AI governance & assurance

Your AI makes decisions.
Turrigan makes them defensible.

An inline governance layer for production AI systems and AI agents. Every model output and every proposed agent action returns allow, block, or escalate in milliseconds, and leaves evidence an auditor can verify years later.

Deterministic core. No LLM in the hot path, so verdicts cost milliseconds and never vary. Runs air-gapped with no external AI service in the decision path.

Your application a model output, or an agent tool call POST /v1/govern Deterministic floor personal data prompt injection unverifiable claims unsafe content excessive agency uncertainty no LLM in the hot path allow authorised to deliver block not authorised escalate held for a human Hash-chained evidence every verdict, redacted, explainable, mapped to the control it satisfies verified

Turrigan authorises the decision. Your code delivers the output or executes the action. It is a control point, never a runtime.

Three verdicts

Two would not be enough.

A system forced to answer either yes or no has to guess on the uncertain cases, and half of those guesses are wrong in the direction that matters.

allow

Nothing critical found. The output is delivered, and the decision is still recorded, so your clean traffic becomes evidence too.

block

A critical finding. Turrigan withholds authorisation, so your code does not deliver it, and what gets stored is redacted before it is written to the chain.

escalate

The floor could not settle it, so a human decides with the reason attached. It fails closed, never open.

Adoption

One HTTP call, in a path you already control.

Keep your models, your vendors and your stack. Nothing is proxied and nothing is rewritten. You add a call before the output ships, and you honour what comes back.

Scoped, expiring, revocable keys. Per-tenant rate isolation, so one caller can never degrade another.

POST /v1/govern14 ms
verdictblock
the AI said"The policy holder is A. Rashid, card 4111 1111 1111 1111."
deliveredfalse
controlseu-ai-act:art-10, art-12
stored as"card [REDACTED:CREDIT_CARD] is on file"

Evidence

The audit that takes weeks becomes an export that takes seconds.

Ask any AI vendor how they will support your next audit. Then ask them to prove a log entry was never edited.

Controls that belong to your own quality management system are reported as yours, not claimed by the tool.

Conformity postureexample · eu-ai-act : 2024-1689
  • Art. 9Risk managementdeployern/a
  • Art. 10Data governancecovered11
  • Art. 12Record-keepingcovered9
  • Art. 13Transparencycoveredn/a
  • Art. 14Human oversightcovered2
  • Art. 15Accuracy & robustnesscovered5
  • Art. 50Content markingcoveredn/a
chain verified · 44 entries · no breaks detected

Deployment

Runs where your data is allowed to live.

Managed cloud

Your tenant, your keys, your encrypted data, our operations. Physical database isolation available per tenant.

Your database

The decision log lives in a datastore you host and own. Walk away with the evidence any day.

Air-gapped

The deterministic floor needs no external AI service at all, so it runs fully offline with customer-managed keys.

What is Turrigan?

Turrigan is an AI governance and assurance platform for production AI systems and AI agents. It sits inline between an AI system and the people or systems it affects: every model output and every proposed agent tool call is submitted to one HTTP endpoint that returns allow, block, or escalate in milliseconds, and every decision is recorded as tamper-evident evidence mapped to the EU AI Act, NIST AI RMF and ISO/IEC 42001.

What is the difference between AI guardrails and AI governance?

A guardrail filters or constrains AI behaviour. Governance decides what behaviour is permitted in the first place, on a policy an organisation owns. Assurance proves afterwards what happened and why, in a form an auditor can verify. Most tools in this market do the first. Turrigan does all three at one chokepoint: a deterministic guardrail floor, a governance decision that returns allow, block or escalate, and a tamper-evident evidence record behind every verdict.

What is Turrigan Guard?

Turrigan Guard is Turrigan's browser extension for the input side. It checks a prompt on the user's own device the moment they press Send in ChatGPT, Claude, Gemini or Microsoft Copilot, and pauses it for review if it contains personal data. The Personal edition is free and has no network permission at all. The Enterprise edition adds a masked, minimised audit record in the organisation's own Turrigan tenant. The platform governs AI outputs, Guard governs AI inputs, and together they bracket the interaction.

Where can Turrigan run?

Three ways. Managed cloud on an isolated tenant, bring-your-own-database where the decision log lives in an organisation's own datastore, or fully air-gapped on-premises. The deterministic core needs no external AI service in the decision path, which is what makes the air-gapped and sovereign deployments possible.

Does Turrigan make my organisation compliant with the EU AI Act?

No, and no tool can. Compliance is an organisational outcome that depends on your own quality management system, risk process and governance. What Turrigan produces is the per-decision evidence and enforced controls that make a compliance case provable rather than aspirational, including a live conformity posture that reports which controls are covered, which are not, and which belong to you as the deployer.

Pilot

Put Turrigan on your real AI traffic.

A free, time-boxed pilot on a dedicated, isolated tenant. Your data in a database that can be handed to you or cryptographically shredded when it ends. You keep the evidence either way.

We do not claim to make you compliant, and we do not certify fairness. An assurance layer that inflates its own coverage is worse than none, so every posture reported here is one an independent auditor can reproduce.