Deploy AI agents faster with runtime governance.

Give every AI agent a mandate, limits and a paper trail. Stop risky actions and roll agents out with evidence risk teams can review.

Stop risky agent actions before they happen
Clear risk reviews and audits faster
Roll agents out across teams and AI stacks

Explore locally with Community. Use the free Evaluation licence for a self-serve technical assessment. Choose the paid production program when a sponsored workflow must reach a decision against a real deadline.

Explore Locally

Use Community when you are validating fit, integration path, and basic governance controls on your own.

Read getting started β†’
Serious Evaluation

Request a free 90-day Evaluation license when you need higher limits, policy simulation, evidence export, and a more realistic production-readiness test.

Start Safe Evaluation β†’
Sponsored Production Decision

Take one governed workflow into scoped production in 60 or 75 days. Paid programs start at $2,000 and require an executive sponsor.

See the production program β†’

What AxonFlow changes for your business

Stop risky agent actions. Clear reviews and audits faster. Roll agents out across teams and AI stacks.

Mandate and limits

Stop risky agent actions before they happen

Set what an agent may access, change and spend. Block destructive actions, pause consequential steps for a person and set AI usage budgets. For payment agents, fraud controls add checks before money moves.

6,649personal-data redactions at the point of the call during BukuWarung's evaluation. See the product and fraud demos.

Paper trail

Clear risk reviews and audits faster

Every governed action records who initiated it, which rule applied and who approved it. Risk teams and auditors can review evidence captured as agents run instead of rebuilding the story later.

1.3Mmodel and tool calls governed with policy decisions in BukuWarung's 60-day evaluation. Read its story.

One control plane

Roll agents out across teams and AI stacks

Reuse mandates, approvals and evidence across connected coding tools, agent runtimes and application frameworks. Five language SDKs and 20+ documented integration paths help teams start new workflows with controls already in place.

21 daysBukuWarung went from signed agreement to organization-wide AI governance in production in 21 days.

Where AxonFlow stands apart

  • Governs AI where people actually use it. Five language SDKs and 20+ documented integration paths span connected coding tools, agent runtimes and application frameworks. BukuWarung covered 121 users during its production evaluation.
  • Decides on business context, not only access. The amount, the payee, how often a payment repeats, who asked and which workflow is running, not only whether a key may call a tool.
  • Fraud controls at the point a payment agent acts. Hard rules for sanctions, limits, bank-detail changes and structuring, plus an optional early-access risk score that can hold a payment for review.
  • Regulator-ready evidence from the same records. Decision records, configurable signed chains and report exports for the EU AI Act, RBI and SEBI, MAS FEAT and OJK / UU PDP.
  • Runs in your own environment. The decision point and the records stay with you, alongside the gateways, frameworks and model providers you already use.

Also included: deterministic policies, tamper-evident audit logs, human approvals, PII redaction, per-user attribution through SSO and SCIM, and workflows that pick up where they left off without repeating an action. See the product and fraud demos.

Where it pays off first

The same mandate, limits and paper trail lead with a different saving in each industry.

Banking and financial services

Stop risky agent payments, give examiners decision evidence produced as agents run, and roll governed agents out across banking teams.

Explore financial services

Telecommunications

Stop risky account and network changes, control AI spend in care workflows and get agents into service operations faster.

Explore telecom

Government and public sector

Keep consequential citizen decisions under human authority, keep data inside your own environment and get public-service agents live sooner.

Explore public sector

In healthcare, hold clinical and billing actions for a person where it matters, and keep patient data out of model providers. See all industry guides.

BukuWarung
Customer story BukuWarung

AI governance in production in 21 days

A YC and Valar-backed fintech went from signed agreement to organization-wide AI governance in production in 21 days, with 1.3 million model and tool calls governed across 121 users.

Read the case study
21 days
to production
1.3M
governed calls
6,649
PII redactions

See it running. Two short walkthroughs: the platform end to end, and the Fraud & Risk Add-on stopping an attack in flight. ▶ Watch the product demos

By the Time a Log Shows It, the Money Has Moved

A log tells you what an agent did after a risky change ran, sensitive data left or the AI bill arrived. To hand agents real work, the decision has to happen before the agent acts, with a record of why. Without that, companies hit the same four problems.

