What it is

Your rules, above every AI.

The control layer between your agents and your company: it blocks what you forbid and turns everything else into sealed, verifiable evidence.

Talk to Axpath
Acts on

How it works

From rule to proof, in a single chain.

the chat compiles it
R-12 block deleting and modifying in /Clients/** GUARANTEED
agent › delete /Clients/report.xlsxBLOCKED

The rule stops the action before it runs — on your machine and with no other AI involved.

action#a17f…block#c3d4…action#e5f6…

Each entry is linked to the one before: if anyone changes something, it shows. Only metadata and fingerprints — never the content.

Timestamp

Every few minutes, an independent third party certifies the date and time of the accumulated record.

And it is kept in a file that cannot be altered or deleted.

$
✓ chain intact · 1,284 records · seal valid

Anyone can reproduce the check on their own, without having to trust Axpath.

Control & evidence

Block. Seal. Verify.

Logs are not proof. Agents act. Axpath attests.

Clients & partners

BancoraNovasegVolteinMeditraLexangoNubiraKorven SystemsDatalys
Regulation

You don't need a new law to be on the hook.

Your agents already operate under DORA, GDPR and NIS2. What you don't have is the evidence. Compliance Packs translate each regulation into rules and evidence ready for your supervisor, your data protection officer (DPO) or your auditor.

DORA
Launch pack
Banking · insurance · asset managers — in force since January 2025

Your agents are ICT assets. An incident caused by an agent is a classifiable ICT incident, reportable within fixed deadlines — and the board answers for risk management.

GDPR
Launch pack
Every company, of any size — in force

Accountability (arts. 5.2 and 24): complying is not enough — you must be able to prove it. Records of processing (art. 30), access traceability (art. 32) and impact assessments (DPIA, art. 35) for agents touching personal data.

NIS2
Available
Essential and important entities — thousands of mid-size companies

ICT risk management, 24/72 h incident reporting and personal liability for executives. An uncontrolled agent is exactly the risk NIS2 requires you to manage and prove.

AI Act
Pre-built · Dec 2027
Companies using high-risk AI — art. 26

Assigned human oversight and activity records kept for at least 6 months. When it lands, you'll already be covered: your current evidence is compatible from day one.

Vertical packs on demand: GxP / 21 CFR Part 11 (pharma: inspections require records that cannot be altered) and SOX / ICFR (listed companies: agents with impact on financial reporting). MiFID II / RTS 6 if your agents touch markets.

The gap

Permissions are set by each employee. Your policy, by no one.

BUILT-IN CONTROLS
Personal: each employee, on their machine, for themselves
Per tool: Claude Code, Cursor and every connected agent tool, separately
A personal “allow always” can open what the company forbids
THE AXPATH COMPANY-WIDE LAYER
One policy above every AI tool
Organization > department > user > personal permission
Every rule, block and exception: sealed evidence
“Marketing never touches client folders” “Nothing leaves the domain on weekends” “Agent X only reads; it never writes”
The policy engine

Who, which agent, which action, where, when. With receipts.

SUBJECT
organization · department · user · role
AGENT
Claude Code · connected tools · any
ACTION
delete a file · send an email · overwrite code history
TARGET
folders · domains · code repositories
TIME
time slots · days · expiry
EFFECT
block · ask · watch · allow
// active rule
R-12 · organization · block writes to /Shared/Clients/**
any agent · outside Mon–Fri 8am–8pm · enacted by ana@ · event #8F42
Guaranteed in: Claude Code · Cursor · Windsurf · tools connected on your own machine
PRECEDENCE

A personal permission never beats an organization rule. At equal scope, the most restrictive wins. And “never delete without asking” admits no permanent exception, ever.

Curated packs

Policy as a product, not a blank canvas.

DEVELOPMENT / AGENCY
·Code repositories protected, no overwriting the main version
·Nothing outside the domain without approval
·Destructive actions only during working hours
Activate in 1 click
PROFESSIONAL FIRM
·Client folders read-only for agents
·No document leaves without approval
·Accounting out of agents' reach
Activate in 1 click
E-COMMERCE / OPERATIONS
·Catalog untouchable during peak hours
·Bulk emails only with approval
·Daily count limits per agent
Activate in 1 click

Curated packs are included. Rules beyond the 3 built-in guardrails are defined in the policy engine.

