AI Governance Platform
Turn AI policy into decisions your agents cannot skip.
A written AI policy does not stop a model call. InferenceFort turns it into rules that run inside every governed application: which models, which data, which destinations, which tools, how much spend. Every decision is recorded.
From policy document to enforcement
| Your policy says | InferenceFort enforces |
|---|---|
| Only approved models may be used | Model-access policy. Once policy is loaded, anything not allowed is denied. |
| Customer data stays in the EU | Egress pins providers to approved endpoints or regions such as region:eu-*, blocked before the prompt leaves. |
| No secrets or national IDs in prompts | Content rules block or flag; PHI redaction replaces identifiers before the model sees them. |
| Agents may not delete data or email outsiders | Blocked tools, approval-required tools, MCP server allow-lists and the lethal-trifecta guard. |
| Teams stay within their AI budget | Daily spend caps checked against a shared ledger before the call runs. |
| We can show who did what | Every decision attributed to user, agent and customer, with a full audit trail and SIEM forwarding. |
Central policy, local enforcement
Policies are edited once and shipped to every SDK as a versioned bundle. Each process caches the bundle and refreshes it on a server-controlled schedule, five minutes by default, with an inexpensive unchanged check. A policy change reaches running agents without a redeploy, and decisions keep working from the cached bundle if the control plane is briefly unreachable.
Per-agent policy files can sit alongside central policy. Either layer can tighten a restriction, so a local file cannot quietly relax what the security team set.
One agent, many customers
A single agent process often serves many end customers. Pin a process to a customer and its policies, rules and provider credentials come from that customer's effective bundle. Session state is always kept per customer and conversation, so one tenant's activity never affects another tenant's verdicts.
Know which agents you have
Multi-agent systems built with CrewAI or LangGraph register their agents and wiring at launch, before any traffic, so the inventory is complete on day one. Agents that appear at runtime are added from observed activity and labelled, so the inventory reflects what actually runs rather than what was declared.
Start from real traffic, not a blank editor
- Create a starter policy with
if-policy init, setenforcement_modetomonitor, and log decisions to a local file. - Run your application as normal.
if-policy learn audit.ndjsonproposes allow-lists of the models, endpoints and MCP servers you actually used.if-policy validateboots the real engine against the file, so valid means enforceable.- Review, then switch to
enforce.
Governance you can inspect
- Scanned scopes: every verdict lists which content was screened, so the trail never implies a check that did not run.
- Capability gaps: controls that could not run, such as a misconfigured detector, are reported instead of silently skipped.
- Versioned detection: each detector finding records the version of the detection instructions that produced it.
- Your tools stay in charge: forward decisions to your SIEM, use your own detectors, and bring your own classifier models.
Frequently asked questions
Is user identity required?
No. Unattributed calls are still enforced and audited. Deployments built on per-user attribution can require identity, and calls without it are then blocked and audited.
Can we run it without a hosted service?
Yes. A policy file enforces static policy with no network calls. Session-based detection, shared budgets, the hosted audit trail and live policy changes need a control plane, hosted or self-hosted.
Does it replace our existing security tools?
No. It enforces at the application layer and works with your SIEM, your detectors and your network egress controls.
Keep reading
Map your governance requirements
Bring one agent workflow, the data it touches, and the actions you need to control. As a design partner, you shape the evaluation and review the policy decisions with our engineers.
Become a design partner →