xSOM AI Guard

Put your AI agents into production.
Without losing control.


An agent that writes text creates a text risk. An agent with tools deletes, pays, sends, writes to production. xSOM AI Guard sits between the agent and its tools, and decides — call by call — what goes through, what waits for a human, and what will not happen.

The shift

This is not a prompt firewall.

Most guardrails look at what the model is told, or at what it answers. That is useful, and insufficient: the damage does not happen in the sentence, it happens the moment the agent calls a tool.

Control therefore has to apply to the action. Deleting a contact, moving money, shipping a release, writing into a client system: those are decided before they are executed, not after they have been described.

It is the only place where a refusal is still a refusal.

The mechanism

Three guarantees, in this order.

Guarantee 01

A readable policy

Every tool call is classified, then settled by a written, versioned, reviewable rule. A language model does not arbitrate authorisations: it is consulted only on ambiguous cases, and never to lift a prohibition.

Guarantee 02

A human on the irreversible

An irreversible action is held, shown as a dry run — what it would do, and to what — then executed only once approved. Not approved means it does not happen. The block is held by the gateway, never delegated to the model.

Guarantee 03

A tamper-evident log

Every decision is append-only and hash-chained: altering one line breaks the chain, and the break is visible. The exports serve a demonstration of compliance rather than a promise of it.

And the rule that holds all three: when in doubt, refuse. Unknown tool, approval service unreachable — on anything irreversible, no answer means refusal, never permission.

Sitting in the path

Three ways, which do not guarantee the same thing.

The difference is not an integration detail: it decides whether a refused action can still happen.

Binding

MCP gateway

The agent's tools go through the gateway. It executes, or it does not. This is the only path where the refusal does not depend on the agent's goodwill.

Cooperative

Authorisation call

For an agent whose code you own: a few lines that ask for a verdict before acting. The guarantee is worth exactly what the agent honouring it is worth.

Binding on egress

Provider proxy

One change of base URL, no code touched. Binding on what leaves — which is already a great deal when the agent's code is not yours.

Where the product stands

Said plainly.

xSOM AI Guard is a product under construction, built by the firm. The foundation is working and tested — gateway, policy, human approval, chained log — and that is what the demonstration shows.

What it does not do, it does not claim: it is not a prompt-injection detector, not a personal-data filter, and not a sovereign hosting offer. Those belong to our consulting work, not to this tool.

The demonstration is given under named access, by appointment: we show an agent attempting an irreversible action, the hold, the refusal, and the fact that the action did not happen.

Next step

Which agents do you already run in production?

Tell us which tools they touch and what keeps you up at night. We will show you what putting them under control would change, on your own case.