Defensive Intelligence
v2.2.3 · Available now

Defensive Intelligence

Every frontier AI model. The security layer your clients expect.

OBEL™ is a secure AI gateway — PII scrubbed, content classified against sovereign frameworks, and every interaction committed to an immutable audit trail before a single token reaches any model. Use Claude, GPT-4o, Gemini, and more with the confidence your professional obligations demand.

Start free trialSign in
PII ScrubbingSovereign PacksDocument StudioAgentic FoundryGoverned RAG

14-day free trial · no credit card required · see pricing →

Enterprise or government deployment? Request a briefing →

From the OBEL™ Intelligence Brief · April 2026

The AI governance gap is widening.

Enterprise Architecture

The AI governance gap is structural — and widening

It's not a capability problem. Frontier models are extraordinarily capable. The barrier is governance — and it compounds with every agentic deployment. Every organisation with a compliance function faces it. Most have no answer.

35%+ CAGRenterprise AI adoption growth

Agentic Security

Agent tool calls are the new attack surface

An autonomous agent may execute dozens of LLM sub-steps, access file systems, query databases, and call external APIs — all without human review. Each tool call is a potential data egress event, a sovereignty violation, and an audit gap.

Zero trustapplied to every tool invocation

Autonomic Discovery

Static rule sets can't keep up with dynamic threats

Any fixed pattern library is a snapshot of yesterday's threat landscape. OBEL™'s Autonomic Discovery Engine closes this gap continuously — the security perimeter grows with each organisation's interaction patterns, not when a vendor ships a patch.

Real-timepattern discovery and proposal
Read the full whitepaper
PII redacted before inferenceSovereign FAIL-SHUT gateAES-256-GCM encrypted vaultTamper-evident audit vaultRow-level data isolationNo data used for model trainingSIEM-ready event streamHITL gate on every agent actionGoverned RAG — ARGUS-i™ at retrieval, not just ingest

Works with the providers your team already uses

Anthropic

Claude

OpenAI

GPT · o-series

Google

Gemini

Meta

Llama via Groq

Azure OpenAI

Microsoft

Groq

LPU Inference

And more

View integrations

Live demo

ARGUS-i™ Classification in action

Type any message and see how OBEL classifies it before it reaches any AI model.

ARGUS-i™ Live Demo

Sovereign PII Scrubber & Classification Engine

Presets
Raw Input215 / 2000
Sovereign Scrutiny

Output appears here…

Audit Vault · Live Stream

Awaiting scan…

Defensive Intelligence

Gateway Architecture

Every request follows this path — no exceptions.

Scrubbing and classification run at $0.00. Inference only starts if the gate passes. A blocked request costs nothing — the model never sees it.

01

Receive

Raw prompt enters the gateway. OBEL intercepts before any AI model sees the text.

$0.00
02

Scrub

PII, API keys, and injection patterns stripped. The cleaned text advances — the original never leaves.

$0.00
03

Classify & Gate

ARGUS-i™ applies sovereign schema. PROTECTED+ content is hard-blocked here — the model is never called.

blocked = $0.00
04

Inference

Only gate-cleared, scrubbed prompts reach the model. You're billed on the cleaned input — never the raw text.

← billed here
05

Audit

Every interaction committed to the immutable vault before this step completes. No audit write, no inference proceeds.

$0.00

Other AI gateway providers may offer PII scrubbing — but only on paid tiers, without sovereign classification and without a pre-inference audit write. OBEL™ runs this pipeline on every request, on every plan, with no bypass.

Platform capabilities

Everything your team needs.Nothing that shouldn't be there.

PII Scrubbing

Every prompt is scanned and redacted before it reaches any model — names, emails, phone numbers, tax file numbers, financial identifiers, and credentials stripped at the gateway.

  • Enforced before every inference call
  • Audit event written per matched value
  • Block mode or audit mode per organisation

Sovereign Classification

ARGUS-i™ classifies every message in real time against PSPF, ISM, NZISM, UK NCSC, NIST, and NATO schemas. PROTECTED+ content is hard-blocked before inference — no bypass possible.

  • FAIL-SHUT gate — never FAIL-OPEN
  • Immutable sovereign schema per release
  • Configurable block threshold per tier

Tamper-Evident Audit Trail

Every AI interaction is committed to an immutable audit vault before the model is called. If the write fails, inference does not proceed. The commit identifier changes if any record is altered.

