Governed AI your data
never has to leave for.

Your teams search, chat, and run real work across your own documents and systems. Every query logged, every prompt policy-checked, nothing crossing your perimeter.

Runs in your VPC, your sovereign cloud, or fully air-gapped. No data leaves your tenancy.

4.2MGoverned queries served across deployments
180+Enterprise connectors in the catalogue
9Regulatory frameworks mapped to controls
0Bytes of customer data leaving your perimeter
The problem

Your people already use AI. You just can't see any of it.

The tools that make employees faster are the ones your policy cannot approve. So the work moves off-platform, and the risk moves with it.

No scoped access

Employees get all-or-nothing access to internal systems. IT has no way to assign the right tools to the right people.

Shadow AI

When employees connect AI tools on their own, IT has no way to track, manage, or revoke connections.

No audit trail or logs

When an employee uses AI to take action in a system, there is no record of what happened or what data was shared.

No data guardrails

AI tool calls pass through third-party systems with no policy enforcement on what data is included.

The product

One workspace. Three things your teams do every day.

Not a chatbot bolted onto a wiki. A working surface that reads your systems, answers with citations, and takes action under policy.

Search

One query across every connected system, answered with citations back to the source document and the permissions the asker actually holds.

  • Results scoped to each user's existing entitlements
  • Every answer cites the document and revision it came from
  • Hybrid retrieval across files, tickets, and structured records
Explore Search
Search · cited resultsGoverned
exposure to the October rate change
3 sourcesSharePointSnowflakeScoped to you
1Treasury exposure October.xlsxSheet 2

“Floating-rate book stands at 38% of total exposure.”

2ALCO pack 02 Sep.pdfp. 7

“Committee agreed a 25bp pass-through scenario.”

2 further matches withheld, outside your entitlements
Returned in 0.9 s · logged as entry 4,412,911
Chat · grounded threadGoverned
Summarise the outstanding exceptions on account 4417-88-2301 and tell me who owns them.
Account number redacted before the model saw it
Completed · 3 steps · 2 sources16:56
Exceptions registerFinancial crime log

Three exceptions are open. Two are documentation refreshes owned by the onboarding desk, both past their 30-day window. The third is a sanctions re-screen owned by financial crime, raised 6 September.

GovernedAll corpora
Ask about a policy, a contract or a control…
Llama 3.1 70B · self-hosted·Retention: 90 days·Thread logged

Chat

A working conversation grounded in your corpus, with redaction applied before anything reaches a model and the whole exchange written to the trail.

  • PII, PCI, and PHI removed pre-inference
  • Threads retained under your own retention policy
  • Model choice governed by role, not by the user
Explore Chat

Agents

Agents that do the step, not just describe it. Each action is checked against policy before it runs and recorded after it does.

  • Scoped tool access per role and per system
  • Pre-flight policy check on every action
  • Human approval gates on anything you designate
Explore Agents
Agents · run 4417Governed
Quarterly access reviewRunning
Run 4417 · 3 of 4 steps · 214 records
Read entitlement records16:52
Pulled 214 role assignments across three systems.
SnowflakeSharePointSlack
Policy check passed16:53
Scope limited to finance. No write access granted.
Drafted revocation list16:54
18 users and 3 dormant service accounts.
Waiting on your approval16:55
Nothing is revoked until a human signs off.
ApproveReview listEvery action logged
Connectors

Reads the systems you already run.

Permissions are inherited from the source system on every query, so a connector never widens what someone can already see.

Browse all 180 connectors
SharePointSharePoint
ConfluenceConfluence
SlackSlack
SnowflakeSnowflake
SalesforceSalesforce
Google DriveGoogle Drive
Microsoft 365OutlookTeamsJiraServiceNowBoxDropboxNotionGitHubWorkdaySAPOraclePostgresS3DatabricksZendesk+ 158 more
Deployment

One platform. Your infrastructure.

Capability does not degrade as you move down the tiers. Air-gapped customers get the same workspace as private cloud.

Fastest to deploy

Shared cloud

Fully managed by Anvax in your preferred region. Get the complete Anvax platform without managing infrastructure, while your data and workloads remain isolated within your environment. Ideal for teams that want enterprise security with the simplicity of SaaS.

Your cloud. Your control.

Sovereign / private cloud

Deploy Anvax directly into your AWS, Azure, or GCP environment, or through an approved sovereign cloud provider. You retain control of the infrastructure, data plane, network policies, and region while Anvax delivers the same product experience. Built for organisations with strict data-residency and regulatory requirements.

Runs entirely inside your facility

On-prem / air-gapped

Deploy the complete Anvax platform on infrastructure you control, with no dependency on Anvax-hosted services. Supports isolated networks and fully air-gapped environments where data cannot leave the facility. Designed for government, defence, critical infrastructure, and highly regulated environments.

Jurisdiction packs

Your regulator, already mapped.

Control mappings ship with the product, documented per framework. Your reviewer gets a mapping table, not a marketing claim.

Request the security pack →
SOC 2 Type IIGlobalAudit underway
ISO/IEC 27001GlobalAudit underway
GDPREuropean UnionMapped
EU AI ActEuropean UnionMapped
DORAEuropean UnionMapped
NIST AI RMFUnited StatesMapped
FCA operational resilienceUnited KingdomMapped
MAS FEATSingaporeMapped
RBI FREE-AIIndiaMapped
How it works

Three layers. One product.

Shipping today

Governed workspace

Search, chat, workflows and agents on your own documents and systems, full audit trail, PII redaction, policy enforcement. Inside your perimeter, from day one.

Compounding

Governance layer

Four structural moats: organisational memory, immutable audit chain, jurisdiction packs across six regulatory frameworks, and enterprise connector depth that takes months to replicate.

Your iron

Deployment

Three tiers, one product: private cloud in your own AWS, Azure, or GCP, any region; sovereign cloud partners; or on-prem and air-gapped. Your data never leaves your perimeter.

The questions your security team asks first.

Where does our data actually sit?

In your tenancy. Documents, embeddings, and inference traces are written to storage you own, in the region you choose. Anvax has no shared data plane and no cross-tenant index.

Which models can we use, and where do they run?

Open-weight models self-hosted alongside the workspace, or your own commercial gateway if you already hold that contract. Model access is gated per role.

What does the audit trail contain?

The prompt, the retrieved sources, the model and version, the redactions applied, the response, and any action taken. Tamper-evident and exportable.

Can it run air-gapped?

Yes. The on-prem tier requires no outbound connectivity, including for updates, which ship as signed offline bundles.

How long until our first department is live?

Three weeks is typical for private cloud, assuming your connectors are reachable and policy owners are available in week two.

Bring your regulator into the room.

We will run the demo on your corpus, in your tenancy, with the audit trail switched on. Forty-five minutes.