What it takes to run this inside your organisation
Packaging, deployment, tenancy, metering and support, stated before you ask. Including the parts a company of this size cannot commit to yet, because you would find those in the first vendor-risk assessment anyway.
// returned by the lane, signed before it is returned { "verdict": "accept", "lane": "dela.evidence-change", "reason": "material change in coordinates; 3 dependent analyses affected", "inputs": { "current": "sha256:9f2c…a71d", "candidate": "sha256:4b80…c2e9" }, "impact": { "affected": 3, "preserved": 41, "replayed": 3, "held_for_review": 1 }, "deterministic": true, "chain": { "index": 18274, "prev": "sha256:0c15…8fa2" }, "sig": "ed25519:7d41c0…9b3e" }
The metered unit. An evidence pack is what you show an auditor, so it is what the entitlement counts.
Simple for the board. Clear for the buyer. Exact underneath.
EcoKure is one assurance layer, explained at three levels so a risk committee can understand the outcome without hiding the architecture from the people who must deploy it.
AI Control Tower
Independent oversight for what AI is allowed to do, what requires review, what is blocked and what evidence must be retained.
EcoKure Governed Workflow
One deployable runtime around an existing workflow, with customer-owned Control Packs, review routing, evidence and replay.
DTL · DAX · DCLA · DELA
Verification, permissioned action, control lineage and evidence lineage, with specialist lanes such as MedGate, MathGate and UnitGate.
The chain a company is buying
AI proposes → DTL checks → DAX permission-controls action → DCLA tracks rule changes → DELA tracks evidence changes → a signed EvidencePack proves what happened. The same core applies across life sciences, financial services, critical infrastructure and internal enterprise workflows.
One core platform, four practical entry paths
Start with the workflow where evidence, rule change or action risk is already costing the organisation time.
Medical and life sciences
Research evidence checks, clinical administration and regulatory submission support. Non-diagnostic, human-reviewed and built around defensible audit evidence.
DISCOVERY PATHAPRA and financial services
Customer communication, fraud support and model-change workflows where control lineage and decision records matter.
VALIDATION PATHCritical infrastructure
Permissioned action and fail-closed boundaries around electrical, industrial, transport and security systems.
GENERAL PATHEnterprise operations
Governed knowledge, policy and workflow assistants for boards, legal, risk and operational teams.
| Stage | What happens | Customer gets |
|---|---|---|
| 01 · Choose | Select one bounded workflow and the accountable owner. | Use-case boundary |
| 02 · Evaluate | Map evidence, controls, dependencies, reviewers and failure modes. | Evidence & Control Readiness Evaluation |
| 03 · Shadow | Run beside the existing process without actuating decisions. | Measured pilot and signed report |
| 04 · Deploy | Connect identity, tenant isolation, key custody and retention. | Production go/no-go decision |
Standards and channel fit
Control Packs can be mapped to customer policy, applicable regulation and structured risk repositories such as the MIT AI Risk Repository. The operating model is designed to work with cloud, governance and regulatory partners rather than replace them.
Three, deliberately
A catalogue nobody can hold in their head does not get bought. Each package has a stated boundary, so the scope is not renegotiated every time.
Readiness evaluation
Three to four weeks. No software deployed.
We map one workflow: its source evidence, governing controls, dependency structure, decisions and reviewers. You get a written definition of what counts as a material change in that workflow, a measured baseline of what the current process costs you, a pilot design with success and failure criteria, and a sample evidence pack built against your own artefact shapes.
Governed workflow
Annual entitlement, one named workflow.
The lanes that workflow needs, an evidence-pack allowance, reviewer accounts, your chosen deployment model and business-hours support. Verification calls are uncapped inside the entitlement, because a control that people avoid using to save budget is not a control.
Integration
Charged separately, priced from measured hours.
Connector work, deployment, key management and reviewer workflow configuration. Kept out of the licence on purpose, so the licence margin stays legible to you and to us.
