the same as governing what it says.

AI governance tools split in two. One half writes the policy down. The other half stops an agent from taking the wrong action, then forgets. Neither governs the claims your AI makes to a customer. ZTZK does — and keeps the receipt.

Governance platforms
  • Policies, inventories and reports
  • Nothing stops a developer calling the model directly
  • Evidence is a document you vouch for
Runtime guardrails
  • Inline checks on each request
  • No mapping to compliance frameworks
  • No auditable record of what was enforced, when
ZTZK
  • Enforces policy on every call
  • Maps each rule to the controls it satisfies
  • Blocks claims it can’t substantiate — and records what it declined to say
  • Signs every decision to a ledger anyone can verify

What it covers

Frameworks for the auditor. Rules for the runtime.

Early access

Model risk management

Prove the approved model — the exact version you validated — produced each decision. Model-risk evidence for SR 26-2 / OCC 2026-13, for banks and their fintech partners.

Early access

ISO/IEC 42001

The AI management system standard as 33 checkable controls — on the same ledger as your SOC 2, HIPAA and ISO 27001 evidence.

Runtime enforcement

Rules that run on every call.

Start from ready-made rules or write your own. Each one runs as the request happens, blocks what it should, and leaves a signed record either way.

  1. RequestYour AI drafts a response
  2. CheckRules run on the callReady-made or your own
  3. Decide
    AllowedSent to the user
    Blocked or declinedWith the reason recorded
  4. RecordDecision signedTamper-evident ledger
  5. VerifyChecked independentlyBy your auditor or examiner
PII leakage
Stop personal data from leaving in a response.
AI disclosure
Make sure users know when they’re talking to an AI, and label generated content.
Bias
Flag and block outputs that treat protected groups differently.
Medical and financial advice
Keep regulated advice inside the lines you set.
Content safety
Block harmful or prohibited content before it ships.
Internal information
Keep confidential material out of external answers.
Production access
Stop agents from touching production systems they shouldn’t.
Data residency
Keep data processing in the regions you’ve committed to.
Hallucination
Catch answers that go beyond the evidence behind them.
Agent boundaries
Limit what autonomous agents are allowed to do.
Brand
Keep responses consistent with how you speak to customers.
Your own rules
Write any rule for any AI in Contract Studio, with human review before it goes live.

Proof-of-Ignorance · Demo

Prove your AI knew when it didn’t know.

The riskiest AI answer is a confident one with nothing behind it. Proof-of-Ignorance measures how far a question sits from the evidence the model is grounded in. When it’s too far, the model refuses — and ZTZK proves the distance was measured honestly. You get a certificate that states what was proven and what was inferred, and the enforcement fires on the proven part.

Not “we think it’s grounded.” Proof that it was.

Request a demo

One ledger, two audit stories

The same proof your auditor already checks.

“Were you HIPAA compliant on June 30?” and “Did your AI stay inside its policy on every call?” are answered by the same signed ledger and checked with the same verifier. Start with compliance; add AI governance the day you ship your first AI feature — no second vendor review.

Compliance.SOC 2, HIPAA, ISO 27001, BSA/AML — early access.
AI governance.Enforcement, model risk, ISO/IEC 42001 — early access.

FAQ

AI governance questions, answered

How is ZTZK different from an AI governance platform?

Governance platforms document your AI policies and use cases. ZTZK enforces the policy on every call and signs a proof of what was enforced, so you can show a risk officer or examiner what actually happened — not just what the policy said.

How is it different from an AI guardrail?

Guardrails check requests inline but leave no auditable record. ZTZK enforces the rule and writes a signed, tamper-evident entry to a ledger, mapped to the framework controls it satisfies.

Does enforcement add model calls to every request?

No. Rules are evaluated as contracts, not by calling another model, so enforcement doesn’t add tokens to your requests.

Which models does it work with?

Any. Rules evaluate what goes into and comes out of the model, so they apply whether you use a hosted API, an open-weight model or your own.

What happens when the AI can’t back up an answer?

It declines, and ZTZK records the declined assertion as a signed entry. You can show a customer or examiner not only what your AI said, but what it refused to claim.

Is this production-ready?

AI governance is in early access. We share exactly what is verified and what is still open before you commit, and we onboard a small number of teams at a time.

Request access

See your AI policy enforced — and proven.

AI governance is in early access with a small number of teams. Tell us what your AI does and who needs to trust it, and we'll show you the demo.

We use your email only to reply to your request. Privacy policy

✓ Request received. We'll be in touch.