Shadow AI Detection

See the Shadow.
Lock the Risk.

GovLoX surfaces unauthorised AI tools across your network, verifies agent identities, and enforces policy in real time. No agents on user devices.

  • Accelerates your ISO 42001 journey
  • Patent pending — Switzerland & US
  • RFC 3161 compliant timestamping
  • Qualified timestamping provisioned at onboarding

Built for evidence. Designed for every vendor. Governed under EU law.

Evidence layer

Every AI agent action is cryptographically bound to an RFC 3161 timestamp, tamper-evident and hashed from day one. Qualified timestamping is provisioned for your organisation as part of onboarding, through a qualified trust service; our selected provider is Swisscom, qualified under both the EU's eIDAS regulation and Switzerland's ZertES law.

Once provisioned, under Regulation (EU) 910/2014 Article 41 a qualified timestamp carries the presumption of accuracy and data integrity. Each receipt records exactly which timestamp standard it was issued under, so what it proves is never overstated.

Vendor-neutral

Works across OpenAI, Anthropic, Azure, AWS, Google, on-premise and custom models — wherever your agents actually run.

GovLoX is built on the open Agent Certificate Standard (AICS). Agent Certificates are a platform-independent credential, not tied to any single cloud provider. Your governance layer does not depend on whose stack you buy — and it does not lock you into one. If you run Microsoft today and Google tomorrow, your agent evidence travels with you.

Swiss / EU sovereignty

Governance infrastructure hosted and governed under Swiss and EU law — independent of any hyperscaler admin console.

Swiss Based. Patent pending. GovLoX's technology is the subject of pending patent applications in Switzerland and the United States. Qualified timestamping is provisioned at onboarding. EU data residency by default.

Supporting evidence your auditor can rely on.

AI agents acting across your estate produce actions that auditors, regulators and certification bodies need to verify. Today those actions sit inside platform-specific logs — your auditor has to trust whichever vendor produced them.

GovLoX binds each action to a timestamp, with qualified timestamping provisioned at onboarding. The resulting audit trail is cryptographically verifiable, defensible, and portable across every AI platform you run. Your ISO 27001 and ISO 42001 auditors can verify the evidence directly. Your FINMA, BaFin, or EU AI Office reviewer can verify without needing you, or your vendors, to provide attestation letters.

That is the difference between compliance and admissibility.

The Challenge

AI is spreading across your organisation faster than governance can keep pace; in the cloud, in SaaS tools, and increasingly on your own infrastructure.

Your employees are using ChatGPT, Copilot, Gemini, and hundreds of AI tools, many without approval, many processing sensitive data, and none with adequate governance.

Shadow AI is a growing concern

Employees frequently use AI tools outside of approved channels, often processing sensitive data without adequate controls or visibility.

Spreadsheets aren't governance

Most organisations track AI systems in Excel. No real-time monitoring. No enforcement. No proof of compliance. Without real-time monitoring and enforcement, demonstrating compliance becomes very difficult.

AI inventories are out of date almost immediately

Regulation is here. Are you ready?

The EU AI Act is law. ISO 42001 is the new standard. GDPR penalties reach 20 million euros or 4% of global turnover. Proactive governance is no longer optional for organisations operating in regulated markets.

The EU AI Act is in force, with obligations phasing in by system category

Most organisations have the policy conversation.
Few have the instruments to evidence that the policy is actually working.
GovLoX is that instrument.

The Solution

One platform. Complete AI governance.

GovLoX replaces fragmented tools and manual processes with a single, integrated platform that discovers, monitors, and controls AI systems across your organisation, whether it calls an external API or runs entirely on your own infrastructure.

Discover

Find AI systems across your estate, sanctioned or shadow, whether cloud-hosted, SaaS, or running on your internal infrastructure

Certify

Issue digital certificates that bind identity, policy, and risk classification to each agent

Enforce

Block unauthorised AI usage at instrumented enforcement points, in real time.

