AIControlsFrom the creators of Kyverno

Control what agents do.Prove what they did.

AIControls governs every AI agent and model call in your Kubernetes clusters — enforced by policy, logged for audit.

Same policy engine. Additional control points.

AIControls extends Enterprise Kyverno's Admission control with three additional control points for AI workloads and agents — Pipeline, Gateway, and Runtime — so an agent is governed before it ships, on every model and tool call it makes, and while it runs.

AIControls

One engine · One audit log

1 Pipeline Registry · CI/CD · Admission

Verify what ships

AI inventory Trusted components Signed & attested
2 Gateway LLM · MCP · A2A · TLS

Control every call

Inspect prompts & responses Allow · Deny · Require approval Cost & attribution
3 Runtime eBPF · Clusters · Egress

Contain what runs

Shadow AI discovery Secure config Runtime sandboxing
Request & Response Scanning + PII Redaction

Every payload is inspected before it reaches a model — or a person.

Requests are checked for identity and privacy before they go out. Responses are checked for cost, security, and policy before they come back — with PII redacted in both directions and a human gated on anything high-risk.

AIControls Gateway
Your AI
Developers
AI Agents & Apps
Pipelines
1

Pre-Flight

  • Identity
  • Attribution
  • Privacy / PII
2

Mutating policies

  • Routing
  • Optimization
  • Compression
3

Validating policies

  • Cost
  • Security
  • Best practices
4

Dispatch

  • Human in the loop
  • Exceptions
  • Audit logs
What They Reach
AI Models
Tools & MCP Servers
Agents & Services
Agent Action Graph & Session Replay for Forensics

Every action traces back to an identity, replayable step by step.

Not a log to correlate by hand. A graph of who delegated to which agent, every tool it called, every resource it touched — with the policy verdict on each one.

InvestigateFull arguments, identity and timing on any node.
ReplayThe session in order, with the rule that judged each step.
RemediateTurn any finding into an enforced Kyverno policy, in one click.
Gateway & Runtime Controls

The controls a security review actually asks for.

Governance enforced while the agent is acting, not policy reviewed after the fact. Real screens from AIControls running on real clusters — not hypothetical failure modes.

Shadow AI Discovery

Finds the MCP servers nobody registered.

AIControls builds a live inventory of every server your agents actually talk to — not just the ones your team knows about.

AIControls MCP Servers inventory flagging an ungoverned server
One-click Promote or Block for ungoverned servers
Prompt Injection Defense

Checks what comes back, not just what goes out.

Most content-safety tools only scan an agent’s outbound request. AIControls scans the response too — catching an attack hidden in a document before the agent ever reads it.

AIControls blocking a prompt injection hidden in a tool response
Blocks the injected instructions before the agent ever sees them
Agent Behavior Anomaly Detection

Catches an agent drifting, not just going over budget.

AIControls baselines each agent’s normal token use, call rate, and prompt patterns, and flags the moment one breaks its own pattern — before a monthly cap would ever notice.

AIControls flagging a session that spiked 65% past its own baseline
82,450 calls vs. a 50,000 baseline — 65% over
Kill Switch

Takes a misbehaving agent off the network in one click.

No policy to write, no deploy to wait on. Scope it to all traffic, MCP only, LLM only, or just egress — and fully reversible.

AIControls kill switch modal scoping enforcement to all traffic, MCP, LLM, or egress
Scope the kill switch to MCP, LLM, egress — or everything
Human in the Loop

High-risk actions get a person, not a checkbox.

A hard cap either blocks real work or gets overridden under pressure. AIControls holds the request for a named approver instead — decision on record, no ticket thread.

AIControls policy exception request awaiting human approval
Routes exceptions to a human — nothing ships without approval

Built to earn your security team’s trust.

Identity your IdP already issues, enforcement your auditors already understand.

Identity provider

Who is this agent, and what is it entitled to reach?

AIControls · Gateway & Runtime Controls

What is the agent doing right now — and should it be allowed to proceed?

Kubernetes ServiceAccount Microsoft Entra ID (Azure AD) Okta Google Workspace
Allow Audit Warn Deny Require Approval
NIST AI RMF OWASP LLM Top 10 EU AI Act AI-BOM export
Design partner

"We were already writing Kyverno policies for our clusters. Governing AI agents turned out to be the same language and the same approval process, which is why this took days rather than a quarter."

— AIControls design partner

Complete visibility
Data protection
Cost control
Audit-ready compliance
Also in AIControls

The rest of the platform.

Risk scoring, identity, cost control, and MCP governance — the controls that round out AIControls Gateway.

Agent & Skill risk scores

Composite risk per agent, trust score per tool; cross a threshold and the Kill Switch is one click away.

Agent risk score Skills trust score SIEM forwarding

Identity on every call

Developer, workload, or delegated agent — verified via your IdP.

Okta · Entra ID · Google K8s ServiceAccount XAA / ID-JAG

Cost visibility

Spend attributed to team, user, and model as it happens; budgets enforced before overrun.

Inline budgets Per-model spend

MCP governance

Per-tool and per-datasource policy, argument validation, discovery scoped to identity.

Argument validation Scoped tool discovery

Deploy inline as your LLM/MCP gateway, or as an ext_proc filter in front of Envoy or LiteLLM. HA, PostgreSQL-backed, running in under 30 minutes.

Read the full data sheet (PDF)

See what your agents are calling before you write a single policy.

A short working session on your own clusters — no agent changes, no code changes, nothing enforced until you decide it should be.