No record of why

Logs do not explain why

Risk and compliance teams need to know not just that an agent acted, but why it was allowed and who approved it. Without that answer, every new agent waits in review.

Nothing stops the action

Costly steps still slip through

Personal data leaks to model providers, risky actions skip the intended checks, and no one can say whether a retry will repeat a payment without rebuilding the run by hand.

Shadow AI

Teams build without guardrails

Teams adopt AI tools on their own, so no one can see who is using what, under which rules, or at what cost.

Compliance mandates

Compliance is not optional

EU AI Act, HIPAA, GDPR, RBI, and SEBI increasingly require audit trails, human oversight, and data residency for AI systems. EU AI Act fines reach up to 7% of global turnover.

Execution Authority for Production AI

Not another gateway or observability add-on. AxonFlow sits in the execution path, enforces policy, and records decision context while workflows are running.

Internal Systems

Databases Documents APIs Code
β†’

AxonFlow Runtime Authority

πŸ”„ Workflow Decisions

Step gates for existing orchestrators with per-step policy checks, approvals, and execution identity

πŸ”— MCP Integration

Secure connectors to internal systems via Model Context Protocol

πŸ›‘οΈ Policy Enforcement

RBAC, ABAC, and runtime policy checks with deny-by-default execution controls

πŸ“Š Decision Records

Decision context, audit trails, and exportable evidence for engineering, security, and compliance reviews

β†’

LLM Providers

OpenAI Anthropic Bedrock Local

Enterprise-Grade AI Governance

Hot-path policy enforcement designed for production AI systems. Not a bolt-on toolβ€”a native governance layer.

Hot Path
Policy Evaluation
99.9%
Uptime SLA
Up to 2X
Parallel Speedup
80+
Grafana Metrics

Real-Time Policy Enforcement

Low-overhead policy evaluation designed for latency-sensitive AI workflows. In-memory policy engine with deny-by-default security and 5 built-in media safety policies.

  • 23+ PII types (SSN, Aadhaar, PAN, UPI, credit cards, IBAN, more)
  • SQL injection scanning (37+ attack patterns)
  • Prompt injection blocking
  • 5 system media policies (NSFW, violence, biometric, PII, sensitive docs)
  • Custom dynamic policy rules

Workflow Governance

Policy checkpoints for external orchestrators. Each workflow step and tool call is governed independently before execution proceeds.

  • Step gates: allow, block, or require human approval per step
  • Per-tool governance within multi-tool nodes
  • Idempotency keys and retry-aware step gates to prevent duplicate side-effects on replays
  • Circuit breaker with auto-trip on upstream failures
  • Trace correlation with LangSmith, Datadog, OpenTelemetry

Policy-Enforced Data Access (MCP)

Agents access internal systems through Model Context Protocol connectors. Every query is scanned for PII, exfiltration, and policy violations before execution.

  • Pre-execution input scanning (SQLi, PII, compliance)
  • Post-execution output redaction and exfiltration limits
  • Databases, enterprise SaaS, ITSM, and custom connectors
  • Standalone policy check API for orchestrators managing their own MCP execution

Audit Trail & Observability

Immutable audit log for every LLM call, tool invocation, and policy decision. Prometheus/Grafana dashboards included. Evidence support for EU AI Act, HIPAA-oriented, GDPR, RBI, and SEBI workflows.

  • Every AI interaction logged with full request/response capture
  • Tool call audit trail for MCP and function executions
  • 80+ Prometheus metrics, Grafana dashboards included
  • SIEM export (Splunk, Datadog) and compliance report generation

Decision-Oriented Execution Record

Trace why every governed action happened. Beyond a chronological log: a structured, queryable record of every allow / deny / require_approval decision — with the policy version that fired, the rules it matched, and whether an override could unblock it. List recent decisions, explain any one of them, and answer "why is this blocked NOW that wasn't 2 days ago?" without guessing.

