Enterprise

What it takes to run this inside your organisation

Packaging, deployment, tenancy, metering and support, stated before you ask. Including the parts a company of this size cannot commit to yet, because you would find those in the first vendor-risk assessment anyway.

evidence-pack.json accept
// returned by the lane, signed before it is returned
{
  "verdict": "accept",
  "lane": "dela.evidence-change",
  "reason": "material change in coordinates; 3 dependent analyses affected",
  "inputs": {
    "current":   "sha256:9f2c…a71d",
    "candidate": "sha256:4b80…c2e9"
  },
  "impact": {
    "affected":  3,
    "preserved": 41,
    "replayed":  3,
    "held_for_review": 1
  },
  "deterministic": true,
  "chain": { "index": 18274, "prev": "sha256:0c15…8fa2" },
  "sig": "ed25519:7d41c0…9b3e"
}
Verify with the published key. No source access required. Replayable

The metered unit. An evidence pack is what you show an auditor, so it is what the entitlement counts.

Product shape

Simple for the board. Clear for the buyer. Exact underneath.

EcoKure is one assurance layer, explained at three levels so a risk committee can understand the outcome without hiding the architecture from the people who must deploy it.

01 · EXECUTIVE VIEW

AI Control Tower

Independent oversight for what AI is allowed to do, what requires review, what is blocked and what evidence must be retained.

Outcome · accountable AI operations
02 · PRODUCT VIEW

EcoKure Governed Workflow

One deployable runtime around an existing workflow, with customer-owned Control Packs, review routing, evidence and replay.

Outcome · a governed operating loop
03 · ARCHITECTURE VIEW

DTL · DAX · DCLA · DELA

Verification, permissioned action, control lineage and evidence lineage, with specialist lanes such as MedGate, MathGate and UnitGate.

Outcome · independently checkable proof

The chain a company is buying

AI proposes → DTL checks → DAX permission-controls action → DCLA tracks rule changes → DELA tracks evidence changes → a signed EvidencePack proves what happened. The same core applies across life sciences, financial services, critical infrastructure and internal enterprise workflows.

Choose your starting point

One core platform, four practical entry paths

Start with the workflow where evidence, rule change or action risk is already costing the organisation time.

StageWhat happensCustomer gets
01 · ChooseSelect one bounded workflow and the accountable owner.Use-case boundary
02 · EvaluateMap evidence, controls, dependencies, reviewers and failure modes.Evidence & Control Readiness Evaluation
03 · ShadowRun beside the existing process without actuating decisions.Measured pilot and signed report
04 · DeployConnect identity, tenant isolation, key custody and retention.Production go/no-go decision

Standards and channel fit

Control Packs can be mapped to customer policy, applicable regulation and structured risk repositories such as the MIT AI Risk Repository. The operating model is designed to work with cloud, governance and regulatory partners rather than replace them.

Packages

Three, deliberately

A catalogue nobody can hold in their head does not get bought. Each package has a stated boundary, so the scope is not renegotiated every time.

01

Readiness evaluation

Three to four weeks. No software deployed.

We map one workflow: its source evidence, governing controls, dependency structure, decisions and reviewers. You get a written definition of what counts as a material change in that workflow, a measured baseline of what the current process costs you, a pilot design with success and failure criteria, and a sample evidence pack built against your own artefact shapes.

Fixed fee · converts to a shadow pilot
02

Governed workflow

Annual entitlement, one named workflow.

The lanes that workflow needs, an evidence-pack allowance, reviewer accounts, your chosen deployment model and business-hours support. Verification calls are uncapped inside the entitlement, because a control that people avoid using to save budget is not a control.

Annual · metered on evidence packs released
03

Integration

Charged separately, priced from measured hours.

Connector work, deployment, key management and reviewer workflow configuration. Kept out of the licence on purpose, so the licence margin stays legible to you and to us.

Scoped per engagement

On pricing

We publish the structure and not the numbers, because no customer has paid them yet. Quoting a rate that has never been accepted would be inventing a market price. You will get a number in the first conversation, and we will tell you plainly that you are among the first to be quoted it.

Metering and entitlement

One unit, and it is the one you care about

QuestionAnswer
What is meteredEvidence packs released. Not calls, not seats, not models. The pack is the artefact you show an auditor, so it is what the entitlement counts.
What is not meteredVerification calls inside the entitlement. Reviewer accounts. Replays of packs you already hold.
VisibilityUsage is readable by you at any time through the API. You never have to ask us what you have consumed.
OverageAdditional packs at a published rate. Never a hard stop. A control system that switches off because a counter reached a limit is a control system nobody should deploy.
TermAnnual, with the renewal date and the entitlement stated in the agreement rather than derived from usage.
Deployment and data

Where it runs, and what leaves your network

ModelWhat leaves your networkSuits
Your infrastructureNothing. The lanes are deterministic and make no external inference call, so verification runs entirely inside your boundary. Signing keys are yours.Regulated data, residency constraints, air-gapped environments
HybridOnly what you route outward. Sensitive lanes stay local.Mixed sensitivity in one workflow
HostedWhat you submit for checking, plus the metadata needed to verify it.Evaluation and lower-sensitivity workflows

Retention

Evidence packs are generated per call and returned to you. The design intent is that we are not a store of your inputs or your outputs, and the retention position for your deployment is written into the agreement rather than left to a policy page. Ask us to demonstrate it rather than assert it.

