Governance runtime for AI agents

Autonomy, under oath.

Your agents are already acting. EcoCloud is the runtime that governs every action — checked against your constitution, signed, audit-chained, and reversible. Before it happens.

57
Governance kernels
ES256
Every action signed
~2ms
Per decision
constitution · pass
signed & chained
block #4,182
Scroll
Constitution enforced • ES256 signed • Audit chained • Actions reversible • Deterministic kernels • Human four-eyes Constitution enforced • ES256 signed • Audit chained • Actions reversible • Deterministic kernels • Human four-eyes

Agents are
shipping. Nothing
is checking them.

Every team is handing real work to autonomous agents. But an LLM is trained to be helpful — not to be governed. One injected web page, one over-broad tool call, one silent failure mid-workflow, and the damage is already done.

Ungoverned
  • Policy lives in the prompt — which the next input can override.
  • No signed record of what ran, when, or why.
  • A failure on step four leaves three systems out of sync.
  • Compliance means exporting the whole database and hoping.
On EcoCloud
  • Policy lives at the action layer — enforced before the tool call executes.
  • Every action is notarized — ES256-signed and hash-chained.
  • Failures self-heal — a saga planner unwinds the steps in order.
  • Compliance is a signed receipt — verifiable without the raw data.
Where you start

Governance is a ladder,
not a feature you buy.

You don’t need 84 primitives on day one. You start with a signed record of what your agents already do — and climb one rung at a time, as you earn trust in the gate.

1
Stage 01 · Recorded

A record nobody can quietly edit.

Every agent action mints an ES256-signed receipt, hash-chained to the last. Not a log line someone can rewrite — a cryptographic record of what happened, in order.

What it proves: “this event happened, in this sequence, and hasn’t been altered since.” The floor every serious deployment starts on.

2
Stage 02 · Enforced

Policy checked before the action runs.

A machine-readable constitution gates every tool call — allow, stage for a human, or deny. Identity is scoped, high-risk actions are reversible, and inputs are screened for injection.

What it proves: “this couldn’t have happened outside policy — the gate was in the path, not a dashboard watching from the side.”

3
Stage 03 · Provable

Verify it yourself — zero trust.

Anyone can check integrity offline, against a public key, with no access to our servers or database — and confirm one component without seeing the rest.

What it proves: “verify this yourself — you don’t have to take our word, or even query our systems.”

4
Stage 04 · Continuous & cross-org

Watched, and it holds across org lines.

Assurance doesn’t stop at deployment or your org chart — anomalies are watched continuously, obligations net across parties, and two organizations’ policies compose without either loosening.

What it proves: “this isn’t a point-in-time attestation — it’s watched, and it survives a second party’s policy in the mix.”

Score your workspace → Stages 1–2 score automatically from your live config. Most teams start at Stage 1 — a signed record of what already happens.
Proof, not promises

We don’t ask for
trust. We sign for it.

No logos to flash yet — just receipts anyone can verify. Governance you can prove is the only kind that scales to machines.

57
Deterministic
governance kernels
100%
Reproducible —
same input, same proof
~2ms
Per decision at
the edge
ES256
Signed & hash-chained,
offline-verifiable

Every claim above is measured or open-source — verify it yourself.

The governed loop

Six steps
between intent
and outcome.

01

Parse

Plain intent becomes a structured, typed action — owner, deadline, risk band and scope resolved before anything runs.
02

Constitution

The action is checked against your workspace rules. Out of bounds? It’s denied or staged for a human — never silently executed.
03

Route

The runtime picks the model or connector by capability, cost and privacy — with the cheapest safe option that clears policy.
04

Sign

The result is sealed with an ES256 signature and linked to the previous block — a tamper-evident chain of everything that happened.
05

Receipt

A compact, verifiable receipt is issued. Auditors confirm conformance without ever touching the sensitive payload.
06

Undo

Anything can be reversed. A saga planner computes the compensations and rolls dependent systems back, in order.
Step 01 — Intake
01
Parse
Start free

Priced for the work,
not the seat.

Full governance on every tier — the difference is scale. Bring your own model key, or use ours.

Solo
For one operator running their first governed agents.
$0
  • Full constitution & audit chain
  • 25 AI dispatches / month
  • Signed outcome receipts
  • All 57 kernels, client-side
Start free
Most teams
Pro
For teams putting agents on real, revenue-bearing work.
$12 / seat · mo
  • Unlimited AI dispatch
  • Team roles, four-eyes & delegation
  • 26 governed connectors
  • Bring-your-own model key
Start free, upgrade later
Enterprise
Outcome-priced governance for regulated operations.
Let’s talk
  • Custom constitution authoring
  • SSO / SAML & audit exports
  • Continuous compliance feed
  • On-prem kernel deployment
Book a walkthrough
Ship autonomy you can defend

Let the agents
run. Keep control.

Give your agents a conscience — enforced, signed, and reversible. Set up your first governed workspace in minutes.