  • List recent decisions per tenant, filterable by outcome, policy, or tool
  • Per-decision explainability: matched policies, matched rules, risk level, override availability
  • Policy version at decision time + current head — surface drift between the run that worked and the run that didn't
  • MCP tools across OpenClaw, Claude Code, Cursor, and Codex — agents can introspect their own block history
  • Tier-gated retention so Free users get a taste; paid tiers get full forensic depth

Multi-Model Routing

Vendor-neutral routing across OpenAI, Anthropic, AWS Bedrock, Google, and local models. Automatic failover when providers go down.

  • Route by cost, latency, or model capability
  • Per-step cost tracking and budget enforcement
  • Automatic failover across providers
  • Provider health monitoring with circuit breaker

Drop-In Integration

Add governance to existing AI applications without rewriting code. Works with your current orchestrator, LLM provider, and deployment.

  • SDKs for Python, TypeScript, Go, Java, and Rust (preview)
  • Plugins for OpenClaw, Claude Code, Cursor, and Codex — shared 75+ policy set (Codex uses a hybrid enforced/advisory model; the others enforce inline)
  • LangGraph adapter with per-tool governance built in
  • OpenAI-compatible proxy mode (zero code changes)
  • Self-hosted, telemetry opt-out available

Customer Portal

Full-featured web portal for AI governance operations. Monitor executions, manage approvals, configure policies, and track costs without writing code.

  • Execution Timeline with step-level cost and policy visibility
  • HITL Approval Dashboard with policy context and audit trail
  • Policy management and LLM provider configuration
  • Usage analytics and compliance dashboards
Enterprise

Fraud & Risk Add-on for Agentic Payments

Financial crime controls for agent-initiated transactions, with deterministic blocks and step-ups, advisory risk scoring, decision-API review gates, and attributed evidence in compliance exports.

Explore the add-on → Enterprise Add-on

Compliance-Oriented Controls for Regulated Industries

Framework mappings, runtime controls, and exportable evidence for healthcare, financial services, and EU AI governance reviews.

πŸ‡ͺπŸ‡Ί

EU AI Act

  • Article 14: Human-in-the-Loop (HITL) queue
  • Article 15: Customer-supplied accuracy evidence and runtime records
  • Article 43: Conformity-workflow evidence records
  • Transparency headers on all responses
  • Configurable audit retention by deployment and tier
Enterprise EU AI Act guide →
πŸ‡ΊπŸ‡Έ

US Financial Services

  • Examiner questions: per-decision reconstruction, human oversight, shutdown, data boundaries
  • SR 26-2 / OCC 2026-13: monitoring evidence for your own model risk documentation
  • GLBA Safeguards: records of model and tool calls, each tied to the person who made it
  • US PII: SSN and bank routing/account detection in the community runtime
  • Examination evidence comes from Evidence Export (not included on Community); model validation, fairness testing, and adverse-action notices remain yours
Community + Enterprise US financial services guide →
🏦

RBI FREE-AI Framework

  • AI system registry with approval context
  • Kill Switch for emergency halt
  • Board-report workflow API
  • Retention and export controls
  • RBI-oriented audit export
Enterprise RBI FREE-AI guide →
πŸ“ˆ

SEBI AI/ML Guidelines

  • Long-term audit retention controls
  • SEBI audit export (JSON/CSV/XML)
  • Readiness and retention status
  • Investment-advisory evidence support
  • India PII: Aadhaar and PAN foundations
Enterprise SEBI governance guide →
πŸ₯

HIPAA Healthcare

  • Healthcare PII redaction
  • Customer-controlled deployment with AWS Bedrock
  • HIPAA-oriented audit trails
  • BAA and HIPAA assessment remain customer responsibilities
Enterprise
πŸ”’

GDPR Data Protection

  • EU PII detection (IBAN, passport, etc.)
  • Policy decisions and redaction records
  • Customer-controlled deployment options
  • Lawful basis and data-subject workflows remain application responsibilities
Community + Enterprise
πŸ’³

PCI-DSS

  • Credit card detection (Luhn validation)
  • Cardholder data auto-redaction
  • Audit records for policy decisions
  • PCI DSS assessment remains the customer's responsibility
Community + Enterprise
Explore Compliance Guides →

Source-Available, Self-Hosted, Production-Ready

Clone the repo, run locally, inspect the source. Full platform under the BSL 1.1 license. No vendor lock-in.

