Governance runtime for AI agents

Autonomy, under oath.

Your agents are already acting. EcoCloud is the runtime that governs every action — checked against your constitution, signed, audit-chained, and reversible. Before it happens.

57
Governance kernels
ES256
Every action signed
~2ms
Per decision
constitution · pass
signed & chained
block #4,182
Scroll
Constitution enforced • ES256 signed • Audit chained • Actions reversible • Deterministic kernels • Human four-eyes Constitution enforced • ES256 signed • Audit chained • Actions reversible • Deterministic kernels • Human four-eyes

Agents are
shipping. Nothing
is checking them.

Every team is handing real work to autonomous agents. But an LLM is trained to be helpful — not to be governed. One injected web page, one over-broad tool call, one silent failure mid-workflow, and the damage is already done.

Ungoverned
  • Policy lives in the prompt — which the next input can override.
  • No signed record of what ran, when, or why.
  • A failure on step four leaves three systems out of sync.
  • Compliance means exporting the whole database and hoping.
On EcoCloud
  • Policy lives at the action layer — enforced before the tool call executes.
  • Every action is notarized — ES256-signed and hash-chained.
  • Failures self-heal — a saga planner unwinds the steps in order.
  • Compliance is a signed receipt — verifiable without the raw data.
The platform

One runtime between your
agents and the real world.

Not a smarter assistant. A layer that decides what an autonomous agent is permitted to do — deterministically, and on the record.

01 / CONSTITUTION

Policy at the
action layer.

A machine-readable constitution gates every tool call before it runs — allow, stage for a human, or deny. Priority caps, quiet hours, forbidden verbs, rate limits, four-eyes thresholds. The rule lives in the runtime, not the model — so the next injected prompt can’t argue its way past it.

§
02 / RECEIPTS

Every action, notarized.

Each completed action mints an ES256-signed receipt, hash-chained to the last. Verify it offline — no database access required.

03 / ACTION GATE

An intent firewall.

When an agent drives a browser, every navigate, click and request is screened first — exfiltration, credential fields and off-allowlist egress blocked before they fire.

04 / SELF-HEALING

Failures that unwind themselves.

When a five-step workflow across five systems trips on step four, a deterministic saga planner computes the compensations and rolls the world back in dependency order — no half-finished state left behind.

05 / KERNELS

57 primitives. All deterministic.

Constitution, injection defence, authorization, saga, netting, reputation, critical path — zero-dependency governance kernels that return the same signed answer every time. Open, inspectable, Apache-2.0.

Proof, not promises

We don’t ask for
trust. We sign for it.

No logos to flash yet — just receipts anyone can verify. Governance you can prove is the only kind that scales to machines.

57
Deterministic
governance kernels
100%
Reproducible —
same input, same proof
~2ms
Per decision at
the edge
ES256
Signed & hash-chained,
offline-verifiable

Every claim above is measured or open-source — verify it yourself.

The governed loop

Six steps
between intent
and outcome.

01

Parse

Plain intent becomes a structured, typed action — owner, deadline, risk band and scope resolved before anything runs.
02

Constitution

The action is checked against your workspace rules. Out of bounds? It’s denied or staged for a human — never silently executed.
03

Route

The runtime picks the model or connector by capability, cost and privacy — with the cheapest safe option that clears policy.
04

Sign

The result is sealed with an ES256 signature and linked to the previous block — a tamper-evident chain of everything that happened.
05

Receipt

A compact, verifiable receipt is issued. Auditors confirm conformance without ever touching the sensitive payload.
06

Undo

Anything can be reversed. A saga planner computes the compensations and rolls dependent systems back, in order.
Step 01 — Intake
01
Parse
Start free

Priced for the work,
not the seat.

Full governance on every tier — the difference is scale. Bring your own model key, or use ours.

Solo
For one operator running their first governed agents.
$0
  • Full constitution & audit chain
  • 25 AI dispatches / month
  • Signed outcome receipts
  • All 57 kernels, client-side
Start free
Most teams
Pro
For teams putting agents on real, revenue-bearing work.
$12 / seat · mo
  • Unlimited AI dispatch
  • Team roles, four-eyes & delegation
  • 26 governed connectors
  • Bring-your-own model key
Start free, upgrade later
Enterprise
Outcome-priced governance for regulated operations.
Let’s talk
  • Custom constitution authoring
  • SSO / SAML & audit exports
  • Continuous compliance feed
  • On-prem kernel deployment
Book a walkthrough
Ship autonomy you can defend

Let the agents
run. Keep control.

Give your agents a conscience — enforced, signed, and reversible. Set up your first governed workspace in minutes.