Fail-closed
If there's no valid policy in place, no AI traffic gets through. If the audit pipeline fails, traffic stops as well. The default is to deny rather than allow.
Verillian is two components and no vendor cloud. A lightweight checkpoint runs on each device, where it decides what any AI tool or agent may do the moment it acts, then signs what happened before it leaves the machine. The admin server is yours too. It runs on your infrastructure, under your control, and the record it holds is sealed under your key. Nothing reaches us at any point, so there's no copy of your data on our side, encrypted or otherwise. Everything else on this page follows from that.
Six properties, enforced by the build rather than promised in a document. The record is hash-chained with SHA-256 and signed on the device with Ed25519, then sealed with X25519 and AES-256-GCM under keys only you hold. Here's what that construction buys you.
If there's no valid policy in place, no AI traffic gets through. If the audit pipeline fails, traffic stops as well. The default is to deny rather than allow.
Every entry is cryptographically signed by the device it came from, so a signature can't be produced by the admin server or by anyone else who doesn't hold that device's key.
Entries are appended to a chain where each one depends on the entry before it, so any modification breaks the chain in a way you can detect.
Signing keys never leave the device, and decryption keys are managed separately and aren't persisted on the server at all.
The admin server runs on your infrastructure, never on Verillian's. It stores the sealed record under your key and indexes metadata so your team can search, and we receive no copy of any of it. Revealing content takes your institution's key, which Verillian never holds, and every reveal happens in the reviewer's own browser and lands in the record.
Checkpoints accept only policies signed by a trusted authority, so anything unsigned or revoked is rejected before it can take effect.
On the endpoint, in the path between the tool and its provider, using the operating system's own mechanisms. There's no plugin, no wrapper, and no change to the tools your people already use: no SDK for a vendor to break, and keeping up with providers and operating systems stays our job rather than yours.
A request is decided on the device, so a blocked action never leaves the machine. A value your policy marks sensitive is hidden before the prompt goes anywhere, rather than flagged after it's gone.
A banned tool call is removed from the model's response before the client ever receives it, which leaves nothing to execute. The action isn't interrupted halfway. It never starts.
Verillian arrives through your existing device management and enrolls against your own server, with no SDKs, no per-tool integration, and a tray icon as the only thing your people see.
The checkpoint decides in both directions. A prompt is screened before it leaves, and the response and any tool calls that come back are ruled the same way. Every crossing is appended to the chain you hold.
Policy, fleet health, chain verification, and reporting live in one self-hosted console for your security and IT teams. It runs wherever you decide, including air-gapped where the mission requires it.
Browse captured AI usage and drill from sessions down to conversations, turns, and individual tool calls, so you can see what was allowed, blocked, or redacted in full context.
An interactive view shows what's being used and how often across the fleet, while the audit table beneath it carries each captured action back to a signed user and device. You can turn those observed patterns straight into policy without leaving the page.
Create, modify, and retire policies with a justification required every time. Every change lands in a tamper-evident history that can route through multiple approvers.
Monitor every enrolled checkpoint for connection status, version, heartbeat health, and chain integrity. Work through the enrollment queue or run bulk operations from the same place.
Verify audit-chain integrity across every enrolled device whenever you want, so tampering, gaps, and anomalies surface both per device and across the whole fleet.
Periodic reports cover usage, enforcement, anomalies, chain integrity, and redactions. They're designed to support a formal acknowledgment step before anything is archived.
System overview, representative view.
The architecture and the security model are documented end to end for exactly this evaluation. Take them into your review, and bring us the hard questions after.
Verillian runs inside your own environment, and the decision happens on the device, before anything leaves for a governed provider, across every tool and account that reaches one. This is the walk-through for your security team: the path a request takes, what crosses each line, what Verillian never receives, and the cryptography behind it all, which covers encryption under a key only you hold, a hash-chained record you can verify yourself, and policy a device rejects unless it's signed.
Read the briefVerillian governs how your organization uses AI, and it never takes your data. It runs inside your own environment, and the record it seals is encrypted under a key only you hold, so we never receive any of it. This covers where your data lives, how it's protected, and the questions security teams ask first.
Read the brief