πŸ”“

Source-Available

Full source code available under BSL 1.1. Inspect, modify, and deploy on your own infrastructure.

πŸ›‘οΈ

Production-Ready

Policy engine, PII detection, SQL injection scanning, Gateway and Proxy modes included.

πŸ“¦

SDKs and Plugins

Official SDKs for Python, TypeScript, Go, Java, and Rust (preview). Plugins for OpenClaw, Claude Code, Cursor, and Codex — shared 75+ policy set across all four. Integrate in minutes.

View on GitHub Read Documentation

Community vs Evaluation vs Enterprise

Start with Community Edition. Get a free Evaluation license for higher limits and org-wide policies, or upgrade to Enterprise for advanced compliance and connectors.

Feature comparison between Community, Evaluation, and Enterprise tiers
Feature Community Evaluation (Free) Enterprise
Resource Limits
Tenant Policies 20 50 Unlimited
Organization-Wide Policies 0 5 Unlimited
Connectors with Custom Policies 2 5 Unlimited
Audit Log Retention 3 days 14 days 10 years
LLM Providers 2 3 Unlimited
Execution History 50 500 Unlimited
Concurrent Executions 5 25 Unlimited
MAP Plans 25 100 Unlimited
Versions per Plan 10 25 Unlimited
SSE Connections 5 25 Unlimited
Cost Estimates / Day 10 100 Unlimited
Pending Execution Approvals Not applicable Not applicable
Creating approvals needs Professional or higher
Unlimited
Media Analyzers 2 2 Unlimited
Concurrent Executions β€” MAP and WCP executions running at the same time per tenant
Pending Execution Approvals β€” the per-tenant ceiling on entries waiting in the human approval queue. Creating approval entries needs Professional or higher, and those tiers are uncapped, so the finite caps the lower tiers declare are never reached
MAP Plans β€” multi-agent plans that break complex tasks into coordinated steps
Versions per Plan β€” how many revisions of a single MAP plan are retained
SSE Connections β€” server-sent event connections for streaming execution progress in real time
Cost Estimates / Day β€” number of LLM cost estimation requests allowed per day
Execution History β€” completed execution records kept for review and audit
Media Analyzers β€” concurrent image analysis modules (OCR, content safety, face detection) per request
Core Platform
Policy Engine (low-overhead path) βœ“ βœ“ βœ“
PII Detection (12+ types incl. Aadhaar, PAN, UPI) βœ“ βœ“ βœ“
SQL Injection Scanning (Advanced - 37+ patterns) β€” β€” βœ“
Multi-Agent Planning (MAP) βœ“ βœ“ βœ“
Prometheus/Grafana Metrics (80+) βœ“ βœ“ βœ“
Multimodal Image Governance (NSFW, PII, faces, OCR) βœ“ βœ“ βœ“
System Media Policies (NSFW, violence, biometric, PII, sensitive docs) 5 rules (opt-in) 5 rules 5 rules + custom
Cloud Vision Analyzers (AWS Rekognition, Google, Azure) β€” β€” βœ“
LLM Providers
OpenAI, Anthropic, Ollama βœ“ βœ“ βœ“
AWS Bedrock β€” β€” βœ“
MCP Connectors
Database (PostgreSQL, MySQL, MongoDB) βœ“ βœ“ βœ“
Enterprise (Salesforce, Slack, Snowflake, Jira, ServiceNow) β€” β€” βœ“
Compliance Frameworks
GDPR & PCI-DSS βœ“ βœ“ βœ“
EU AI Act, RBI FREE-AI, SEBI, HIPAA (policy templates) β€” β€” βœ“
US PII detection (SSN, bank routing/account) βœ“ βœ“ βœ“
US examination evidence (Evidence Export based) — βœ“
Evidence Export limits apply
βœ“
Enterprise Features
Customer Portal (Execution Timeline, Approval Dashboard, Analytics) β€” β€” βœ“
Human-in-the-Loop, Kill Switch, SSO/SAML β€” β€” βœ“
Per-Tenant Media Governance β€” β€” βœ“
HITL Approval Gates β€” —
Resolve-only; creating approvals needs Professional or higher
βœ“
Policy Simulation β€” βœ“
300/day
βœ“
Unlimited
Evidence Export β€” βœ“
14-day, 3/day
βœ“
Unlimited
24/7 Support + SLA β€” β€” βœ“
Get Community Edition Get Free Evaluation License Run a Paid Production Program

Deploy Anywhere: SaaS or In Your Infrastructure

Start with our managed SaaS or deploy in your VPC/on-premises for complete data sovereignty.

