ENTERPRISE AI SECURITYSecurity · Compliance · Cost, in one score

Govern every AI across your entire estate.

Most platforms watch one slice of your AI. Kapālins covers the whole estate — every model, copilot and agent — and scores each surface for security, compliance and cost as a single AI Trust Index. The capability, capacity and coverage to make enterprise AI safe to use, at scale.

Whole-estate coverage · 3 modes Security · Compliance · Cost APRA CPS 234 evidence
Live · AI Command Centerdemo tenant · 1,284 AI systems
0 / 100
AI Trust Index · medium
+0 this week · 0 threats stopped today
Agentic runtimelive
0 agents
behaviour + identity guarded
AI securityOWASP
0 blocked
injection · DLP · jailbreak
Compliance20+ frameworks
0%
NIST · APRA · EU AI Act
FinOpson budget
$0k
token spend · DoW guard
Guardrail stream · real time0 / min
    0 policies enforcing0 framework controls mapped0 evidence items
    The whole platform

    60+ capabilities. Every framework. One score.

    Competitors map to one framework and stop at the feature layer. Kapālins maps every capability to OWASP, MITRE ATLAS and NIST at once — then collapses it into a single AI Trust Index. Hover a node, switch the lens, or run an attack scenario and watch it trace through the graph.

    62capabilities11domains20+frameworks1score
    Whole-estate coverage

    The AI we cover.

    Every model, copilot and agent your teams touch — not just your API traffic. 28 providers, brought under one roof through three observation modes and scored as a single AI Trust Index.

    LLM API providers8 providers
    OOpenAIAnthropicGoogle GeminiMistral AICoCohereGrok (xAI)PerplexityDeepSeek
    Cloud AI platforms3 providers
    awsAWS BedrockAzAzure OpenAIGoogle Vertex AI
    Workplace copilots5 providers
    MMicrosoft 365 CopilotGemini for WorkspaceNotion AISlSlack AIZoom AI Companion
    SaaS & developer AI3 providers
    SFSalesforce EinsteinNAServiceNowGlGlean
    Coding & agent tools5 providers
    GitHub CopilotCursorJetBrains AIWindsurfReplit Agent
    Data & ML pipelines4 providers
    DatabricksSnowflake CortexHugging FaceSMAWS SageMaker
    28providers207models6categories3observation modes
    The three modes

    Proxy. Probe. Connector.

    One mode is a gateway. Three modes are coverage — each reaches AI a gateway-only platform can never see.

    MODE 01
    AppLLMK200 allow446 block

    Proxy

    Inline gateway. Full payload visibility and real-time enforcement on every API call — allow, flag or block.

    MODE 02
    CopilotProbescheduled scan · sweep

    Probe

    Scheduled scanning of SaaS-embedded AI — Copilot, Agentforce, Gemini in Workspace — behaviour a gateway never sees.

    MODE 03
    audit-log ingestion

    Connector

    Audit-log ingestion from admin APIs — inventories what is authorised, configured and drifting across the estate.

    A gateway sees one slice. Kapālins runs all three modes — so the AI your teams actually use is governed, not just your API traffic.

    One number for the board

    The AI Trust Index.

    Boards cannot read a forty-tab dashboard. The AI Trust Index is a single 0–100 score — like a credit rating for your AI estate — composed of three weighted pillars, every input traceable to evidence.

    AI Trust Index
    0
    ● MEDIUM · 65–84
    ▲ +11 vs last quarter
    AI Security weight 50%86 / 100
    Measured across Proxy, Probe, Connector and the Recon questionnaire — the whole estate, not just the gateway.
    AI Compliance weight 30%70 / 100
    APRA, DPDP, ISO 42001 and NIST mapped continuously from live telemetry, exported as PDF + JSON.
    AI Value weight 20%40 / 100
    FinOps cost attribution and token-budget fences — the CFO's question, answered beside the CISO's.

    Composite 0–100 per tenant. Bands: 85+ good · 65–84 medium · 45–64 high risk · <45 critical. A decision engine, not a dashboard.

    One platform, not seven point tools

    Everything it takes to make enterprise AI trustworthy.

    Hardening, privacy, runtime firewalling, model integrity, governance, compliance and cost — one control plane. Stop stitching five vendors together to govern one estate.

    01

    LLM Hardening

    Prompt-injection and jailbreak defence, output validation and runtime enforcement — every deployment hardened before it ships.

    02

    AI Privacy & Data Governance

    PII and sensitive-data detection, prompt privacy, cross-border governance and AI data lineage — with regulator-ready evidence.

    03

    LLM Firewall · Policy Shield

    A 23-rule policy catalogue: prompt filtering, cross-tenant blocking, agent guardrails. Detect & shadow GA; block mode rolling out rule-by-rule.

    04

    Model Integrity & Trust

    The AI Trust Index, runtime drift visibility and exposure analysis — evidence-linked, never a vanity metric.

    05

    AI Runtime Governance

    Proxy, Probe and Connector: continuous monitoring across the whole estate, with ≤15-minute inventory snapshots.