Prove

Generate verifiable audit records that stand up to regulatory scrutiny

Shadow AI Detection

GovLoX identifies AI tools in use from the network and infrastructure signals your organisation forwards to it, across cloud services, SaaS tools, and models running on your own servers.

  • Discovery from forwarded network log sources
  • Curated registry of AI platforms and tools
  • Instant alerts when blocked tools are still in use

Agent Certification

Every AI agent receives a digital certificate that defines what it can do, what data it can access, and who oversees it. Digital certificates purpose-built for AI governance.

  • Identity verification for every AI agent
  • Data classification and oversight levels baked in

Enforcement at the Decision Point

Set your governance policy once. GovLoX fails closed for agents that integrate with us, at the network perimeter and inside instrumented applications. Configurable enforcement levels. You choose.

  • Configurable enforcement levels to match your risk appetite
  • A decision point that answers in under a second when asked
  • Resilient enforcement even when the platform is unreachable

Verifiable Audit Trail

Every AI action generates a verifiable governance record. Not just a log entry; evidence of control that regulators and auditors can rely on.

  • Tamper-evident action records with trusted timestamps
  • Privacy-preserving; no personal data stored in audit records
  • Cryptographically verifiable without vendor attestation

Compliance

Built for the regulatory landscape, not built around it.

GovLoX maps every control directly to the frameworks regulators and auditors expect. A platform designed from the ground up to meet the requirements.

EU AI Act

Regulation 2024/1689

  • AI system inventory and risk classification
  • Human oversight and intervention controls
  • Record-keeping under Article 12
  • Incident reporting and post-market monitoring

Readiness dashboard with live scoring against AI Act articles

ISO 42001:2023

AI Management System Standard

  • Statement of Applicability with justification tracking
  • Risk assessment and treatment plans
  • Monitoring and measurement (Clause 9.1)
  • Continual improvement evidence

Audit-supporting documentation generated automatically

GDPR

EU Data Protection Regulation

  • DPIA for AI systems processing personal data
  • Records of Processing Activities (ROPA)
  • Transfer impact assessments
  • Automated lawful basis and retention tracking

Integrated DPO workflow with evidence export

Also supported

NIST AI RMF IEEE 7000 ISO/IEC 27001 OECD AI Principles Singapore Model AI Governance Framework UK GDPR, DPA 2018 & ICO AI Guidance Canada AIDA China AI Governance (TC260) China Algorithm Regulation (CAC) China Deep Synthesis Rules China Generative AI Measures

How It Works

From shadow AI to governed AI in four steps.

GovLoX works alongside your existing network infrastructure. No rip-and-replace. Governance from day one.

1

Connect

Enterprise AI governance without the endpoint agent problem. GovLoX integrates with your existing network infrastructure — no new software on user devices, no IT change management required.

2

Discover

GovLoX automatically identifies AI tools in use across your organisation and classifies each one against your approved tool registry. Shadow AI surfaces immediately.

3

Govern

Certify the AI systems you approve. Set enforcement policies. Assign oversight responsibilities. Run gap analysis against EU AI Act, ISO 42001, and GDPR simultaneously.

4

Prove

Every AI agent action is cryptographically bound to an RFC 3161 timestamp from day one, with qualified timestamping provisioned at onboarding. A qualified timestamp carries the eIDAS Article 41 presumption of accuracy and integrity, putting your audit trail in a materially stronger position before regulators and auditors, without vendor attestation letters.

Briefings are tailored to your sector and use case. Typically 30-45 minutes, remote or in-person across Europe.

Live right now

Watch it happen in real time

Request a Briefing

Request Access

The technical foundation

GovLoX Action Receipts are cryptographically hashed and bound to an RFC 3161 timestamp on every governed action, from day one of deployment. Qualified trust services are provisioned per organisation, at onboarding: you carry the qualified layer from the moment you have governed actions worth qualifying, and not before. Our selected provider is Swisscom, dual-qualified under both the EU's eIDAS regulation and Switzerland's ZertES law (the two regimes our primary markets sit under).

