web stats

We help organizations build and run AI agents they can trust with real work

We deploy AI agents directly in your environment, governed by SAFi at runtime. Every action is evaluated against your policies, every decision is recorded, and every tool call is authorized before it runs. You keep the infrastructure, the data, and the keys.

SAFi Control Panel

What you get

Governed agents, your infrastructure, your data.

We configure and deploy AI agents tailored to your organization's use case. SAFi sits between the agent and the outside world, evaluating every turn before an answer is returned or a tool runs.

The agents run on your infrastructure. Your data stays in your environment. Your model keys stay on your machine. You own everything.

Because SAFi is open source, you can inspect the governance engine, verify its behavior, and take over operations whenever you choose. You never surrender control to a proprietary vendor cloud.

What we deliver

The agents, the engine, and the operations

What we bring

Agents, deployment, and ongoing operations

  • Governed Agents: We build and configure AI agents for your specific use case, with SAFi governance built in from day one.
  • Deployment: We deploy SAFi and the agents from a published, integrity-verified release into your environment.
  • Maintenance: We apply updates on the release cadence and execute immediate security hotfixes.
  • Monitoring: We track system health, watch for resource exhaustion, and manage log rotation.
  • Data Protection: We execute routine backups and perform regular tested restores.
  • Integrations: We configure your SSO providers and requested MCP tool servers.
  • Integrity Attestation: We verify the running Core Loop against its published TCB Fingerprint and generate recurring integrity reports for your auditors.
  • Training: We train your team to operate the agents and SAFi when you are ready to take over.

What you bring

Ownership and resources

  • Infrastructure: A Linux VM or bare-metal server sized to your expected load. Everything runs inside your boundary.
  • API Keys: You provide your own AI model keys. They are stored securely on your machine, and our operating procedures ensure we cannot access their contents.
  • Policies and Directory: Your internal corporate policies, agent scopes, and user directory configurations.
  • Data Ownership: You retain complete ownership of all governance records and conversation data at rest.
  • Approvals: You review and approve change windows for version upgrades.

Environment and deployment

What the machine has to be

Your OS is Linux

All of SAFi's tooling and the reference deployment require a Linux environment.

Docker or bare-metal

We deploy SAFi via Docker or as a bare-metal installation with system services and a reverse proxy. We confirm the exact deployment path during scoping to match your internal operating standards.

Data ownership and egress

Where your data sits, and where requests go

Everything stays in your environment

The software, your governance records, and your conversation data remain at rest entirely on your machine.

Requests may leave your tenant

SAFi sends prompts and data to the AI model providers and external tools you explicitly configure. You control those endpoints and credentials.

You control the boundary

You place the machine in its own subnet with a strict egress allowlist. Traffic only routes to your designated model providers and internal tool endpoints.

We do not train on your data

We never use your governance records or conversation data to train models.

Access model

Admin on one machine, and nothing beyond it

We require administrative access to the host

This allows us to install system dependencies, deploy the engine and agents, manage configured tool servers, and apply patches. This access is strictly limited to the single machine.

We connect through your approved channels

We access the host via your dedicated VPN, jump box, or scoped IAM roles. We adopt your secure access requirements.

You control our access

You grant administrative credentials governed by your organization. You retain the ability to audit our session logs and can rotate, restrict, or revoke our access at any time.

You keep ultimate control

You own the machine. You can snapshot it, inspect the filesystem, restrict its egress, or power it off whenever necessary.

Who does what

The responsibility split, line by line

Division of responsibilities between RunSAFi and the customer
AreaWeYou
Environment, networking, IAMAdviseOwn and pay
Access to the machineHold admin on that single hostGrant, isolate, audit, and revoke
Agent configurationBuild and configure for your use caseDefine requirements and approve
Deploy and upgradesExecute themApprove the change windows
Backups and restoreExecute and test themRely on them
Model provider keysNever view themOwn, apply, and rotate them
Model usage costZero markupBilled directly by your provider
Policies, agents, usersConfigure on requestDefine and govern
Governance dataMaintain the databaseOwn the data entirely
Integrity verificationProvide scheduled attestationsIndependently verify at any time
End-user supportMaintain system uptimeManage internal staff help desk

Onboarding

The path to production

  1. Security Review & Scoping

    We define your environment specifics, verify your access model (VPN, jump box, IAM), and scope the required SSO and tool integrations.

  2. Infrastructure Provisioning

    You stand up the required Linux VM or bare-metal server sized to your expected load.

  3. Deployment & Configuration

    We install the verified SAFi release, configure your domain over HTTPS, and set up system monitoring.

  4. Agent Configuration

    We build and configure the governed agents for your use case, wire them to SAFi, and connect your approved MCP tool servers.

  5. SSO & Keys

    We connect your chosen Identity Provider (Entra or Workspace). You log in and apply your model provider API keys securely.

  6. Go Live

    We verify the TCB Fingerprint, establish monitoring baselines, the operational SLA begins, and your governed agents start doing real work.

A path to self-operation is built in

We can train your team to assume operations whenever you are ready. On exit you keep the machine, the keys, and the data with a clean handover. The software was never ours to hold.

Start a scoping conversation

Scope

What this is not

  • Not a reseller of model access. You bring your own keys and pay your provider directly.
  • Not custom engineering. Deploying and operating governed agents is the product. Bespoke features or plugins are a separate engagement.
  • Not your compliance team. SAFi produces the evidence. Deciding your policies and reviewing your audit trails remains your responsibility.
  • Not your help desk. We keep the agents and platform running. Supporting your own staff stays with your internal IT support.

Deploy governed agents in your environment

Tell us about your use case, environment, and security requirements. We will scope the agents, the deployment, and provide a quote.