AI governance · Early access
Stop your AI from saying what it can’t back up — and prove it.
Other platforms stop an agent from doing the wrong thing. ZTZK also stops a system from asserting something it can’t substantiate — and turns what it declined to answer into a signed, auditable record your risk officer, auditor or examiner can check.
The gap
Governing what AI does isn’t the same as governing what it says.
AI governance tools split in two. One half writes the policy down. The other half stops an agent from taking the wrong action, then forgets. Neither governs the claims your AI makes to a customer. ZTZK does — and keeps the receipt.
- Policies, inventories and reports
- Nothing stops a developer calling the model directly
- Evidence is a document you vouch for
- Inline checks on each request
- No mapping to compliance frameworks
- No auditable record of what was enforced, when
- Enforces policy on every call
- Maps each rule to the controls it satisfies
- Blocks claims it can’t substantiate — and records what it declined to say
- Signs every decision to a ledger anyone can verify
What it covers
Frameworks for the auditor. Rules for the runtime.
Model risk management
Prove the approved model — the exact version you validated — produced each decision. Model-risk evidence for SR 26-2 / OCC 2026-13, for banks and their fintech partners.
ISO/IEC 42001
The AI management system standard as 33 checkable controls — on the same ledger as your SOC 2, HIPAA and ISO 27001 evidence.
Runtime enforcement
Rules that run on every call.
Start from ready-made rules or write your own. Each one runs as the request happens, blocks what it should, and leaves a signed record either way.
- RequestYour AI drafts a response
- CheckRules run on the callReady-made or your own
- DecideAllowedSent to the userBlocked or declinedWith the reason recorded
- RecordDecision signedTamper-evident ledger
- VerifyChecked independentlyBy your auditor or examiner
- PII leakage
- Stop personal data from leaving in a response.
- AI disclosure
- Make sure users know when they’re talking to an AI, and label generated content.
- Bias
- Flag and block outputs that treat protected groups differently.
- Medical and financial advice
- Keep regulated advice inside the lines you set.
- Content safety
- Block harmful or prohibited content before it ships.
- Internal information
- Keep confidential material out of external answers.
- Production access
- Stop agents from touching production systems they shouldn’t.
- Data residency
- Keep data processing in the regions you’ve committed to.
- Hallucination
- Catch answers that go beyond the evidence behind them.
- Agent boundaries
- Limit what autonomous agents are allowed to do.
- Brand
- Keep responses consistent with how you speak to customers.
- Your own rules
- Write any rule for any AI in Contract Studio, with human review before it goes live.
Proof-of-Ignorance · Demo
Prove your AI knew when it didn’t know.
The riskiest AI answer is a confident one with nothing behind it. Proof-of-Ignorance measures how far a question sits from the evidence the model is grounded in. When it’s too far, the model refuses — and ZTZK proves the distance was measured honestly. You get a certificate that states what was proven and what was inferred, and the enforcement fires on the proven part.
Not “we think it’s grounded.” Proof that it was.
One ledger, two audit stories
The same proof your auditor already checks.
“Were you HIPAA compliant on June 30?” and “Did your AI stay inside its policy on every call?” are answered by the same signed ledger and checked with the same verifier. Start with compliance; add AI governance the day you ship your first AI feature — no second vendor review.
FAQ
AI governance questions, answered
How is ZTZK different from an AI governance platform?
Governance platforms document your AI policies and use cases. ZTZK enforces the policy on every call and signs a proof of what was enforced, so you can show a risk officer or examiner what actually happened — not just what the policy said.
How is it different from an AI guardrail?
Guardrails check requests inline but leave no auditable record. ZTZK enforces the rule and writes a signed, tamper-evident entry to a ledger, mapped to the framework controls it satisfies.
Does enforcement add model calls to every request?
No. Rules are evaluated as contracts, not by calling another model, so enforcement doesn’t add tokens to your requests.
Which models does it work with?
Any. Rules evaluate what goes into and comes out of the model, so they apply whether you use a hosted API, an open-weight model or your own.
What happens when the AI can’t back up an answer?
It declines, and ZTZK records the declined assertion as a signed entry. You can show a customer or examiner not only what your AI said, but what it refused to claim.
Is this production-ready?
AI governance is in early access. We share exactly what is verified and what is still open before you commit, and we onboard a small number of teams at a time.
Request access
See your AI policy enforced — and proven.
AI governance is in early access with a small number of teams. Tell us what your AI does and who needs to trust it, and we'll show you the demo.
We use your email only to reply to your request. Privacy policy
✓ Request received. We'll be in touch.