THE PRIVATE-AI DEPLOYMENT BLUEPRINT · PART ZENTINELLE
The GRC layer that sees and governs every agent action
Zentinelle sits transparently between your agents and your model providers: it watches everything in a real-time event stream, governs it with 18+ policy evaluators, and keeps tamper-evident evidence your auditors can actually use. MIT licensed, no agent code changes.
A real-time event stream, an audit log chain, a risk register with a 5x5 matrix, and FinOps metering that counts every token whoever owns the keys.
Three integration modes, hooks, a Django proxy or a Go gateway, mean policy lands in front of existing agents as-is. Policy inherits from org to team to deployment to endpoint to user.
One-click packs map controls to SOC2, GDPR, HIPAA, the EU AI Act and NIST AI RMF, so the drawing your engineers deploy is the drawing your auditors sign.
| Integration | Hooks · Django proxy · Go gateway, no code changes |
|---|---|
| Policy | 24 evaluators, org-to-user inheritance, RBAC + ABAC |
| Evidence | Audit log chain, risk register, 5x5 risk matrix |
| Metering | FinOps token metering across every mode |
| Licensing | MIT, open source |
| BROCS coverage | Control + Secure (owns) · Observe |
O · Observe tech sheet C · Control tech sheet S · Secure tech sheet
Calliope AI WorkbenchThe browser bench for everyone who works with AI
AstroliftThe cloud-agnostic PaaS that runs whatever you build