The runtime control plane for compliant AI.

Evaluate resource access, supported identity context, and query or content compliance through explicit, ordered runtime stages.

Resource access. Identity. Compliance.

The independent Resource Access Gate handles resource access. AI-IAM returns ALLOW / DENY / STEP_UP within a scoped enterprise deployment. The Compliance Engine returns PASS / WARN / FLAG / BLOCK.

Resolve each boundary in sequence.

Capture supported context

Accept query or content, jurisdiction, agent identity, PII or data classification, and supported agent_role / resource_tags.

Apply Resource Access Gate

Independently evaluate resource_tags with agent_role at the resource-access boundary, before any identity or content evaluation.

Apply AI-IAM

Check agent identity, status, jurisdiction, clearance, and rate budget; return ALLOW, DENY, or STEP_UP. Available only within a scoped enterprise deployment.

Evaluate compliance

Classify query or content, match shipped rules, and return PASS, WARN, FLAG, or BLOCK with the judge result.

Record delivered evidence

Write request_id, query hash, optional IAM effect, classification, results, prev hash, and chain hash.

Distinct controls, connected in sequence.

Stage 1 - Resource Access Gate

Evaluate resource_tags with agent_role as an independent resource-access boundary. This stage runs first.

Stage 2 - AI-IAM Enterprise deployment scope

Check agent identity, status, jurisdiction, clearance, and rate budget; return ALLOW, DENY, or STEP_UP. This is a reference implementation available within a scoped enterprise deployment, not the default path of the current public API.

Stage 3 - Compliance Engine

Evaluate query or content and policy matches; return PASS, WARN, FLAG, or BLOCK with classification and judge result.

Stage 4 - Evidence ledger

Link each record with prev hash and chain hash for cryptographic continuity after the compliance decision resolves.

Start from mapped controls. Add your operating rules.

Activate pre-built packs by regulation, jurisdiction, and industry, then layer organization-specific requirements without changing application code.

Privacy and data

HIPAA-aware, GDPR, APPI, LGPD, PIPA, PIPEDA, and cross-border data handling profiles.

AI governance

EU AI Act, NIST AI RMF, model-use restrictions, human oversight, disclosure, and risk-class controls.

Industry operations

Healthcare, financial services, legal, telecommunications, and enterprise data-handling profiles.

Enforce policy where your AI runs.

LogionOS Cloud

Managed control plane and runtime endpoints for the fastest path to production.

Private cloud or VPC

Keep processing within your cloud account and approved regional boundary.

On-premises

Run the enforcement plane inside your private network alongside regulated workloads.

Air-gapped

Operate without external network dependency for restricted and high-assurance environments.

Review security, privacy, and deployment controls →

Delivered fields, linked record by record.

Each stored record is tamper-evident and hash-chained through the delivered evidence fields.

Request

request_id and query hash identify the stored request without claiming additional context fields.

Runtime results

IAM effect when agent_id is provided, classification, compliance result, and judge result.

Chain continuity

prev hash links the prior record; chain hash records the current chain value.

Turn AI policy into runtime behavior.

Choose one production workflow. We will help map the supported inputs, integrate enforcement, and validate the delivered evidence fields.