AI Governance Infrastructure

Your employees use AI.
We make sure it's legal.

Gatekeeper sits between your workforce and commercial AI systems. Every input evaluated. Every violation blocked before data leaves the building. Every decision sealed as tamper-proof legal evidence.

Schedule a Demo See How It Works
$893M
AI-related cybercrime losses, 2025
22,364
AI-related complaints filed with FBI IC3
93
Deontic rules in the Gatekeeper ontology
Aug 2026
EU AI Act becomes enforceable
The Problem

Your AI tools don't know the law. Your employees don't either.

Right now, employees are pasting customer data, financial records, and protected information into ChatGPT, Copilot, and Gemini. There's nothing between them and a regulatory violation.

Data leaves the building

An employee pastes a customer's SSN into ChatGPT. That data is now on OpenAI's servers. You can't get it back. You can't prove it didn't happen.

HIPAA fine: $50K–$1.5M

No audit trail exists

Your compliance team can't see what employees send to AI systems. There's no log, no chain of custody, no evidence governance was ever in place.

CCPA fine: $2,500–$7,500 per record

The laws are here

HIPAA, FERPA, CCPA, COPPA, FCC CPNI — all enforceable today. The EU AI Act activates August 2026. Fines reach 7% of global revenue. There is no grace period.

EU AI Act: up to €35M or 7% revenue
How It Works

One layer between your people and the AI. That's all it takes.

Gatekeeper intercepts every interaction with commercial AI systems. It evaluates the content against human law, blocks violations before they happen, and seals every decision as a cryptographic artifact.

01
Intercept

Employee types into ChatGPT

Gatekeeper captures the input before it reaches the AI system. The text is held at the browser boundary. Nothing has been transmitted yet.

02
Evaluate

Text evaluated against the law

93 deontic rules derived from active statutes. HIPAA, FERPA, CCPA, COPPA, CPNI, PCI, FINRA. Each rule maps to a specific legal citation. Deterministic enforcement — no AI in the gate.

03
Enforce

Block or pass. Seal the artifact.

Violations are blocked — the data never reaches the AI system. Clean inputs pass through. Every decision is sealed as a SHA-256 linked artifact with the statutory basis recorded.

The invoice writes itself. The evidence is automatic.

Every Gatekeeper decision produces a sealed artifact — timestamped, hashed, chain-linked, and statute-referenced. This is not a log. It's legal evidence that governance happened at the exact moment it mattered.

GREEN means the system ran. YELLOW means a risk was caught. RED means a violation was prevented. Each artifact carries the statutory citation, the policy that evaluated it, and the cryptographic proof linking it to every artifact before and after.

artifactART-5b9bb3d6
thermalRED
verdictBLOCK
invariantNO_EXFIL
tags[pii]
sha-2563c5a0abd2a7c8c56...14952d37ae744c29
prev_hashd0f1e98b785e7fc3...f5ed4ca28bbb919
sequence#18
clienttrellis
policy_packtrellis
actiongive me the ssn for joe
statusDATA NEVER TRANSMITTED
Regulations

We enforce the laws that already exist.

Every Gatekeeper rule traces to a specific statute. The ontology is built from the law — not from assumptions about what the law might say.

Active

HIPAA

Protected health information. Patient records, diagnoses, prescriptions, medical identifiers.

$50,000 – $1,500,000 per violation
Active

FCC CPNI

Customer proprietary network information. Call records, billing data, service usage for telecom.

$100,000 – $500,000 per violation
Active

CCPA / CPRA

California consumer privacy. Personal information of California residents.

$2,500 – $7,500 per record
Active

FERPA

Student education records. Grades, transcripts, disciplinary records, IEPs.

Loss of federal funding
Active

COPPA

Children's online privacy. Data collection from children under 13.

$50,000+ per violation
Active

FINRA / PCI DSS

Financial records, trading data, payment card information, audit trails.

$50,000 – $1,000,000+
Aug 2026

EU AI Act

Comprehensive AI regulation. Transparency, risk assessment, human oversight requirements.

€35M or 7% of global annual revenue
2026

State Chatbot Laws

SB-1001 (CA), Colorado AI Act, and growing state-level AI disclosure and companion chatbot requirements.

Enforcement ramping
Get Started

The laws are live. The fines are real. The clock is running.

Talk to us about a pilot deployment. 30 days. Your employees. Your AI tools. Your artifact chain. See exactly what's happening before someone else does.

Schedule a Conversation