Coverage honesty

Every rule states where it blocks and where it only watches.

We can only block what passes through Axpath. Where we don't reach, the rule declares it on its face — an honest alert is worth more than a promised block.

GUARANTEED WATCHED MIXED
// simulate before enacting
$ axpath simulate R-16 --last-week
Would have blocked 3 actions · 41 allowed
1 would have required a partner’s approval
No rule is enacted blind.
Evidence

Everyone will say “control.” Control provable to a third party — that, they won’t.

01
Every rule, a record linked to the one before

Who wrote it, who approved it, when, and with which source text. Rules cannot be altered once enacted.

02
Every block, sealed evidence

A record that only grows, never rewritten: each entry is linked to the one before, so any tampering shows. Sealed every 10 minutes with a date and time certified by an independent third party, and kept in an archive that cannot be altered or deleted.

03
Verifiable without trusting Axpath

axpath verify re-checks the entire record and its seals — anyone can run it and get the same result. Export for auditors included.

FREE
Built-in guardrail
Fixed rule, workspace
PRO
Custom rule
All rule criteria + packs + chat
TEAM
Group policy
Scopes + approvers
ENTERPRISE
Signed mandate
Qualified e-signature + two-person approval + amount limits

The rule you write in the chat today is the mandate your CFO signs tomorrow. Same structure, more solemnity.

Enterprise · Phase 3 — in development

Command and block inside your own systems.

For banks, insurers and multinationals. Axpath Enterprise will run the rules and the evidence record inside your own infrastructure: your data never leaves; only digital fingerprints of each record go out to be sealed.

Installation in your systems

In your own cloud or on your own servers. Blocking, records and data stay inside; only digital fingerprints go out to be sealed externally.

Mandate Registry (qualified e-signature)

Formal empowerments signed with a qualified certificate by the accountable executive. Each mandate is a solemnized rule: same structure, same decision engine, same evidence record.

Blocking at the moment of action

Every action is checked against your rules before it runs, inside your systems. If a block or approval rule is active and the check cannot be completed, the action does not go through.

Two-person approval and amount limits

Two-signature approval for sensitive actions and exceptions. Limits on amounts and totals per agent, department and period, defined like any other rule.

Verifiable quarterly report

Independently verifiable report, ready for your supervisor, your auditor and your cyber-risk insurer. On the path to QTSP — qualified sealing, with stronger legal standing in the EU.

Forensic Replay

Millisecond-by-millisecond reconstruction of any incident from the sealed record. Expert witness pack in PDF plus a standard digital format.

POLICY CHAT ENTERPRISE

The same chat drafts mandates for the CFO to review and sign with a qualified e-signature. The chat proposes, a human enacts — in the boardroom too.

Talk to Axpath about your infrastructure
FAQ

Frequently asked questions

Can an employee bypass a rule with “allow always”?+

No. Organization > department > user > personal permission. The only valid exception is one created through that rule's approval flow, with an author, bounded scope and expiry, visible and revocable in the dashboard.

Can Policy Chat activate rules on its own?+

Never. The chat turns your text into structured rules and shows you how it understood them; a human enacts. The AI never decides a block: decisions follow fixed rules, in under 150 ms, with no AI involved at the moment of action.

What happens where Axpath cannot block?+

The rule declares it: guaranteed in the tools Axpath sits inside (Claude Code, Cursor, Windsurf and the tools connected on your own machine); it only watches where we don't reach. An incident in a watched zone generates an alert and evidence, never a broken promise.

What data leaves my machine?+

No content, ever. Rules look only at descriptive details — who, which action, where, when — and at digital fingerprints of files; no rule needs to read the content itself. Content never leaves your systems.

How do I prove it to an insurer or a judge?+

axpath verify re-checks the entire record and its seals — dates and times certified by an independent third party — and anyone gets the same result, without trusting Axpath. Every decision points to the exact rules that were in force when it was made.

Agents act. Axpath attests.
ax/path_

From record to control. Provable.

© 2026 Axpath · Made in the EU

PRODUCT
Activity record Policies Enterprise
RESOURCES
Docs GitHub Status
LEGAL
Privacy Terms Security