Protect · Compliance layer

Build the tamper-proof record regulators require.

Protect is the compliance layer. It turns your live agent traffic into the evidence chain, the disclosures, and the residency guarantees your legal, compliance, and audit teams need. Privacy is enforced by architecture: raw content stays under your control.

11 compliance frameworks
EU AI ActGDPRSOC 2 Type IIHIPAAISO 27001ISO 42001 (AI)PCI-DSSNIST AI RMFDPDPA (India)Colorado AI ActSOX

Tamper-evident audit trail

Every event — every prompt evaluated, every action blocked, every approval routed — is hashed into a chain. If anyone tries to alter or remove a record, the chain breaks and the inconsistency is visible.

Append-only · 5-year retention · No deletion API

Auditor-ready compliance reports

Click a framework. Get a report with Policy → Rule → Evidence → Pass-rate traceability — already filled in from your live traffic. What used to take a 4-week consulting engagement becomes a button click.

11 frameworks · Generated from real traffic · PDF + JSON export

Disclaimers, automatically

When the model gives medical, legal, or financial output, Cerberus prepends or appends the right disclaimer based on your policy. No duplicates, no ad-hoc edits, configurable per agent.

YAML or GUI policy · Hot-reload · Per-agent overrides

Internal-thinking trace stripping

Many models leak their internal chain-of-thought tags in responses. We strip them before the response reaches your user — cleanly handling streaming responses across chunk boundaries.

Streaming-safe · Customizable tag patterns

Language enforcement

If your customer-facing agent must respond in approved languages only, we detect the language of every response and enforce the allow-list.

Fail-open on short text · Allow-list per agent

Data residency by architecture

Raw prompt and response content stays encrypted on your own infrastructure. Only metadata — agent ID, risk score, policy decision, ~500 bytes per event — is used by the platform. Aleytheya never sees your prompts.

AES-256-GCM · Customer-controlled storage · Metadata-only architecture