Guardrails, enforced where the traffic is

A policy nobody can enforce is a wish. Aicura turns governance decisions into guardrails that are compiled, signed and enforced in the request path, with a record of every intervention.

Where policy stops and traffic carries on

Most AI governance stops at the document. The acceptable use policy says what staff may do, the risk assessment says what worries you and both sit in a folder while the actual traffic, meaning prompts, responses and agent actions, flows past untouched. In most of the market, "enforcement" means an approval workflow, which is a record that someone said yes, not a control on what happens next.

Aicura joins the two. Governance decisions become guardrail rules, rules are compiled into signed bundles and bundles are enforced in the request path, so the thing your policy prohibits is the thing the gateway blocks. The gateway runs in your environment, not ours, so the rules travel to your traffic rather than your traffic travelling to us.

From decision to enforcement

Guardrail sets and rules. Authored against your registered systems and agents, with suggested guardrails drawn from your assessments, so what you enforce follows from what you found. Authoring starts at Essentials.

The guardrail compiler. Rules compile into signed guardrail bundles, so what runs at the enforcement point is exactly what was approved, versioned and attributable.

The AI gateway, running in your environment. A chokepoint in the request path that applies your guardrails to traffic in and out of models and agents. You deploy and run it, so your AI traffic never passes through Aicura. Deployment support is part of Pro, and you can point the bundles at your own gateway if you already run one.

Input and output scanning, also yours. Australian PII detection, LLM Guard and local classifier serving at Pro, with your own scanners welcome. Enterprise adds Presidio, Bedrock Guardrails and Granite Guardian. All of it runs on your side of the line, alongside the gateway.

Agent runtime constraints. Guardrails apply to agents as well as prompts, constraining tools and action scope, with suspension and re-scoping when an agent needs to be pulled up. More on the agent governance page.

Enforcement events. Every intervention is recorded, meaning what was blocked, redacted or constrained, under which rule and when. Enterprise adds CI/CD deployment gates, so ungoverned systems do not reach production in the first place.

Controls you can show operating

A control that exists on paper and a control that fired 40 times last month are different things, and anyone who assesses your governance knows it. The enforcement record turns your guardrails from asserted controls into demonstrated ones, sitting alongside your risks and controls so the same rule connects the assessment that motivated it, the bundle that implements it and the events that show it working.

Aicura provides guidance, not legal advice, and does not certify, audit or issue a compliance verdict. Which guardrails your organisation runs, and how strict they are, stays a decision your people make with the risk picture in front of them.

Guardrail questions, answered

See enforcement running

Guardrail authoring starts at Essentials and runtime enforcement is part of Pro. The best way to judge it is a walkthrough against your own scenarios.

Talk to us

Aicura Pty Ltd. AI governance support SaaS built for Australian organisations.