Company

About Turrigan

Turrigan is an AI governance and assurance platform for production AI systems and AI agents. It sits inline between an AI system and the people or systems it affects. Every model output and every proposed agent tool call is submitted to one HTTP endpoint that returns allow, block, or escalate in milliseconds, screened by a deterministic core with no LLM in the hot path. Every decision is recorded as tamper-evident evidence mapped to the EU AI Act, NIST AI RMF and ISO/IEC 42001.

The company

Brand and platform
Turrigan
Legal entity
8plus2 Omnitech OPC Private Limited
Founded
2026
Founder
Ratish Kumar
Headquarters
Dombivali, Thane, Maharashtra, India
Category
AI governance, AI assurance, AI security
Website
turrigan.com
Console
app.turrigan.com
API
api.turrigan.com
Sales
pilotturrigan.com
Support
supportturrigan.com

What Turrigan does

AI systems stopped only answering and started acting. Assistants file tickets, move money and message citizens. Agents call tools on their own. Each of those is a decision an organization owns, whether or not anyone saw it happen. At the same time the EU AI Act, NIST AI RMF and ISO/IEC 42001 all ask the same question: show how each decision was controlled.

Turrigan answers that question with a chokepoint rather than a dashboard. One HTTP call, POST /v1/govern, is placed in the path an organization already controls, before an output reaches a user or before an agent executes a tool call. A deterministic detector floor screens for leaked personal data, fabricated citations, prompt injection, unsafe content, excessive agency and coverage gaps. Critical findings block. Uncertainty escalates to a human. The floor fails closed rather than open. Every verdict lands in an append-only, hash-chained log that is redacted, explainable and mapped to the exact control it satisfies, so tampering is mathematically detectable.

What is being enforced is inspectable rather than implied. The detectors, the frameworks and the controls they map to are held as versioned data rather than buried in code, and the console lists them, so an auditor or a platform owner can see which checks exist, which version ran, and which control each one is claimed to satisfy.

The three products

The platform governs what AI says and does. Guard governs what goes into it. Together they bracket the interaction.

Guardrails, governance, assurance

These three words are used interchangeably across this market, and they should not be. We use them precisely:

Most tools in this market do the first. Turrigan does all three at one chokepoint: a deterministic guardrail floor, a governance decision that returns allow, block or escalate, and a tamper-evident evidence record behind every verdict.

Where Turrigan runs

Managed cloud on an isolated tenant, bring-your-own-database where the decision log lives in a datastore you host and own, or fully air-gapped on-premises with customer-managed keys and crypto-shredding. The deterministic core needs no external AI service in the decision path, which is what makes the air-gapped and sovereign deployments possible rather than aspirational.

A deployment is either single-tenant on SQLite, which is the sovereign zero-egress shape, or multi-tenant on PostgreSQL. The decision log itself is scoped centrally: one hook in the data layer filters every read of a decision or a decision event by organization, so an individual query cannot forget to. The control-plane tables around it, such as users, keys, baselines and legal holds, filter by organization explicitly at each query site, and a test enumerates every one of them, so a new table cannot be added without that being a deliberate and recorded choice. A tenant may also register its own client-hosted database, so the decision log is physically separate; if that datastore is unreachable, governance fails closed rather than quietly continuing.

The console can be white-labelled per deployment. An owner sets the product name, accent colour, logo and favicon from a separate control plane, so a partner or an internal platform team can run Turrigan under its own name. Verdict colours are deliberately excluded from that theming: allow, block and escalate must mean the same thing in every deployment.

What we deliberately do not claim

Turrigan does not make an organization compliant. No tool can. Compliance is an organizational outcome that depends on your own quality management system, risk process and governance. What Turrigan produces is the per-decision evidence and enforced controls that make a compliance case provable instead of aspirational, including a live conformity posture that reports which controls are covered, which are not, and which belong to you as the deployer.

Turrigan does not certify fairness. Disparate-impact screening surfaces signals worth investigating, at population level, and is honest about its limits.

The evidence infrastructure has passed an independent technical review of its integrity, tenancy isolation and data protection, alongside adversarial reviews across the detector floor. Our EU AI Act conformity work has been assessed internally, against our own published audit scope. Formal notified-body certification is a separate, later step, and we will not pretend otherwise. An assurance layer that inflates its own coverage is worse than none.

Turrigan elsewhere

Pilot Turrigan on your real AI traffic