  • Pre-LLM blocking write — no audit, no inference
  • Append-only — no silent deletion
  • Cryptographic record per session

Cost Governance

Per-user and per-org spend limits enforced at the gateway before inference runs. No charge on blocked requests. Prepay credit and real-time usage visible to every admin.

  • Budget check before every LLM call
  • Prepay credit — impossible to overspend
  • Department-level sub-allocations

AES-256-GCM Credential Vault

API keys and secrets encrypted at rest with per-record nonces — reusing a nonce is cryptographically impossible. Decryption occurs server-side only. Keys never leave in plaintext.

  • Per-record nonces — no IV reuse
  • Key hint stored for rotation verification
  • Vault key never in the database

Multi-Tenant Workspaces

Row-level security isolates every organisation at the database layer. Every query is scoped to the authenticated user's organisation. Zero cross-tenant data access — ever.

  • Row-level security on every table
  • Admin role + department management
  • Service role never exposed to browser

Multi-Provider Model Routing

Access frontier models from OpenAI, Anthropic, Google, Meta, Azure, and more — all through one governed interface. Switch providers without changing your workflow or losing governance posture.

  • OpenAI · Anthropic · Google · Meta · Azure
  • Consistent governance across all providers
  • Model selection without API key exposure

Governed Image Generation

FLUX.1 and GPT Image 2 with ARGUS-i™ applied to every generation request — classification, PII scrubbing, NSFW pre-flight filtering, and C2PA provenance metadata stamped on every file.

  • Full ARGUS-i™ pipeline on every prompt
  • NSFW block before generation API called
  • C2PA provenance — attribution persists across platforms

SIEM Integration

Forward every governance event to your existing SIEM in real time — scrubber hits, classification decisions, blocked requests, audit writes, agent tool calls, and HITL actions. Configurable per organisation, with optional content inclusion under admin control.

  • Splunk · Microsoft Sentinel · Elastic · any webhook SIEM
  • Agent run events and tool call outcomes included
  • Optional content payload — off by default, admin-gated

Integrations & Skills Hub

Connect your enterprise stack — Notion, Jira, Salesforce, HubSpot, Slack, GitHub, Google Workspace, Zendesk, Asana, Linear, Workday, Outlook, and more. Each connection unlocks a governed set of skills your agents can invoke.

  • 15+ enterprise apps via MCP
  • Per-app token vault — AES-256-GCM encrypted
  • Skills gated through ARGUS-i™ on every invocation

Agentic Foundry

Deploy governed autonomous agents that connect to your real systems. Mention @AgentName in chat to dispatch a task. Every tool call is inspected, every action can require human approval before it executes.

  • @mention dispatch — route tasks to agents in chat
  • HITL gate — approve or reject each tool call
  • Blueprint builder — configure authority and connectors without code

Governed Knowledge Bases

Retrieval-Augmented Generation (RAG) with OBEL's full governance stack. Upload your documents and chat with them — without leaking a single sensitive token. ARGUS-i™ classifies, scrubs, and re-scrubs every retrieved chunk before it reaches the model. Your data never trains an external model.

  • PII scrubbed from chunks at ingest and at retrieval
  • PROTECTED+ chunks quarantined — never stored or returned
  • Source citations alongside every answer

Document Studio

Governed AI document generation — every output through the same security gateway.

Draft contracts, reports, code, and diagrams with frontier AI — then export, audit, and reuse them. Every generation request passes through ARGUS-i™ before a word is drafted.

Template Intelligence

A governed document library — seeded and ready.

Every org gets a pre-built library of NDAs, employment contracts, service agreements, statements of work, consulting agreements, and more — each with required fields, formatting rules, and placeholder validation. Define your own types for custom workflows.

10+document types seeded per org

Secure AI Generation

No AI-generated document skips the security layer.

ARGUS-i™ runs on every generation request — classifying intent, scrubbing PII, and blocking sovereign violations before a word is drafted. Documents, code, diagrams, reports, and workflow outputs are all treated as governed artifacts, not free text.

Zero bypassARGUS-i™ on every generation call

Artifact Vault & Export

Every output saved, attributed, and exportable.

Generated artifacts are stored in your org vault — version-controlled and tied to the audit session that produced them. Export any document as a branded PDF. Every export is attributable to a user, a session, and a complete governance record.

Full chainprompt → draft → export → audit

Agentic Foundry

Governed agents that connect to your real systems.

