AI Governance

The evidence and certification layer for the AI your company uses.

Joopler is the verifiable-evidence and GRC layer that sits under your AI gateway, not another gateway to rip and replace. It discovers shadow AI from your identity graph, ingests your gateway and SWG/CASB logs, inventories every tool, and produces a verifiable no-training proof. It also governs your agents - the ones you operate, with a register, a named owner, a signed step-by-step trace of every run and a stop button, and the ones you bought, through the credentials they hold and a containment drill that is graded rather than assumed. Every AI interaction flows into the same tamper-evident, cryptographically signed evidence ledger.

AI usage, mapped and signed

Sanctioned Shadow / rogue
ava395 callsmarcus500 callspriya258 callsjonas410 callselena252 callstomas250 callsaisha306 callsli-wei305 callssofia272 callsnoah258 callsyuki213 callsdana304 callsomar261 callssupport-agent960 callssales-copilot690 callsci-runner730 callsdata-pipeline850 callsdoc-summarizer544 callssre-oncall-bot570 callsrecruiting-screener476 callsAnthropic1860 callsOpenAI1815 callsAzure OpenAI1395 callsGemini650 callsBedrock1005 callsMistral255 callsCohere275 callsGitHub Copilot490 callsChatGPT466 calls · unapprovedDeepSeek194 calls · unapprovedPerplexity149 calls · unapprovedClaude.ai174 calls · unapprovedGrok76 calls · unapproved

Hover a person or provider to trace their traffic.

Calls per day

35,440 in 14 days · 1990 rogue

Illustrative product preview. Every call is signed to the tamper-evident ledger.

The stack

Visibility, governance, and proof, in one loop.

AI gateways stop at inline control and DLP. Joopler works with the gateway you already run, ingesting its logs, or gives you a gateway of its own, and adds the identity graph you already connect plus cryptographic, independently verifiable evidence, the parts a gateway does not give you.

Shadow-AI discovery

Find unsanctioned AI tools straight from your identity provider (Okta, Entra, Google). AI SaaS shows up as OAuth grants, so we enumerate it with no proxy and no endpoint agent. ChatGPT, Claude, Gemini, Copilot, Cursor, Perplexity, and more.

AI asset inventory

One inventory of every AI tool in use, unifying discovered apps, gateway usage, and configured connectors, with a sanction toggle. The mandatory inventory artifact for AI-governance frameworks.

Reverse-proxy gateway

For the AI your team builds, point your app's LLM SDK at Joopler instead of the provider. Enforce per-tenant model allow and block lists, block on detected secrets, and record every request as signed evidence. Anthropic, OpenAI, and Amazon Bedrock (Nova Pro).

Content inspection and enforcement

On requests that flow through Joopler's gateway or inline proxy: classified detection of secrets, keys, and PII with severity and data classification, Luhn-validated cards to cut false positives, prompt-injection detection, and model-response inspection for leakage, with block-on-secret enforcement. Deterministic and cheap. Full content inspection on the inline proxy runs in terminate mode, which uses your organization's existing MITM CA; without a CA the proxy stays in visibility-only observe mode.

Verifiable no-training proof

A signed, independently verifiable proof that your AI usage ran through no-training API endpoints and that consumer-app exposure is bounded by the shadow-AI inventory. The artifact an AI vendor hands its own customers.

AI usage monitoring

Full visibility by provider, model, user, and action. Ingest your existing gateway or SWG and CASB logs (Zscaler, Netskope), route the AI you build through the reverse-proxy gateway, or point devices and agents at Joopler's live inline egress proxy (proxy.joopler.com). Every event links back to a signed ledger record.

Agents

Everyone governs the call. Joopler governs the run.

An agent is not another AI tool. A tool is something your staff use; an agent acts on your systems, unattended, on somebody's behalf - whether you built it or bought it. That is a different set of obligations, and the question asked after an incident is never about a single prompt. It is about the run.

A register, with an owner

Every agent you operate is recorded with its purpose, one named accountable person, an approved level of autonomy - suggests only, acts with human approval, or autonomous - and the limits it runs under: which tools it may call, how many actions and how much spend per run and per day, and the data sensitivity above which a human must approve. An agent producing activity that nobody registered is reported as a gap.

A trace of every run

Point your agent runtime at Joopler with one SDK wrapper and every run is recorded step by step: the model calls, the tool calls, the systems it touched, where policy refused it, and where a human approved. Each step is signed into the evidence ledger and the finished run is signed as one record. Arguments are never stored, only a hash, so the trail is verifiable without Joopler holding your content.