☁️

SaaS Multi-Tenant

Get started in minutes with our fully managed platform. Zero infrastructure overhead with automatic updates.

  • 99.9% uptime SLA
  • Automatic scaling
  • Managed updates
  • 24/7 support
Start Free Trial β†’
πŸ”’

On-Premises

Deploy in your data center for maximum security and compliance requirements.

  • Disconnected-network compatible option
  • Complete sovereignty
  • Custom integrations
  • White-glove support
Contact Sales β†’

Feedback from senior engineers evaluating AxonFlow for production AI governance.

"The governance layer is genuinely useful for production systems where compliance is a hard requirement. It adds real value on top of existing orchestration, not just another wrapper."
Engineering Manager
Data platform team, enterprise marketplace
"This is classic middleware done right. Intercepting execution at a central point and enforcing controls is a proven pattern in reliability engineering. Applying it to LLM calls makes sense."
Senior Staff SRE
Payments infrastructure
"PII redaction, audit trails, and rate limiting are exactly the controls we need before our compliance team will sign off on production LLM use. Integration took less than a day."
Senior Software Engineer
Platform engineering
Nir Chervoni Β· Head of Security Products, Nebius Β· Former Head of Data Security, Booking.com

Infrastructure-Grade AI Governance

AxonFlow is built for the teams responsible for running AI systems safely in production, not for building demos.

⚑
Production-Grade Performance

Hot-path policy enforcement. The governance layer is designed for latency-sensitive request paths, and teams should benchmark it in their own deployment mode and policy mix.

πŸ—οΈ
Self-Hosted, Network-Controlled

Runs entirely in your infrastructure. Prompts, policies, audit logs, and LLM traffic stay in your environment. Anonymous telemetry can be disabled, and deployment can fit customer-controlled network boundaries.

πŸ”’
Built by Infrastructure Engineers

Founded by engineers who built internal platforms at Booking.com (1,500+ engineers, millions of daily users). AxonFlow reflects that operational experience.

🎯
Incremental Adoption

Start in observe-only mode. Add policy enforcement progressively. Gateway mode wraps existing LLM calls with zero code changes. No rip-and-replace required.

πŸ“ˆ
Evidence Before Expansion

The paid Production Program fixes one workflow, one decision question, measurable success criteria, an indicative conversion price, and a sponsor decision date before Enterprise access begins. Teams prove the operating model before expanding it.

🀝
Deployment Evidence From A Design Partnership

A Southeast Asian fintech reached its first production integration in 21 days in its own environment. Four services were integrated and validated at the gateway layer in staging. The platform supplied 87 policies out of the box, and the enabled baseline covered the engineering security requirements without a custom policy. Read the jointly reviewed deployment story.

Start Evaluating

AxonFlow is source-available and self-hosted. Clone it, run it locally, and evaluate it against your requirements.

Evaluate on Your Own

Clone the repo and run locally in 5 minutes

  • Full platform with Docker Compose
  • Policy enforcement, PII detection, audit logging
  • SDKs for Python, TypeScript, Go, Java
View on GitHub β†’

Need higher limits? Get a free Evaluation License

Serious Internal Evaluation

For teams that already have AxonFlow running and want a safer, more realistic production-readiness test.

  • Free 90-day evaluation license
  • Higher limits, policy simulation, evidence export
  • No mandatory sales call, still self-hosted and reversible
Start Safe Evaluation β†’

Paid Production Program

For teams with a dated forcing event, written control requirements, and an executive sponsor who needs a production decision.

  • One scoped production workflow over 60 or 75 days
  • Public Design Partner from $2,000; Confidential Paid Pilot from $4,000
  • Founder-led rollout, evidence readout, and a fixed decision date
Review fit and pricing β†’

Questions? Reach out directly:

hello@getaxonflow.com