GLACIS Managed · Per-tenant arbiter

A boundary in the action path, operated for you.

A managed Glacis deployment applies the intended rule where an AI takes action: allow, block, or escalate. Each covered decision leaves a signed operational record that can be checked independently. The deployment plan states what is in scope and what is not.

Defined coverage · Explicit fail posture · Signed records you can verify

Runtime event stream simulation · arbiter-01 · us-east
  • 14:02:31agent-billingtool.invoke · stripe.refundallow
  • 14:02:31arbitersigned · 4f2c…a081witnessed
  • 14:02:33agent-supportmail.send · external recipientwitnessed
  • 14:02:36agent-opsdb.drop_table · prodblocked
  • 14:02:36arbitersigned · b3d9…07e2witnessed
Action
tool.invoke · stripe.refund
Policy
spend-limit-v3 · allow
Witness
witness.glacis.io
Hash chain
4f2c…a081 → 9d17…33c5
canonicalize (RFC 8785) ✓ SHA-256 ✓ Ed25519 ✓ chain ✓

✓ VERIFIED

Simulated for illustration · the cryptographic verification below runs locally in your browser.

Observability sees. GRC documents. Guardrails filter. Platform logs are the platform’s word. Glacis leaves evidence another party can check.

The demo

From governed action to verifiable record.

The whole loop fits in one breath.

  1. 0:00

    One command

    The connector brings up a WireGuard tunnel. Your agents now reach their arbiter over a private WAN.

  2. 0:02

    One line

    Change the agent’s base URL. It doesn’t know anything happened.

  3. 0:04

    Arbitrated inline

    Each configured in-scope operation can be allowed, witnessed, or blocked. A signed record is created for the covered event.

  4. 0:07

    Verify it yourself

    The receipt goes into the browser verifier, which checks it without trusting us.

tenant-arbiter · demo capture
$ glacis connect
wg0 up · tenant arbiter reachable · private WAN

# agent config — one line
- base_url: https://api.provider.example
+ base_url: https://arbiter-01.tenant.glacis

# event stream
14:02:31  agent-billing  tool.invoke      allow
14:02:33  agent-support  mail.send        witnessed
14:02:36  agent-ops      db.drop_table    blocked

# receipt 4f2c…a081
canonicalize (RFC 8785) ✓  SHA-256 ✓  Ed25519 ✓  chain ✓
✓ VERIFIED IN YOUR BROWSER — local cryptographic check complete

Simulated for illustration · the verification is real. Run it on a real signed receipt below.

Verify it yourself

The record, checked in your browser.

This is a real signed sample record. The verifier processes the record locally in your browser (Ed25519 over SHA-256, canonicalized under RFC 8785) and does not submit it as verification input. A valid signature establishes integrity and signer identity for the fields shown; it does not establish completeness, safety, or compliance.

Why teams point agents at us

Not another log. Evidence.

EVIDENCE

The end of finger-pointing.

When an agent does something wrong, “we think it was the model” is not an answer. A Glacis record links the governed action, the intended rule, and the control decision in a signed, hash-chained artifact. An outside party can verify its integrity while still examining coverage, configuration, key custody, and whether the control was appropriate.

ISOLATION

A private transport path for the governed workflow.

A dedicated per-tenant arbiter can be reached over WireGuard, Twingate ZTNA, or AWS PrivateLink, depending on configuration. The transport and payload boundary must be assessed for the actual deployment.

SPEED

Where the AI already acts.

The action path that matters is mapped to the supported integration path, and the network, identity and control configuration confirmed. The meter is the signed-receipt count, the same operational unit the Console records. Usage stays legible as a workflow moves into production.

Private WAN · Assurance ladder

Private transport, with an explicit boundary.

GLACIS Managed can provide a dedicated per-tenant arbiter reached over WireGuard, Twingate ZTNA, or AWS PrivateLink. That can reduce public routing and multi-tenant mixing, but the exact network path depends on the selected transport and surrounding customer architecture.

The honest boundary: Managed means Glacis operates the arbiter. Dedicated infrastructure and private transport are evidence about isolation and routing; they are not proof that an operator cannot access payloads. Stronger confidentiality claims require additional controls and their own evidence.

RungThe claimHow you check it
Managed Operational isolation. Private WAN, dedicated per-tenant instance. Receipts + the connector config you control
+ Nitro Enclave-backed. Hardware attestation can identify the enclave image and configuration that ran. Check the attestation document and its stated measurements
PrivateLink / your VPC PrivateLink can keep configured service traffic on AWS network paths; a customer-VPC deployment can keep the configured data plane inside the account, subject to actual routing and surrounding services. Your own VPC console
Self-hosted / airgap The data plane can remain within the customer-operated boundary. Inspect your host, routing, and deployment configuration

Each rung makes a different claim. The supporting evidence and exclusions should travel with it.

Getting started

One commercial path from exploration to production.

Start free, move a live workflow to production, or talk to us about a consequential enterprise deployment. The price is scoped to what the deployment requires.

Start free →

Design partners

Design partnerships.

Design partnerships are scoped case by case: availability, evidence, permissions and working boundaries are agreed up front.

Managed deployment

Mapped from the action and the rule.

From the action the AI can take and the rule that matters, we map the managed deployment, private connectivity, and the operational evidence your reviewers need.

Private deployment · regulated workflows · evidence an outside party can verify