Fail closed, always

If a gate cannot be reached, the result is recorded as unavailable. Never as a pass. Test this during a pilot by cutting network access to a gate and confirming what comes back. We will help you construct that test.

Onboarding

From agreement to first verified decision

01
Tenant created. Your entitlement is recorded as an object: which workflows, which lanes, what allowance, what term.
02
Keys issued, scoped to your tenant and to the lanes in your plan. Rotatable without touching the subscription.
03
Deployment stood up in the model you chose, with signing key custody settled before anything runs.
04
Shadow mode. The system observes and produces packs. It controls no production decision until you have seen what it would have done.
05
Reviewer workflow configured for the cases the lanes decline to decide, with the routing rules agreed rather than assumed.
06
Usage visible to you through the API from day one.
Support

A commitment we can actually meet

Published rather than negotiated, and sized to the company that has to honour it. An impressive support schedule we would breach in month two is worth less than a modest one we keep.

SituationWhat we commit to
Verification returning wrong resultsTreated as the highest severity there is. Same business day, and we will tell you to stop relying on the affected lane while we work.
Service unavailableSame business day. Fail-closed behaviour means an outage blocks rather than silently permits, so the risk is disruption rather than a bad decision.
Questions and configurationTwo business days, Australian hours.
EscalationDirect to the founder. At this size that is not a premium tier, it is the only tier, and it is stated honestly.
Honest limits

What we cannot commit to yet

  • No 24/7 on-call rotation. Headcount is one, and a schedule that implies otherwise would be a false statement in a contract.
  • No certifications held. Not ISO 27001, not SOC 2, not ISO/IEC 42001. Controls are built to be auditable, which is a different and weaker claim.
  • No third-party penetration test or security assurance report yet. Commissioning one is planned and has not happened.
  • No customer has taken a pilot through to a production licence, so there is no reference deployment to point you at.
  • Business continuity rests on source escrow and the fact that most gates are public repositories. That should be discussed before a pilot, not after.
  • Pricing is untested. You would be among the first organisations quoted, and we would tell you that rather than let you assume otherwise.

Why this section is on a public page

Every item here surfaces in the first vendor-risk assessment. Publishing them costs nothing and saves both sides several weeks, and if one of them is disqualifying for your organisation, that is worth discovering in week one rather than week six.

Request the detail pack

Architecture, tenancy, key custody, the security questionnaire and the integration specification, sent under a mutual NDA. If your review needs something not in it, tell us and we will either produce it or say plainly that it does not exist yet.

Where it sits in what you already run

Nothing is replaced. The runtime deploys in your own account, so the only thing crossing the seam is a decision request one way and a verdict with its evidence coming back.

Your existing stack unchanged, nothing replaced The AI model or agent you already run Your workflow and orchestration Your GRC platform and risk register Your identity provider Your data platform decision request verdict + evidence no agent installed no data leaves your boundary EcoKure Assurance Runtime deployed in your account · 11 dependencies Control packs, versioned and owned by you ALLOW / BLOCK / ABSTAIN on every decision Signed, append-only evidence chain Review queue for abstentions Change impact and selective replay EcoKure never touches • Your model — it is never evaluated, tuned or replaced • Your GRC platform — integrated with, not replaced • Your data — a digest is stored, never the input • Any actuation — nothing is executed on your behalf
EcoKure sits beside what you run rather than inside it. There is no agent to install and no data to send us: the runtime deploys in your own account, and the only thing crossing the seam is a decision request going one way and a verdict with its evidence coming back.

What one decision actually does

The same runtime and the same evidence contract as every other pathway. What changes is the control pack and the workflow.

your own account — evidence and keys never leave Your system Existing AI, agent or workflow EcoKure Assurance Runtime deterministic gate Decision ALLOW / BLOCK / ABSTAIN Your rules Control Pack — version + hash binds version + hash entry 412 ABSTAIN signed, append-only evidence chain signs every outcome only on ABSTAIN Queue Review queue depth + ageing Person Qualified reviewer your IdP, your roles entry 587 BLOCK sign-off — commitment only, no identity references, never rewrites Evidence pack export Independent verifier no EcoKure code runs offline
The dashed arrow is the load-bearing detail. A reviewer’s decision is appended as a SECOND signed entry that points at the first. Entry 412 stands unaltered forever and still replays to ABSTAIN — the record shows that the machine had no basis and a named human took responsibility, rather than a system that was always confident.
Next · Start a pilot Adoption