Give every AI agent a mandate, limits and a paper trail. Stop risky actions and roll agents out with evidence risk teams can review.
Explore locally with Community. Use the free Evaluation licence for a self-serve technical assessment. Choose the paid production program when a sponsored workflow must reach a decision against a real deadline.
Use Community when you are validating fit, integration path, and basic governance controls on your own.
Read getting started βRequest a free 90-day Evaluation license when you need higher limits, policy simulation, evidence export, and a more realistic production-readiness test.
Start Safe Evaluation βTake one governed workflow into scoped production in 60 or 75 days. Paid programs start at $2,000 and require an executive sponsor.
See the production program βStop risky agent actions. Clear reviews and audits faster. Roll agents out across teams and AI stacks.
Set what an agent may access, change and spend. Block destructive actions, pause consequential steps for a person and set AI usage budgets. For payment agents, fraud controls add checks before money moves.
6,649personal-data redactions at the point of the call during BukuWarung's evaluation. See the product and fraud demos.
Every governed action records who initiated it, which rule applied and who approved it. Risk teams and auditors can review evidence captured as agents run instead of rebuilding the story later.
1.3Mmodel and tool calls governed with policy decisions in BukuWarung's 60-day evaluation. Read its story.
Reuse mandates, approvals and evidence across connected coding tools, agent runtimes and application frameworks. Five language SDKs and 20+ documented integration paths help teams start new workflows with controls already in place.
21 daysBukuWarung went from signed agreement to organization-wide AI governance in production in 21 days.
Also included: deterministic policies, tamper-evident audit logs, human approvals, PII redaction, per-user attribution through SSO and SCIM, and workflows that pick up where they left off without repeating an action. See the product and fraud demos.
The same mandate, limits and paper trail lead with a different saving in each industry.
Stop risky agent payments, give examiners decision evidence produced as agents run, and roll governed agents out across banking teams.
Explore financial servicesStop risky account and network changes, control AI spend in care workflows and get agents into service operations faster.
Explore telecomKeep consequential citizen decisions under human authority, keep data inside your own environment and get public-service agents live sooner.
Explore public sectorIn healthcare, hold clinical and billing actions for a person where it matters, and keep patient data out of model providers. See all industry guides.
See it running. Two short walkthroughs: the platform end to end, and the Fraud & Risk Add-on stopping an attack in flight. ▶ Watch the product demos
A log tells you what an agent did after a risky change ran, sensitive data left or the AI bill arrived. To hand agents real work, the decision has to happen before the agent acts, with a record of why. Without that, companies hit the same four problems.
Risk and compliance teams need to know not just that an agent acted, but why it was allowed and who approved it. Without that answer, every new agent waits in review.
Personal data leaks to model providers, risky actions skip the intended checks, and no one can say whether a retry will repeat a payment without rebuilding the run by hand.
Teams adopt AI tools on their own, so no one can see who is using what, under which rules, or at what cost.
EU AI Act, HIPAA, GDPR, RBI, and SEBI increasingly require audit trails, human oversight, and data residency for AI systems. EU AI Act fines reach up to 7% of global turnover.
Not another gateway or observability add-on. AxonFlow sits in the execution path, enforces policy, and records decision context while workflows are running.
Step gates for existing orchestrators with per-step policy checks, approvals, and execution identity
Secure connectors to internal systems via Model Context Protocol
RBAC, ABAC, and runtime policy checks with deny-by-default execution controls
Decision context, audit trails, and exportable evidence for engineering, security, and compliance reviews
Hot-path policy enforcement designed for production AI systems. Not a bolt-on toolβa native governance layer.
Low-overhead policy evaluation designed for latency-sensitive AI workflows. In-memory policy engine with deny-by-default security and 5 built-in media safety policies.
Policy checkpoints for external orchestrators. Each workflow step and tool call is governed independently before execution proceeds.
Agents access internal systems through Model Context Protocol connectors. Every query is scanned for PII, exfiltration, and policy violations before execution.
Immutable audit log for every LLM call, tool invocation, and policy decision. Prometheus/Grafana dashboards included. Evidence support for EU AI Act, HIPAA-oriented, GDPR, RBI, and SEBI workflows.
Trace why every governed action happened. Beyond a chronological log: a structured, queryable record of every allow / deny / require_approval decision — with the policy version that fired, the rules it matched, and whether an override could unblock it. List recent decisions, explain any one of them, and answer "why is this blocked NOW that wasn't 2 days ago?" without guessing.
Vendor-neutral routing across OpenAI, Anthropic, AWS Bedrock, Google, and local models. Automatic failover when providers go down.
Add governance to existing AI applications without rewriting code. Works with your current orchestrator, LLM provider, and deployment.
Full-featured web portal for AI governance operations. Monitor executions, manage approvals, configure policies, and track costs without writing code.
Financial crime controls for agent-initiated transactions, with deterministic blocks and step-ups, advisory risk scoring, decision-API review gates, and attributed evidence in compliance exports.
Explore the add-on → Enterprise Add-onFramework mappings, runtime controls, and exportable evidence for healthcare, financial services, and EU AI governance reviews.
Clone the repo, run locally, inspect the source. Full platform under the BSL 1.1 license. No vendor lock-in.
Full source code available under BSL 1.1. Inspect, modify, and deploy on your own infrastructure.
Policy engine, PII detection, SQL injection scanning, Gateway and Proxy modes included.
