Our mission

Regulated organisations should be able to adopt AI without losing control of it.

obstruo is a European control layer for AI. We build it so security, compliance and platform teams can say yes to AI projects and still prove, request by request, what data was exposed, which model answered, and which rule decided.

Built and hosted in the EU Three founders, one product Neutral across providers
Why obstruo exists

Companies are deploying AI faster than they can govern it.

We spent years shipping production software and machine learning for organisations with regulated data and low-latency requirements. The pattern repeated everywhere. A team launches an assistant, a second team wires an agent into a core system, and the organisation discovers it has no single place to decide what data may reach a model, which provider may process it, where that processing happens, and how any of it is recorded.

Governance arrived after deployment, as a document nobody could enforce. We started obstruo to move that control into the request path, where a rule either executes or it does not. The question is no longer whether an organisation will use AI. It is whether it can prove how AI was used.

The gap we close
Sensitive data reaches providers unredacted
Redaction is per team, per prompt, and inconsistent by definition.
Provider keys are scattered
Across teams, environments and tools, with no way to rotate or revoke centrally.
Audit trails live in vendor dashboards
Fragmented across providers, and never linked to the rule that applied.
Agents can act before anyone limits them
Tool access is granted at build time and reviewed, if at all, after an incident.
Principles

Six rules we hold ourselves to

They decide what we build, and just as often what we refuse to build.

01
Neutral by design

We do not build models. We govern them, so you can change provider without changing your controls.

02
Policy has to execute

A rule that only lives in a document is not a control. Every policy in obstruo acts on the request itself.

03
Evidence by default

If a decision is not recorded with the policy version that caused it, then for an auditor it did not happen.

04
Safe when uncertain

When a check cannot run, fail closed is the default. Opening it up stays possible, and stays a deliberate decision.

05
European by construction

EU-hosted, EU-operated, built for organisations that have to show where data was processed and under whose rules.

06
Say the specific thing

Named regulations, measured numbers, and honest capability labels, including for what we have not built yet.

Founders and team

A team with over 14 years of experience

Production software, applied AI, and building delivery teams inside strictly regulated environments.

Mateusz Łępicki
Mateusz Łępicki
Co-founder and CEO

Designs and ships enterprise-grade AI systems, with experience delivering in strictly regulated environments.

LinkedIn
Marta Prewysz-Kwinto
Marta Prewysz-Kwinto
Co-founder and CTO

Built high-scale, low-latency machine learning for marketing. Leads AI projects and the people who build them.

LinkedIn
Michał Madey
Michał Madey
Co-founder and CCO

Creator of AI and cybersecurity centres of excellence. Runs enterprise-grade delivery end to end.

LinkedIn
Company details

Who you are contracting with

Procurement and vendor-review teams tend to need these first. Registry identifiers are marked where they still need confirming before this page goes live.

LEGAL ENTITYOBSTRUO prosta spółka akcyjna (P.S.A.)
REGISTERED OFFICEul. Święty Marcin 29 lok. 8, 61-806 Poznań, Poland
COMPANY AND VAT IDKRS 0001254019, NIP 7831958330, REGON 545245656
PROCESSING REGIONSEU regions only
SECURITY, PRIVACY AND DISCLOSURESame address, marked in the subject line
DOCUMENTS ON REQUESTDPA and sub-processor list

Your AI. Your data. Your control.

Talk to a founder about your first governed project, or ask us the awkward vendor-review questions.

Talk to the team Work with us