Tool servers you can trust

A tool's description is an instruction the model follows, so approving a tool server by name approves nothing. Joopler pins approval to a fingerprint of that server's tool definitions and flags a server that keeps its names and quietly rewrites what they say - the agent supply-chain change no inventory tracking names can see. Agents can be held to approved servers only.

Limits that bite, and a stop button

Ask before the action and the answer is allow, deny, or waiting on a human - a refusal prevents the action rather than annotating it afterwards. Stopping an agent refuses everything it asks from then on and revokes its credential in the same act, and that stop is exercised as a drill so it is a control you have tested rather than a claim you have made.

You will buy more agents than you build

A support agent, a research assistant, a coding agent, an agent inside a suite you already pay for. Each arrives holding credentials into your systems, and not one of them will ever call an API you control to ask permission. That does not put them outside governance - it moves the governance to the credentials they hold.

Pick it from a catalogue, not a form

The support, research, coding and workflow agents actually on the market are already in Joopler, with their category, the systems they typically reach, and whether the vendor hosts them. Registering one your company bought is a click rather than a description you have to write.

Discovery hands you a list to approve

The same catalogue is what discovery matches against, so an agent nobody registered arrives already identified as the product it is. You approve it into the register instead of opening an investigation into what it might be.

Permissions measured against what you approved

Not against what it had yesterday. When a vendor quietly widens what its agent can touch, that is drift, and it is scored by how far the new reach goes - directory or identity access reads differently from the ability to write, and both read differently from read access. Permissions being removed never raises the severity.

Containment, and proof you have practised it

You cannot put a check in front of an agent running on somebody else's infrastructure, so containment means revoking the credential where it actually lives. Joopler gives you the real revocation path at each provider, fastest first, and says which take effect immediately and which wait for a token to expire. Running it is a graded exercise: confirmed effect records as proven, action-without-observation records as attested, and the two stay different words.

One consequence worth stating plainly: on an agent you bought, Joopler refuses to record a kill-switch test, because stopping it here would stop nothing and the passing control would be a lie. It sends you to a containment drill against the real credentials instead.

Finding the agents nobody registered

The network is the weakest place to look for an agent. A tool server running locally never crosses it, a model invoked inside your own cloud never leaves it, and at the TLS layer an agent and a person calling the same provider look identical. So Joopler looks in the four places agents actually show themselves, in the order they are worth trusting.

Your identity graph

Machine credentials and client-credential apps holding AI grants, read live from Okta and Entra. An agent has to hold credentials to act, and a credential is far more findable than a packet.

Your own cloud

Model activity by the role that invoked it, read from CloudTrail. This traffic never leaves your cloud, so no proxy, secure web gateway or CASB can see it at all.

Developer machines and repositories

Tool-server configuration and agent frameworks found through your MDM or a repository scan. This is the only way a tool server running locally is found.

Your AI traffic

Cadence, hours and client in your own telemetry. Destination tells you nothing here, so this raises an actor for a human to look at rather than declaring it an agent.

Running the models yourself?

Moving AI in-house does not remove the governance obligations, it removes the vendor who was quietly meeting some of them for you. We deploy and support local AI for small and mid-sized businesses, with the evidence trail built in from day one.

Local AI managed services
AI-provider governance

Prove your AI providers are configured safely.

Read-only connectors check your AI vendor org settings through their admin APIs and turn the result into verifiable evidence that maps to controls.

Anthropic

Admin hygiene and workspace-scoped API keys, no unscoped org-wide keys.

OpenAI

Owner hygiene and audit-log access on the organization.

Microsoft Copilot

Global Admin hygiene, MFA Conditional Access, and directory audit logging.

Framework-ready

ISO/IEC 42001, the NIST AI RMF, and the EU AI Act all have controls mapped today, so Joopler governs AI, inventories it, and maps the evidence to every major AI framework in one loop. Because everything is modeled in OSCAL, adding the next framework is a mapping exercise, not a re-platform.

ISO 42001 mappedNIST AI RMF mappedEU AI Act mapped

And AI works for you, too.

Joopler does not just govern the AI you use. Its compliance assistant reads your live control state, flags what is failing or drifting toward failure before it breaks, and recommends the fix, grounded in your real data so it never invents a control or a number.

See the full platform

Put every AI under governance.

Discover it, govern it through your gateway or ours, and prove it, with evidence anyone can verify.