Official SDKs for Python, TypeScript, Go, Java, and Rust (preview). Plugins for OpenClaw, Claude Code, Cursor, and Codex — shared 75+ policy set across all four. Integrate in minutes.
Start with Community Edition. Get a free Evaluation license for higher limits and org-wide policies, or upgrade to Enterprise for advanced compliance and connectors.
| Feature | Community | Evaluation (Free) | Enterprise |
|---|---|---|---|
| Resource Limits | |||
| Tenant Policies | 20 | 50 | Unlimited |
| Organization-Wide Policies | 0 | 5 | Unlimited |
| Connectors with Custom Policies | 2 | 5 | Unlimited |
| Audit Log Retention | 3 days | 14 days | 10 years |
| LLM Providers | 2 | 3 | Unlimited |
| Execution History | 50 | 500 | Unlimited |
| Concurrent Executions | 5 | 25 | Unlimited |
| MAP Plans | 25 | 100 | Unlimited |
| Versions per Plan | 10 | 25 | Unlimited |
| SSE Connections | 5 | 25 | Unlimited |
| Cost Estimates / Day | 10 | 100 | Unlimited |
| Pending Execution Approvals | Not applicable | Not applicable Creating approvals needs Professional or higher |
Unlimited |
| Media Analyzers | 2 | 2 | Unlimited |
|
Concurrent Executions β MAP and WCP executions running at the same time per tenant
Pending Execution Approvals β the per-tenant ceiling on entries waiting in the human approval queue. Creating approval entries needs Professional or higher, and those tiers are uncapped, so the finite caps the lower tiers declare are never reached
MAP Plans β multi-agent plans that break complex tasks into coordinated steps
Versions per Plan β how many revisions of a single MAP plan are retained
SSE Connections β server-sent event connections for streaming execution progress in real time
Cost Estimates / Day β number of LLM cost estimation requests allowed per day
Execution History β completed execution records kept for review and audit
Media Analyzers β concurrent image analysis modules (OCR, content safety, face detection) per request
| |||
| Core Platform | |||
| Policy Engine (low-overhead path) | β | β | β |
| PII Detection (12+ types incl. Aadhaar, PAN, UPI) | β | β | β |
| SQL Injection Scanning (Advanced - 37+ patterns) | β | β | β |
| Multi-Agent Planning (MAP) | β | β | β |
| Prometheus/Grafana Metrics (80+) | β | β | β |
| Multimodal Image Governance (NSFW, PII, faces, OCR) | β | β | β |
| System Media Policies (NSFW, violence, biometric, PII, sensitive docs) | 5 rules (opt-in) | 5 rules | 5 rules + custom |
| Cloud Vision Analyzers (AWS Rekognition, Google, Azure) | β | β | β |
| LLM Providers | |||
| OpenAI, Anthropic, Ollama | β | β | β |
| AWS Bedrock | β | β | β |
| MCP Connectors | |||
| Database (PostgreSQL, MySQL, MongoDB) | β | β | β |
| Enterprise (Salesforce, Slack, Snowflake, Jira, ServiceNow) | β | β | β |
| Compliance Frameworks | |||
| GDPR & PCI-DSS | β | β | β |
| EU AI Act, RBI FREE-AI, SEBI, HIPAA (policy templates) | β | β | β |
| US PII detection (SSN, bank routing/account) | β | β | β |
| US examination evidence (Evidence Export based) | — | β Evidence Export limits apply |
β |
| Enterprise Features | |||
| Customer Portal (Execution Timeline, Approval Dashboard, Analytics) | β | β | β |
| Human-in-the-Loop, Kill Switch, SSO/SAML | β | β | β |
| Per-Tenant Media Governance | β | β | β |
| HITL Approval Gates | β | — Resolve-only; creating approvals needs Professional or higher |
β |
| Policy Simulation | β | β 300/day |
β Unlimited |
| Evidence Export | β | β 14-day, 3/day |
β Unlimited |
| 24/7 Support + SLA | β | β | β |
Start with our managed SaaS or deploy in your VPC/on-premises for complete data sovereignty.
Feedback from senior engineers evaluating AxonFlow for production AI governance.
AxonFlow is built for the teams responsible for running AI systems safely in production, not for building demos.
Hot-path policy enforcement. The governance layer is designed for latency-sensitive request paths, and teams should benchmark it in their own deployment mode and policy mix.
Runs entirely in your infrastructure. Prompts, policies, audit logs, and LLM traffic stay in your environment. Anonymous telemetry can be disabled, and deployment can fit customer-controlled network boundaries.
Founded by engineers who built internal platforms at Booking.com (1,500+ engineers, millions of daily users). AxonFlow reflects that operational experience.
Start in observe-only mode. Add policy enforcement progressively. Gateway mode wraps existing LLM calls with zero code changes. No rip-and-replace required.
The paid Production Program fixes one workflow, one decision question, measurable success criteria, an indicative conversion price, and a sponsor decision date before Enterprise access begins. Teams prove the operating model before expanding it.
A Southeast Asian fintech reached its first production integration in 21 days in its own environment. Four services were integrated and validated at the gateway layer in staging. The platform supplied 87 policies out of the box, and the enabled baseline covered the engineering security requirements without a custom policy. Read the jointly reviewed deployment story.
AxonFlow is source-available and self-hosted. Clone it, run it locally, and evaluate it against your requirements.
Questions? Reach out directly:
hello@getaxonflow.com