Your rules.
AI follows.
Turn policy and regulatory requirements into controls enforced across models, agents, and tools, with evidence for every governed decision.
A research agent attempts to place a live trade. The agent was approved for market research, not execution. obstruo blocks the order before it reaches the trading system and preserves the policy, owner and attempted action as evidence.
AI is reaching production faster than governance can follow.
Every team interprets the document differently. Exceptions live in email and new projects start without the required controls.
An agent begins with read access and gradually receives the ability to write, delete, transfer money or contact customers.
When an auditor, customer or incident team asks what policy was active, the answer must be reconstructed from logs, tickets and screenshots.
Stop reconstructing AI decisions across engineering, compliance and vendor systems.
Compliance and engineering see the same reality. One technical event becomes a developer response, a compliance record and an auditor-ready artefact.
A 403 naming the policy that refused the tool call, in the trace the engineer is already reading.
The policy version, the owner, the vendor and the incident, without asking engineering to pull logs.
The same event exported against EU AI Act, GDPR, ISO 27001 and SOC 2 controls.
One policy. Active across every AI project.
Your organisation sets the rules once. obstruo applies them to every project, agent and request, and keeps the evidence that it did.
Locked, recommended and optional policies, inherited by every project the moment it is created.
Redaction, model restrictions, guardrails, budgets and tool permissions act on the request itself, not on a report.
The policy version, the decision, the routing, the redactions and the tool call stay connected as one record.
Control what AI can see, use and do
Redact PII and secrets before they reach models, and again when they return through tools.
Control which providers and models are allowed, behind stable logical model names.
Apply policy by agent identity, and restrict which MCP tools and actions each one can reach.
Enforce budgets, rate limits, safety guardrails and fail-closed behaviour when a check cannot run.
Connect runtime decisions to projects, agents, vendors, incidents and approvals.
Data, models, agents, risk and evidence are governed from the same place, so a rule changes once and applies everywhere.
Three problems that need governance first
Once an agent can place an order or issue a refund, tool permissions become the control that matters. Allow the reads, deny the writes, record the attempts.
Personal data and secrets reach models through prompts, retrieval and tool responses. Redaction runs in path, in both directions, and records what it removed.
Applications ask for a logical model name. Policy decides which approved provider and region answers, and refuses the ones your review has not cleared.
Fits the AI infrastructure you already operate
You do not have to replace your proxy or re-onboard every project to start governing AI.
Point your applications at obstruo and let it hold the provider connections, the policy and the evidence.
Keep the proxy you already run for traffic, and put obstruo in front of it for policy and evidence.
Start with the higher-risk projects and agents, then widen coverage as the policy proves itself.
Live today
These controls are enforced in production now. Preview and planned work is tracked in the changelog, so your security review reads one honest list rather than a roadmap.
Built to the standards your auditors ask about
No. Use it directly or chain it in front of the proxy you already run. Either way, policy and evidence stay in one place.
EU-hosted by default, in EU regions only. Traffic can be pinned to in-jurisdiction endpoints per project.
You choose the behaviour per policy: fail closed and refuse the request, or fail open and let it through. Either way the outcome is recorded with the policy version that caused it.
Around 20ms p50 for the enforcement path. Redaction with entity detection adds more, and is measured per project.
No. Most teams start with two or three higher-risk projects, then inherit the same organisation policy as coverage widens.
Policy version, decision, routing, redaction counts, tool calls, incidents and approvals, exportable per project, agent or framework.
Your AI. Your data. Your control.
Start free on one project, then make the same policy executable across the organisation.