Deploy autonomous agents against Notion, Jira, Salesforce, Slack, and 10+ other enterprise apps. Mention @AgentName in chat to dispatch a task instantly. Every tool call is inspected by ARGUS-i™ and can require a human sign-off before it executes.

@ Mention Dispatch

Route tasks to agents directly from chat.

Type @AgentName followed by a task in any conversation and OBEL™ dispatches it to the correct agent — no context switch, no separate interface. The agent's tool calls, reasoning steps, and final response stream back inline.

@mentionagent dispatch from chat

HITL Governance

Every tool call can require human approval.

Configure agents at any authority level. At Level 1, agents observe and report. At Level 2, agents can act — but high-risk tool calls pause the run, surface a proposed action to an administrator, and wait for approval or rejection before proceeding. The SSE stream stays live throughout.

Zero blind executionHITL gate on every action

Blueprint Builder

Connect apps, set authority, deploy — no code.

The Blueprint builder lets you configure an agent's identity, connected apps, and read/write permissions in a single view. Authority level is automatically derived from the permissions you grant — read-only agents can never write, regardless of what an LLM requests.

Authority-lockedpermission derived from connector config

ARGUS-i™ Detection Packs

Jurisdiction-aware PII rules,
shipped and ready.

ARGUS-i™ ships with certified detection packs covering every major regulatory jurisdiction. Each pack is a portable bundle of regex rules, replacement tokens, and severity classifications — applied to every message before it reaches inference. And if your jurisdiction isn't covered yet, you can add it.

🌐Certified

Global

Universal patterns

🇦🇺Certified

Five Eyes

FVEY intelligence frameworks

🇪🇺Certified

European Union

GDPR · ePrivacy Directive

🌍Certified

MENA

UAE · KSA · Egypt

🌏Certified

Asia-Pacific

SGP PDPA · AUS Privacy Act

🤝Open

Community

Submit for your jurisdiction

Rule Anatomy

Every rule is a regex with a purpose.

Each detection rule carries a pattern, a jurisdiction-scoped replacement token, a severity level (low / medium / high / critical), and a PII event type. ARGUS-i™ evaluates every active rule against every message — before a single token reaches the model.

[REDACTED:VE_CEDULA]replacement convention — zero raw PII to inference

Built-in Coverage

Five certified packs ship with every account.

Global covers universal patterns (emails, phone numbers, API keys). Regional packs add jurisdiction-specific IDs: UK National Insurance, EU VAT numbers, Australian TFNs, UAE Emirates IDs, Singapore NRICs, and more. Every built-in rule is reviewed and certified by ninthLABS.

40+ rulesacross 5 certified packs, active from day one

Community Packs

Your jurisdiction. Your rules. Reviewed and published.

Write a pack.json, validate it against the open schema, and submit it through the OBEL™ governance panel. ninthLABS reviews each pack for schema validity and safety before approving it — once live, it's available to every organisation on the platform.

Any countryVenezuela, Brazil, South Africa — if there's a regulation, it can have a pack

Retrieval-Augmented Generation

RAG your compliance team can actually approve.

Standard RAG retrieves documents and hands them straight to the model. OBEL™ runs every retrieved chunk through ARGUS-i™ classification and PII scrubbing before a single token reaches inference — at retrieval time, not just at upload.

Double Scrub

PII removed at ingest — and again at retrieval.

Most RAG pipelines scrub once at upload and trust the result forever. OBEL™ re-runs the PII scrubber and ARGUS-i™ classifier on every chunk at the moment of retrieval, so updated classification rules apply retroactively — without re-indexing.

2× scrubat ingest and at every retrieval

Source Citations

Every answer is traceable to its source document.

OBEL™ surfaces which chunks grounded each response so your team knows exactly where an answer came from. Every retrieval event is written to the immutable security event log — auditable, exportable, and SIEM-ready.

Full traceabilityevery retrieved chunk cited and logged

Zero Training Risk

Your documents never leave your organisation.

Chunks are stored in your own Supabase instance under pgvector, never sent to a shared embedding service, and never used to fine-tune an external model. Your organisation's row-level isolation boundary holds — even during retrieval.

Zero egressyour data stays in your infrastructure

Start free. Scale when you're ready.

Start with a 14-day free trial — full Individual Pro access, no credit card required. Upgrade to a team plan when you need multi-member workspaces and full governance.

Create free accountCompare plans