web stats

Your AI. Your infrastructure. Your governance.

We help organizations build and run AI agents they can trust with real work. SAFi governs the agent's reasoning and actions at runtime, enforcing defined boundaries and leaving an immutable audit record behind. We deploy the agents directly in your environment, so you retain control of your AI, infrastructure, and data.

Operated by the framework's creator, with more than two decades of enterprise IT infrastructure experience.

  • Your Infrastructure
  • Your Data
  • Your AI Model API Keys
  • Your Governance Records

RunSAFi Engine

Operates & Monitors

Your Secure Environment

Infrastructure
Data
Model Keys
Audit Records

We bring the tech. You bring your resources and use cases.

We run governed agents that make legal and compliance teams smile.

We help you build and run AI without regulatory anxiety. SAFi enforces your corporate policies in real time, preventing unauthorized actions before they happen, and backs every single decision with an immutable audit trail that holds up under review.

Immutable Audit Records

Hash-chained trails of every turn and tool call provide tamper-proof evidence. This architecture directly supports SEC 17a-4 and FINRA 3110 recordkeeping requirements and ISO 42001 evidence generation.

Regulatory Readiness

SAFi provides controls to support HIPAA-ready deployments, including configurable BAA-capable provider routing, application-layer encryption, and TLS. It also supports EU AI Act transparency requirements with automated Article 50 disclosures and machine-readable AI-generated content marking. Compliance depends on your deployment, configuration, contracts, and operating procedures.

Self-Hosted Data Sovereignty

Your charter, policies, and audit trail stay securely in your own database and environment. SAFi only connects externally to the model providers you choose.

For environments requiring the highest level of data control, SAFi can run with locally hosted AI models, keeping inference within your infrastructure.

Need help setting it up? We can help you deploy the hardware and local models too.

Zero Vendor Lock-In

Everything we build, you own 100%. If you ever decide to take over operations, simply revoke our server access. Everything continues running as usual with no license expirations.

Enterprise Security & Controls

Concrete guardrails that plug directly into your existing security stack.

Identity & Access

Enterprise-grade authentication featuring OIDC single sign-on for Microsoft Entra and Google Workspace, SCIM 2.0 provisioning, and strict four-role RBAC enforcement.

Sensitive Data Blocking

Deterministic pre-flight blocking of payment cards, IBANs, ABA routing numbers, and SSNs. Identifiers are refused before they ever reach a language model.

Cryptographic Verification

Every deployment features an automatic cryptographic verification mechanism. Administrators can independently verify the installation's integrity directly from the organization settings at any time.

How it works

We deploy and configure the governed agents for your use case. Once live, we handle all ongoing maintenance and updates so your agents stay secure and current without adding to your team's workload.

What we do

  • Deployment: Install a published, integrity-verified SAFi release onto a Linux machine directly in your environment.
  • Setup & Configuration: Secure your deployment at your own domain over HTTPS and perform the initial configuration with default agents.
  • SSO Integration: Work with your IT team or MSP to integrate your identity provider, restrict access to valid company directories, and enforce MFA.
  • MCP Server Configuration: Install and configure MCP servers to securely grant your agents access to specific internal tools.
  • Custom Agent Development: Build specialized, strictly governed agents tailored to your specific business use cases and workflows.
  • Backups & Disaster Recovery: Manage routine backups, execute tested restores, and provide DR/BCP documentation aligned with your organizational policies.
  • Training & Handoff: Train your IT team on the system architecture so they can confidently take over the operator role whenever you are ready.

What you do

  • Define the Policies: You provide the charter and business-unit policies that govern your agents' behavior.
  • Bring Your Own Keys: You secure the API keys directly from your chosen AI provider, ensuring your enterprise agreement guarantees your data will not be used for model training.
  • Provision the Infrastructure: You provide the environment (a Linux VM, bare metal server, or cloud instance) sized to our hardware specifications.
  • Design Approval Workflows: You determine the internal chain of command for approving new policies, editing tool access, and authorizing agent capabilities.
  • Control Our Access: You issue, audit, and restrict the administrative access we need to maintain the system, which you can revoke at any time.
  • Manage Internal Communications: Your internal team handles organizational rollouts, training announcements, and user adoption.

How we charge

Hourly to get live, then a flat monthly fee. You pay your hosting provider for the machine at cost, with no markup from us. Your model usage is billed by your AI provider directly, because the keys are yours.

Setup: time and materials

Installing SAFi is quick. Getting your organization live involves your security review, access provisioning, and policy design. Billed hourly against an estimate with a not-to-exceed cap agreed up front.

Run: flat monthly

A predictable fee covering updates, monitoring, backups, incident response, and integrity attestation, with SLA tiers for teams and enterprises.

Bring your own keys

You pay your model provider directly for tokens. We never front, mark up, or pool your model spend.

The software we operate

SAFi is open source, and stays that way

RunSAFi is not a proprietary black box. We deploy and maintain the exact same open-source governance engine you can inspect on GitHub. It features enterprise-ready integrations like OIDC SSO and SCIM 2.0 provisioning out of the box, ensuring seamless alignment with your existing IT infrastructure.

Read the code, deploy it locally with Docker, or try the live demo to see real-time policy enforcement and the hash-chained audit trail in action.