On pricing
We publish the structure and not the numbers, because no customer has paid them yet. Quoting a rate that has never been accepted would be inventing a market price. You will get a number in the first conversation, and we will tell you plainly that you are among the first to be quoted it.
One unit, and it is the one you care about
| Question | Answer |
|---|---|
| What is metered | Evidence packs released. Not calls, not seats, not models. The pack is the artefact you show an auditor, so it is what the entitlement counts. |
| What is not metered | Verification calls inside the entitlement. Reviewer accounts. Replays of packs you already hold. |
| Visibility | Usage is readable by you at any time through the API. You never have to ask us what you have consumed. |
| Overage | Additional packs at a published rate. Never a hard stop. A control system that switches off because a counter reached a limit is a control system nobody should deploy. |
| Term | Annual, with the renewal date and the entitlement stated in the agreement rather than derived from usage. |
Where it runs, and what leaves your network
| Model | What leaves your network | Suits |
|---|---|---|
| Your infrastructure | Nothing. The lanes are deterministic and make no external inference call, so verification runs entirely inside your boundary. Signing keys are yours. | Regulated data, residency constraints, air-gapped environments |
| Hybrid | Only what you route outward. Sensitive lanes stay local. | Mixed sensitivity in one workflow |
| Hosted | What you submit for checking, plus the metadata needed to verify it. | Evaluation and lower-sensitivity workflows |
Retention
Evidence packs are generated per call and returned to you. The design intent is that we are not a store of your inputs or your outputs, and the retention position for your deployment is written into the agreement rather than left to a policy page. Ask us to demonstrate it rather than assert it.
Fail closed, always
If a gate cannot be reached, the result is recorded as unavailable. Never as a pass. Test this during a pilot by cutting network access to a gate and confirming what comes back. We will help you construct that test.
From agreement to first verified decision
A commitment we can actually meet
Published rather than negotiated, and sized to the company that has to honour it. An impressive support schedule we would breach in month two is worth less than a modest one we keep.
| Situation | What we commit to |
|---|---|
| Verification returning wrong results | Treated as the highest severity there is. Same business day, and we will tell you to stop relying on the affected lane while we work. |
| Service unavailable | Same business day. Fail-closed behaviour means an outage blocks rather than silently permits, so the risk is disruption rather than a bad decision. |
| Questions and configuration | Two business days, Australian hours. |
| Escalation | Direct to the founder. At this size that is not a premium tier, it is the only tier, and it is stated honestly. |
What we cannot commit to yet
- No 24/7 on-call rotation. Headcount is one, and a schedule that implies otherwise would be a false statement in a contract.
- No certifications held. Not ISO 27001, not SOC 2, not ISO/IEC 42001. Controls are built to be auditable, which is a different and weaker claim.
- No third-party penetration test or security assurance report yet. Commissioning one is planned and has not happened.
- No customer has taken a pilot through to a production licence, so there is no reference deployment to point you at.
- Business continuity rests on source escrow and the fact that most gates are public repositories. That should be discussed before a pilot, not after.
- Pricing is untested. You would be among the first organisations quoted, and we would tell you that rather than let you assume otherwise.
Why this section is on a public page
Every item here surfaces in the first vendor-risk assessment. Publishing them costs nothing and saves both sides several weeks, and if one of them is disqualifying for your organisation, that is worth discovering in week one rather than week six.
Request the detail pack
Architecture, tenancy, key custody, the security questionnaire and the integration specification, sent under a mutual NDA. If your review needs something not in it, tell us and we will either produce it or say plainly that it does not exist yet.
Where it sits in what you already run
Nothing is replaced. The runtime deploys in your own account, so the only thing crossing the seam is a decision request one way and a verdict with its evidence coming back.
What one decision actually does
The same runtime and the same evidence contract as every other pathway. What changes is the control pack and the workflow.
