Kordane BoundSenseInformation control for AI

Your information. Your rules.

Set the terms before information reaches a model. Protect sensitive values, decide where a request can run and keep a record of the decision.

Demonstrated in the browser · available in pilots

Interactive demonstration

Follow one controlled crossing.

Choose a policy, run a request and inspect the result. See what is protected, where the request may go and which decisions are recorded.

User or applicationSensitive contextAI model or toolResponse or action

Policy profile

Sensitive values are tokenised or redacted, codewords may not leave at all, and the request is routed only to an approved external model.

Synthetic demonstration. Runs deterministically in your browser on fictional data. Nothing is transmitted.

Ready. Choose a profile and run the crossing.

Original requeststays local
Sanitised outbound requestwhat would cross
Policy & audit timelinereviewable trace

    Route: the approved external model.

    authorisedtransformedblockedcontained
    Synthetic model responsewaiting

    Restore is a local substitution inside your browser. Reset clears the request, result, and audit trail.

    Control what is shared.

    Find sensitive values and apply the right treatment: tokenise, redact, keep local or block the request.

    Choose the permitted path.

    Define which models, tools and environments are allowed. Require human approval when the action needs it.

    Understand each decision.

    Review the information found, the policy applied and the destination selected in one trace.

    BoundSense Audit

    One crossing, fully recorded

    The decision record a single synthetic crossing leaves behind.

    Demonstrated
    Kordane BoundSense · AuditCrossing #2481

    Operational briefing (synthetic fixture)

    Policy profile
    Controlled Routing
    Detected
    4 sensitive values, 3 classes
    Transformation
    3 tokenised · 1 redacted
    Environment
    Private cloud / VPC
    Route
    Approved private model
    Restore
    Tokenised values restored locally
    Audit
    8 events recorded, reviewable

    Every crossing produces a reviewable record: what was found, what policy did, where the request went.

    Illustrative decision record · Synthetic data

    Follow the policy and information lifecycle

    Detect

    Sensitive values are found in the request before anything moves: identifiers, codewords, references, contact channels.

    Classify

    Each value is assigned a class your policy can reason about: identity, document, contact, codeword, reference.

    Apply policy

    The active profile decides per class: pass, tokenise, redact, block, or contain. Decisions are explicit and versioned.

    Transform

    Values that may cross in shape but not in substance are tokenised; values that must never cross are redacted at source.

    Route

    The request goes only to an approved destination: external model, private deployment, or a local model with no egress.

    Respond

    The downstream answer returns through the boundary, carrying tokens instead of your originals.

    Inspect

    The answer is checked before anything is restored: an unknown token, a malformed one, or a sensitive value the model produced on its own stops the crossing.

    Restore

    Where policy permits, tokenised values are restored locally, inside your environment, after the crossing.

    Audit

    Each decision lands in a detailed audit trail: what was found, what policy did, where the request went, what came back.

    Explore the decision record
    BoundSense-authorised nodes

    Planned

    The same control plane, placed in each customer-controlled environment rather than only in front of one.

    What may enter

    Which evaluation package or query is allowed to reach this environment at all.

    What may execute

    Which candidate model may run locally, from the set already permitted for the task.

    What may participate

    Which local dataset or source is eligible for this specific run.

    What may leave

    Which metrics, excerpts, structured facts or local answers policy authorises out of the node.

    What record remains

    The crossing record each node keeps locally, and the identity it contributes to the combined record.

    A node is a placement of BoundSense, not a separate product. Nothing here adds a product family or a navigation entry.

    A first conversation

    Start with
    one workflow.

    Tell us the task and where the information must stay. We'll show a relevant example and discuss whether a scoped pilot makes sense.

    Request a demo