Controlled AI Execution

Every AI task should earn its execution.

Information crosses on your terms.

Kordane decides whether a sensitive task may run, where it may run and which model is sufficient. It records the policy, evaluation evidence, fallback path and final decision.

Controlled AI for sensitive workflows: private cloud, on-premises or isolated infrastructure, with frontier models only when the task genuinely requires them.

  • Private by architecture
  • Policy enforced
  • Auditable by design
  • Deploy where required

What you control

Control the crossing, the execution and the cost.

  1. Control sensitive information

    Detect, classify, transform, or block restricted information before it reaches an AI system.

  2. Control execution

    Run each task only in a permitted environment and preserve the decision that allowed it.

  3. Control model cost

    Use the smallest permitted model capable of meeting the required quality threshold.

Interactive demonstration

Follow one controlled crossing.

See how a request is classified, governed, transformed, routed, executed, restored, and recorded. A user or application takes restricted material to an AI system, and a response or an action comes back. Nothing decides what may leave, which model may see it, or what record remains. Kordane inserts a policy-controlled boundary into that path.

User or applicationSensitive contextAI model or toolResponse or action

Policy profile

Sensitive values are tokenised or redacted, codewords may not leave at all, and the request is routed only to an approved external model.

Synthetic security demonstration. Detection, policy, and transformation run locally in your browser. The model response is generated deterministically for illustration. Nothing is transmitted.

Ready. Choose a profile and run the crossing.

Original requeststays local
Sanitised outbound requestwhat would cross
Policy & audit timelinereviewable trace

    Route: the approved external model.

    authorisedtransformedblockedcontained
    Synthetic model responsewaiting

    Restore is a local substitution inside your browser. Reset clears the request, result, and audit trail.

    The decision record

    An audit log records what happened. A decision record explains why it was allowed.

    Every controlled execution closes with one structured record: the policy that permitted it, the environments that were valid, the models that were considered and the evidence retained. This is a synthetic example.

    Kordane Boundary · Decision recordKDR-2026-0714-00381

    Summarisation of a restricted investigation report was permitted in the private VPC using the specialised private model, which cleared the 0.92 quality threshold. Protected identifiers were tokenised locally before the crossing. The approved frontier route is held as fallback only.

    Task
    Summarise a restricted investigation report
    Information class
    Restricted
    Requested by
    Named analyst with authorised case access
    Policy version
    boundary-policy-17
    Permitted environments
    Private VPC · isolated local
    Rejected environment
    Public frontier API, refused for this information class
    Quality threshold
    F1 at or above 0.92 on the case-summary evaluation set
    Transformation
    Protected identifiers tokenised locally
    Fallback condition
    Candidate evaluation falls below 0.92 before deployment or during scheduled re-evaluation; escalation runs through the approved frontier route, after transformation
    Human approval
    Not required for summarisation · required before any external action

    Candidate models

    • local-small-v3rejectedF1 0.89 · Below the 0.92 threshold
    • specialised-private-v2selectedF1 0.94 · Smallest permitted model above threshold
    • approved-frontierfallbackF1 0.96 · Held as fallback; not required

    Evidence retained

    • Policy decision
    • Information classification
    • Transformation record
    • Evaluation set version
    • Candidate comparison
    • Selection reason
    • Fallback path
    • Response provenance
    • Decision identifier

    Synthetic example · Illustrative decision record · Not customer evidence · Not a measured production benchmark

    See the full evidence model

    Control platform

    Two decisions before any task runs.

    Boundary decides whether and where a task may run. Forge decides which permitted model should perform it. Optimisation never overrides policy.

    Not a gateway. Not a masking proxy. Not just a private cloud. The difference is the decision. How Kordane compares

    Applications built on the platform

    • CortexPrivate assistants, document intelligence and speech, grounded in your approved sources.Explore Cortex →
    • AxonCustomer conversation automation with a governed human handoff.Explore Axon →

    Integration between products is configured per workflow and deployment; each product carries its own maturity, stated on its page.

    Explore the product portfolio

    Deployment and trust

    Runs inside your constraints. Proves what it did.

    The same boundary architecture is designed to deploy from approved cloud to fully air-gapped environments, on infrastructure you control. No badges, no absolutes: mechanisms are explained, each control carries its status and limitations are documented.

    The products consolidate working systems the founders have already built; Kordane is opening its first design-partner pilots. The public demonstration is synthetic: deterministic, local logic on fictional data. Production controls are scoped per pilot, and security documentation is shared during qualified pilot discussions.

    Bring one sensitive workflow.

    We will map the information crossing, identify the required controls, recommend an execution pattern, and determine whether a focused pilot is justified.