    06

    AI Compliance & Regulatory Ops

    APRA, DPDP, ISO 42001 and NIST AI RMF — evidence automation and audit readiness generated from live telemetry.

    07

    AI FinOps & Cost Governance

    Attribute AI spend per tool, team and tenant; set budgets; report unit economics — an adjacency no AI-security vendor has claimed.

    Regulation, operationalised

    Regulation as running evidence — not a binder.

    Compliance Shield turns each obligation into continuously-generated evidence: every AI interaction mapped to the controls your auditor actually tests, exported as PDF + JSON.

    AUAPRA CPS 234AUCPS 230INDPDP ActAUPrivacy ActISO42001USNIST AI RMF
    See the APRA mapping
    compliance-shield · evidence chaincontinuous
    §17(b) data classification
    PASS
    §18–23 control mapping
    88%
    §32–34 incident readiness
    GAP
    CPS 230 operational resilience
    79%

    Representative view on synthetic, APRA-labelled data. Figures illustrative.

    Why Kapālins

    Capability. Capacity. Coverage.

    We win on the three things that matter to a regulated enterprise: how much of your AI we can see, how deeply we can govern it, and how completely we can prove it.

    Whole-estate coverage

    Proxy, Probe and Connector reach every model, copilot and agent — not just the API traffic a gateway can see.

    One board number

    Security, compliance and cost composited into a single AI Trust Index your board can act on.

    Security, three ways deep

    Inline enforcement, scheduled probing and audit-log inventory — plus a 330-question Recon assessment.

    APAC-native regulation

    APRA CPS 234/230, DPDP and the Privacy Act as first-class features, mapped continuously from live telemetry.

    au-southeast1 residency

    Your data stays in-country, with evidence — built for Australian prudential expectations.

    AI FinOps

    Cost attribution per tool, team and tenant — an adjacency no AI-security platform has claimed.

    By the numbers

    Procurement-grade from day one.

    No logo wall — verifiable product facts. This is what ships in v1.0.

    0
    observation modes — Proxy · Probe · Connector
    0
    runtime Policy Shield rules
    0
    AI inventory snapshot cadence
    0
    frameworks mapped from live telemetry

    The whole estate, every dimension, one number. That is what enterprise-grade AI governance looks like.

    — Kapālins design principle

    Request a briefing

    Govern your AI before your regulator asks.

    A 30-minute walkthrough of the Trust Index, the three observation modes and your regulator’s evidence chain — on your estate.

    FAQ

    Frequently asked questions

    What is Kapālins?
    Kapālins is an enterprise AI security, governance and FinOps platform. It governs every AI an organisation runs — model, copilot and agent — across the whole estate, scores each for security, compliance and cost as a single AI Trust Index (0–100), enforces policy at the gateway, and proves it with regulator-ready evidence. It is independent and Australian-owned.
    How is Kapālins different from an AI gateway or AI firewall alone?
    A gateway only sees the traffic routed through it. Kapālins covers the whole estate through three observation modes — Proxy (inline gateway), Probe (scheduled probing of model endpoints and AI systems) and Connector (audit-log ingestion) — so it governs AI a gateway-only tool never sees, and unifies security, multi-framework compliance, agentic and identity controls and FinOps in one control plane and one score.
    Which AI providers and models does Kapālins cover?
    28 AI providers and 207 models across six categories: LLM APIs (OpenAI, Anthropic, Google Gemini, Mistral, Cohere, xAI, Perplexity, DeepSeek), cloud AI (AWS Bedrock, Azure OpenAI, Vertex AI), workplace copilots (Microsoft 365 Copilot, Gemini for Workspace, Slack AI), SaaS and developer AI, coding and agent tools (GitHub Copilot, Cursor), and data and ML pipelines (Databricks, Snowflake Cortex).
    How is Kapālins different from Lakera, Prompt Security or Protect AI?
    It is the only independent platform that unifies AI security, multi-framework compliance, agentic and identity controls and FinOps in one control plane and one score — most competitors cover one slice, and several independents have been acquired. Kapālins also offers whole-estate coverage (three modes, not gateway-only) and APAC-native regulatory depth (APRA, MAS, HKMA, BNM, DPDP, PDPA, PIPL).
    Is Kapālins built for regulated enterprises?
    Yes. It is designed for regulated industries — financial services, government, healthcare — with deep APAC coverage and a dual-confidence posture model: attested from assessments and verified from live gateway telemetry.
    How quickly can we see value?
    You connect an AI provider, Kapālins discovers your AI estate (including shadow AI), and returns a risk score and AI Trust Index — typically without changing how teams work. You can start in Detect (observe) mode and move to Enforce (block) when ready.
    Where is our data hosted — is it data-resident?
    Kapālins is Australian-owned with in-country (Australia) data residency. A Sovereign deployment overlay (air-gapped and fully data-resident, built on Fortress) is on the roadmap for the highest-assurance environments.
    Does Kapālins replace our existing security stack?
    No — it governs the AI layer specifically and complements your stack. It ingests audit logs via Connector and feeds findings to XDR and SIEM, mapping every capability to OWASP LLM Top 10, MITRE ATLAS and NIST AI RMF at once.