Axonyx Core

Govern the essentials.

DLP and prompt-injection enforcement, a capped model allowlist and a board-ready governance summary - everything a smaller organisation needs to put AI under control.

Every AI request runs through the same governed gateway as Enterprise - logged, cost-attributed and enforced. What is different is the surface: eleven screens, no groups, and nothing that assumes you employ a full-time security engineer.

Book a demo   Compare editions →
Preview

Look round the dashboard first

Eleven steps through Axonyx Core, from the governed gateway and the call log to enforcement, the board report, troubleshooting a blocked call, and Nando. It is a preview, not the demo: a live demo runs on your own traffic, in shadow mode, with nothing blocked.

What Core answers

Four questions, answered properly

Most AI governance tooling is built for an organisation that already has applications registered, someone writing data loss rules, and a working definition of what audit evidence looks like. If that is not you yet, these are the questions that actually matter.

What AI are we actually using?

Not the sanctioned list - the real one, including the tools nobody told IT about.

Is anything sensitive going into it?

Customer data, card numbers, staff records, credentials. Stopped, not reported after the fact.

What is it costing us?

One number, by team and by tool, with a trend. Enough to answer a board question.

Can we show we are being sensible?

One exportable summary for an insurer, a customer questionnaire or a tender.

Everything else is noise at this stage. Model drift baselines, bias grading, SIEM forwarding, nine mapped frameworks - all real capabilities, all in Enterprise, and none of them actionable by a team of twelve. Shipping them to a smaller company is not generous. It is a product they cannot operate.

What you get

Enforcement, not just reporting

Core applies policy at the gateway, so unsafe requests are stopped before they reach a model provider rather than flagged afterwards.

Observe

  • Governed gatewayEvery request routed, logged and cost-attributed with a Ray ID.
  • AI runs logOne row per request, expandable to the full trace and the rules that fired.
  • Live flowReal-time view of requests flowing into outcome buckets.
  • Applications viewPer-application traffic, blocks, findings and spend.
  • Cost ExplorerSpend by model, application and cost centre.
  • Gateway replayReplay a call and watch each check apply, step by step.
  • TroubleshootingRay-ID lookup and error playbook for developers.
  • Command paletteJump to any page or setting from the search bar.

Enforce

  • DLP rule packsData loss prevention across PII, financial data, secrets and more.
  • Prompt-injection rulesJailbreak and instruction-override detection.
  • Per-rule on/offSwitch individual rules within a pack.
  • Approved-model allowlist 4 active modelsRequests to any other model are refused at the gateway.

Govern and comply

  • Governance summaryOne-page, board-ready posture report as a PDF.
  • Nando, your virtual CISOA virtual CISO and cost optimiser that reads your live telemetry and hands back prioritised security and cost advice.

Operate and brand

  • Connection and SDK guideEverything needed to send a first governed call.
Getting started

Nothing is blocked in week one

Core does not open on an empty dashboard waiting for you to configure it. It runs in shadow mode first, and tells you plainly that it is doing so.

1. Point your traffic at us

One endpoint, one key, copy and paste per tool. Nothing else is asked of you yet.

2. Watch for a week

Shadow mode by default. Everything is recorded, nothing is stopped, and the product says so rather than burying it in a setting.

3. See what we found

The discovery report: which AI tools are in use, what data went near them, and what it cost. Usually the moment something surprising turns up.

4. Choose a protection pack

Not a regular expression editor. A small number of curated packs, chosen by the kind of business you are, each a named bundle of rules described in plain English.

Then turn enforcement on. Core prompts for it at the end of the shadow week, once you have seen the evidence, rather than leaving it as a setting nobody returns to.

Where Core stops

What Enterprise adds

Core is deliberately bounded. If any of the following describes your situation, Enterprise is the right edition.

You need your own rules

Core ships curated protection packs you can switch on and off, rule by rule. Writing your own rules from scratch, and setting a different policy for each application, is Enterprise.

You have to evidence a framework

Core produces a board-ready governance summary. Mapped control reports, tamper-evident evidence packages and a DSAR register for ISO 42001, the EU AI Act, SOC 2 and others are Enterprise.

You are running agents

Agent Safety guardrails and gateway-enforced budgets are Enterprise capabilities.

You need more than four models

Core enforces an allowlist of four active models. Enterprise removes the cap and adds per-application allowlists.

See the full comparison

Put AI under control without the admin overhead.

Core gives a single team real enforcement, full visibility of every AI request, and a governance summary a board will accept.

Book a demo