Govern the essentials.
DLP and prompt-injection enforcement, a capped model allowlist and a board-ready governance summary - everything a smaller organisation needs to put AI under control.
Every AI request runs through the same governed gateway as Enterprise - logged, cost-attributed and enforced. What is different is the surface: eleven screens, no groups, and nothing that assumes you employ a full-time security engineer.
Book a demo Compare editions →Look round the dashboard first
Eleven steps through Axonyx Core, from the governed gateway and the call log to enforcement, the board report, troubleshooting a blocked call, and Nando. It is a preview, not the demo: a live demo runs on your own traffic, in shadow mode, with nothing blocked.
Four questions, answered properly
Most AI governance tooling is built for an organisation that already has applications registered, someone writing data loss rules, and a working definition of what audit evidence looks like. If that is not you yet, these are the questions that actually matter.
What AI are we actually using?
Not the sanctioned list - the real one, including the tools nobody told IT about.
Is anything sensitive going into it?
Customer data, card numbers, staff records, credentials. Stopped, not reported after the fact.
What is it costing us?
One number, by team and by tool, with a trend. Enough to answer a board question.
Can we show we are being sensible?
One exportable summary for an insurer, a customer questionnaire or a tender.
Everything else is noise at this stage. Model drift baselines, bias grading, SIEM forwarding, nine mapped frameworks - all real capabilities, all in Enterprise, and none of them actionable by a team of twelve. Shipping them to a smaller company is not generous. It is a product they cannot operate.
Enforcement, not just reporting
Core applies policy at the gateway, so unsafe requests are stopped before they reach a model provider rather than flagged afterwards.
Observe
- Governed gatewayEvery request routed, logged and cost-attributed with a Ray ID.
- AI runs logOne row per request, expandable to the full trace and the rules that fired.
- Live flowReal-time view of requests flowing into outcome buckets.
- Applications viewPer-application traffic, blocks, findings and spend.
- Cost ExplorerSpend by model, application and cost centre.
- Gateway replayReplay a call and watch each check apply, step by step.
- TroubleshootingRay-ID lookup and error playbook for developers.
- Command paletteJump to any page or setting from the search bar.
Enforce
- DLP rule packsData loss prevention across PII, financial data, secrets and more.
- Prompt-injection rulesJailbreak and instruction-override detection.
- Per-rule on/offSwitch individual rules within a pack.
- Approved-model allowlist 4 active modelsRequests to any other model are refused at the gateway.
Govern and comply
- Governance summaryOne-page, board-ready posture report as a PDF.
- Nando, your virtual CISOA virtual CISO and cost optimiser that reads your live telemetry and hands back prioritised security and cost advice.
Operate and brand
- Connection and SDK guideEverything needed to send a first governed call.
Nothing is blocked in week one
Core does not open on an empty dashboard waiting for you to configure it. It runs in shadow mode first, and tells you plainly that it is doing so.
1. Point your traffic at us
One endpoint, one key, copy and paste per tool. Nothing else is asked of you yet.
2. Watch for a week
Shadow mode by default. Everything is recorded, nothing is stopped, and the product says so rather than burying it in a setting.
3. See what we found
The discovery report: which AI tools are in use, what data went near them, and what it cost. Usually the moment something surprising turns up.
4. Choose a protection pack
Not a regular expression editor. A small number of curated packs, chosen by the kind of business you are, each a named bundle of rules described in plain English.
Then turn enforcement on. Core prompts for it at the end of the shadow week, once you have seen the evidence, rather than leaving it as a setting nobody returns to.
How the platform works underneath
Core enforces at the gateway. Longer explanations of each capability area, and how they fit together in the control layer.
Discover AI
Surface every AI tool, model, agent and provider in use across the organisation, sanctioned or not.
Read more →AI Control & Enforcement
Inspect prompts and responses and apply policy before an AI action executes.
Read more →Converse
A governed AI chat portal for staff, with every major model behind one controlled workspace.
Read more →Dashboard & Virtual Advisors
Live insight across AI risk, usage and cost, with advisors that turn platform data into briefings.
Read more →Audit & Compliance Reporting
Turn AI activity into audit-ready evidence mapped to the frameworks you report against.
Read more →What Enterprise adds
Core is deliberately bounded. If any of the following describes your situation, Enterprise is the right edition.
You need your own rules
Core ships curated protection packs you can switch on and off, rule by rule. Writing your own rules from scratch, and setting a different policy for each application, is Enterprise.
You have to evidence a framework
Core produces a board-ready governance summary. Mapped control reports, tamper-evident evidence packages and a DSAR register for ISO 42001, the EU AI Act, SOC 2 and others are Enterprise.
You are running agents
Agent Safety guardrails and gateway-enforced budgets are Enterprise capabilities.
You need more than four models
Core enforces an allowlist of four active models. Enterprise removes the cap and adds per-application allowlists.
Put AI under control without the admin overhead.
Core gives a single team real enforcement, full visibility of every AI request, and a governance summary a board will accept.
Book a demo