Once provisioned, under Regulation (EU) 910/2014 Article 41 each qualified timestamp carries the presumption of accuracy of date and time, and integrity of the bound data. That presumption puts an audit trail in a materially stronger position before a regulator, a certification auditor, or a court. We are specific about which timestamp standard a given receipt was issued under, so that strength is never assumed ahead of where the record actually is.

Compliance is policy. Admissibility is proof.

Read the white paper

Why GovLoX

Built for practitioners.

ISO
Designed by and built for AI Governance Practitioners

Designed by a PECB Certified ISO/IEC 42001 Lead Implementer

AI
Governance-First Design

Built by an AI governance specialist with deep data privacy and enterprise compliance experience across global organisations

Swiss Based

Swiss-headquartered, built for the European regulatory environment from the ground up

What sets GovLoX apart

  • Real-time, not retrospective

    Most tools tell you what happened. GovLoX acts on what is happening.

  • Governance, not just visibility

    Discovery alone is insufficient. GovLoX certifies, enforces, and proves.

  • Multi-standard from one platform

    EU AI Act, ISO 42001, and GDPR from a single evidence base.

  • Built for the European regulatory environment

    Designed from Geneva, for EU AI Act, ISO 42001, and GDPR. Not retrofitted compliance — governance-first from day one.

Questions we hear from every prospect

How long does deployment take?

Deployment scope is assessed during the briefing. No endpoint software or infrastructure replacement is required.

Does it work with our existing tools?

GovLoX integrates with standard network log formats (Syslog, CEF, LEEF) today. Purpose-built platform connectors are on the roadmap. Briefings include a tailored integration walkthrough for your specific stack.

Where is our data hosted?

European data centres. Customer data is held in a dedicated database per organisation, isolated by physical database separation. Jurisdiction options available on request.

Can we see it before we commit?

Yes. Contact us to arrange a walkthrough — we'll demonstrate real governance events firing against a live platform, tailored to your use case.

Who We Work With

Wherever AI governance accountability is required

GovLoX is built for AI-forward agencies and professional service firms running multi-agent workflows for regulated clients, and for regulated enterprises in financial services, healthcare and pharma, public sector, and enterprise technology. If your agents act on behalf of clients or regulators who expect defensible evidence, GovLoX is built for you.

Financial Services

FCA · PRA · EBA · SEC · MAS

Healthcare & Pharma

EU AI Act · GxP · MDR · FDA

Public Sector

EU AI Act · NIS2 · GDPR

Enterprise & Technology

ISO 42001 · SOC 2 · GDPR · NIST

Common triggers for GovLoX deployment

Regulatory audit or examination approaching

Board or executive AI governance mandate

EU AI Act compliance deadline pressure

Shadow AI discovered across the organisation

ISO 42001 certification programme underway

Client or procurement due diligence on AI risk

Working in a sector not listed? If you deploy AI in a regulated environment, we should talk.

Request Access

Cryptographic identity. Qualified evidence. LLM perimeter. Continuous monitoring.

GovLoX is built on the Agent Certificate Standard (AICS). Every agent carries a signed certificate. Every action is bound to a timestamp, with qualified timestamping provisioned at onboarding. Every scope violation is detected and timestamped the moment it happens.

🔐

Cryptographic Identity

Every agent carries a signed Agent Certificate (AICS). No certificate, no operation. Fail-closed by design.

⏱️

Qualified Evidence

Qualified timestamping is provisioned at onboarding; the eIDAS Article 41 presumption of accuracy and data integrity then applies.

🌐

LLM Perimeter Controls

Declare approved LLM endpoints as internal or sovereign. Know immediately when an agent reaches outside its certified LLM perimeter.

📡

Behavioural Monitoring

Scope drift, unapproved endpoint calls, and volume anomalies surface as timestamped audit records the moment they occur — evidence, not just alerts.

Get Started

See where your AI governance stands today.

Request access to GovLoX, or take the 11-question readiness scorecard to see where your current governance posture ranks across eight dimensions of EU AI Act readiness.