EDEFENSIVE INTELLIGENCE
Defensive
Intelligence
Built for the security review, not around it

Solutions · CISOs

The governance layer your security review will actually approve.

OBEL™ puts scrubbing, classification, an immutable audit trail, and tenant isolation on every prompt - not as a bolt-on, but as the architecture every conversation runs through.

Request a security briefingSecurity overview

Scrub before send

PII and secrets are removed before any prompt reaches a model - not detected after the fact.

Runs inline on every request - pattern and entropy detection tuned for PII, secrets, and credentials, with no added latency budget.

FAIL-SHUT, not FAIL-OPEN

If classification ever fails or times out, the request is denied. Availability never overrides risk.

A classifier outage fails safe, not silent - your riskiest requests never slip through during a glitch.

Immutable by design

Audit records are append-only - no retroactive edits, no silent deletion, ever.

Every commit is hash-chained; altering a past record breaks the chain and is detectable on the next audit pass.

RLS on every table

Tenant isolation is enforced at the database layer, not just in application logic.

Row-level security policies scope every query to the authenticated tenant - a bug in application code can't leak across orgs.

Quota enforced, not reported

Spend and access limits are checked before the call, not flagged in a dashboard afterward.

Budgets are a gate before the API call fires, not a report you check after the invoice - overspend is structurally prevented.

SIEM-native

Governance events stream into the tools your SOC already watches - Splunk, Sentinel, Elastic, or webhook.

Structured events map onto schemas your SOC already trusts, so this becomes another feed - not a new console to monitor.

Capabilities

Everything a security review needs answered before rollout.

PII & Secret Scrubbing

  • Every prompt passes through the scrubber before it reaches any model - no bypass, no dry-run mode
  • Detects PII, credentials, API keys, and secrets before they leave your network boundary
  • A security event is written before the LLM call proceeds whenever a hit occurs
  • The cleaned text - never the original - is what gets sent to the model
  • Individual Pro users can opt out on their own sessions only, under an explicit, audited exception

ARGUS-i™ Classification

  • Every interaction classified before inference - scan order and sovereign schema are version-locked
  • Configurable block thresholds, up to a FAIL-SHUT sovereign gate for the most sensitive tiers
  • If the classifier errors or times out, the request is denied - never FAIL-OPEN
  • Classification decisions logged to the audit trail alongside the interaction itself
  • Extends to agentic tool calls - every tool invocation is classified before it executes

Immutable Audit Trail

  • Every conversation committed to a tamper-evident, append-only audit vault
  • Commit dispatched asynchronously - never blocks the user-facing response
  • No silent deletion, no retroactive modification of committed records
  • Compliance-ready export in JSON and CSV for internal review or regulator requests
  • Audit trail spans chat, agent tool calls, and HITL approval decisions in one place

Tenant Isolation & Access Control

  • Row-level security enforced at the database layer - every table, no exceptions
  • Application code always queries via the scoped user client, never the service-role client
  • Role-based access - org admin, department lead, end user - all audited
  • AES-256-GCM encryption at rest for stored keys and tokens; TLS in transit
  • SSO/identity federation for centralised access control and deprovisioning

Cost & Quota Enforcement

  • Hard spend caps enforced before an LLM call - quota checked, not just reported after the fact
  • Per-user, per-department, and org-wide budgets with automatic soft-blocks
  • Blocked-account states checked on every request - suspended users can't slip through
  • Real-time visibility into who is spending what, on which model
  • Removes the open-ended cost exposure that comes with unmanaged AI tool sprawl

SIEM & Governance Integration

  • Governance events - scrubber hits, classification decisions, agent tool calls, HITL approvals - forwarded in real time
  • Compatible with Splunk, Sentinel, Elastic, and generic webhook receivers
  • Feeds your existing detection and response workflows instead of creating a new silo
  • Prompt injection shield flags hijack attempts on agentic and CLI-proxied sessions
  • OWASP Top 10 scanning available on AI-generated code before it lands in a repo

For security & risk teams

Ready to put a governance layer in front of AI usage?

We'll walk your security team through the architecture, the audit trail, and how classification and scrubbing behave under load.

Request a security briefingVisit the Trust Centre