What it is
The control layer between your agents and your company: it blocks what you forbid and turns everything else into sealed, verifiable evidence.
Talk to AxpathHow it works
agent › delete /Clients/report.xlsxBLOCKEDThe rule stops the action before it runs — on your machine and with no other AI involved.
Each entry is linked to the one before: if anyone changes something, it shows. Only metadata and fingerprints — never the content.
Every few minutes, an independent third party certifies the date and time of the accumulated record.
And it is kept in a file that cannot be altered or deleted.
Anyone can reproduce the check on their own, without having to trust Axpath.
Control & evidence
Block. Seal. Verify.
Logs are not proof. Agents act. Axpath attests.
Clients & partners
Your agents already operate under DORA, GDPR and NIS2. What you don't have is the evidence. Compliance Packs translate each regulation into rules and evidence ready for your supervisor, your data protection officer (DPO) or your auditor.
Your agents are ICT assets. An incident caused by an agent is a classifiable ICT incident, reportable within fixed deadlines — and the board answers for risk management.
Accountability (arts. 5.2 and 24): complying is not enough — you must be able to prove it. Records of processing (art. 30), access traceability (art. 32) and impact assessments (DPIA, art. 35) for agents touching personal data.
ICT risk management, 24/72 h incident reporting and personal liability for executives. An uncontrolled agent is exactly the risk NIS2 requires you to manage and prove.
Assigned human oversight and activity records kept for at least 6 months. When it lands, you'll already be covered: your current evidence is compatible from day one.
Vertical packs on demand: GxP / 21 CFR Part 11 (pharma: inspections require records that cannot be altered) and SOX / ICFR (listed companies: agents with impact on financial reporting). MiFID II / RTS 6 if your agents touch markets.
A personal permission never beats an organization rule. At equal scope, the most restrictive wins. And “never delete without asking” admits no permanent exception, ever.
Curated packs are included. Rules beyond the 3 built-in guardrails are defined in the policy engine.
We can only block what passes through Axpath. Where we don't reach, the rule declares it on its face — an honest alert is worth more than a promised block.
Who wrote it, who approved it, when, and with which source text. Rules cannot be altered once enacted.
A record that only grows, never rewritten: each entry is linked to the one before, so any tampering shows. Sealed every 10 minutes with a date and time certified by an independent third party, and kept in an archive that cannot be altered or deleted.
axpath verify re-checks the entire record and its seals — anyone can run it and get the same result. Export for auditors included.
The rule you write in the chat today is the mandate your CFO signs tomorrow. Same structure, more solemnity.
For banks, insurers and multinationals. Axpath Enterprise will run the rules and the evidence record inside your own infrastructure: your data never leaves; only digital fingerprints of each record go out to be sealed.
In your own cloud or on your own servers. Blocking, records and data stay inside; only digital fingerprints go out to be sealed externally.
Formal empowerments signed with a qualified certificate by the accountable executive. Each mandate is a solemnized rule: same structure, same decision engine, same evidence record.
Every action is checked against your rules before it runs, inside your systems. If a block or approval rule is active and the check cannot be completed, the action does not go through.
Two-signature approval for sensitive actions and exceptions. Limits on amounts and totals per agent, department and period, defined like any other rule.
Independently verifiable report, ready for your supervisor, your auditor and your cyber-risk insurer. On the path to QTSP — qualified sealing, with stronger legal standing in the EU.
Millisecond-by-millisecond reconstruction of any incident from the sealed record. Expert witness pack in PDF plus a standard digital format.
The same chat drafts mandates for the CFO to review and sign with a qualified e-signature. The chat proposes, a human enacts — in the boardroom too.
No. Organization > department > user > personal permission. The only valid exception is one created through that rule's approval flow, with an author, bounded scope and expiry, visible and revocable in the dashboard.
Never. The chat turns your text into structured rules and shows you how it understood them; a human enacts. The AI never decides a block: decisions follow fixed rules, in under 150 ms, with no AI involved at the moment of action.
The rule declares it: guaranteed in the tools Axpath sits inside (Claude Code, Cursor, Windsurf and the tools connected on your own machine); it only watches where we don't reach. An incident in a watched zone generates an alert and evidence, never a broken promise.
No content, ever. Rules look only at descriptive details — who, which action, where, when — and at digital fingerprints of files; no rule needs to read the content itself. Content never leaves your systems.
axpath verify re-checks the entire record and its seals — dates and times certified by an independent third party — and anyone gets the same result, without trusting Axpath. Every decision points to the exact rules that were in force when it was made.
From record to control. Provable.
© 2026 Axpath · Made in the EU