Every prompt classified. Every denial logged. Every action attested. ModelCop is the runtime governance layer between your applications and the fifteen LLM providers they call — with the non-human identity graph underneath that makes every classification defensible to your auditor.
Anthropic, OpenAI, Bedrock, Azure OpenAI, Azure AI Foundry, Vertex, Mistral, Cohere, Together, NVIDIA NIM, Ollama, Groq, Perplexity, Hugging Face. PII, PHI, PCI, ITAR, CUI, secret, internal, public. For every cell in this 14×8 matrix your apps need to know: is this allowed? Most enterprises can't answer for a single cell. ModelCop answers for all one hundred twelve, in real time, with cryptographic evidence the answer was correct.
Your engineers ship features that call Anthropic for reasoning, OpenAI for embeddings, Bedrock for compliance-sensitive workloads, Vertex for batch processing, and a long tail of specialty providers. Each one has different residency. Each one has different terms. Each one has different log retention. Each one is, somewhere, processing data your CISO doesn't know it has.
Eval companies tell you whether a model is safe in general. ModelCop tells you whether this specific prompt, from this specific service identity, on this specific tenant's data, is allowed right now — and proves it. The proof matters because your auditor is going to ask.
The proof needs an identity graph underneath it: which service account requested the call, which agent it was acting on behalf of, what scope the agent had, what the agent's owner attested to last quarter. That's the non-human identity layer. ModelCop correlates it, governs the prompts, and lets your audit committee read the evidence in one place.
And the regulators have caught up. EU AI Act Article 9 requires risk-management evidence for every AI system. NY DFS Part 500 now reaches AI-handled customer data. SOX 302/404 ITGC controls extend to any system processing financially-relevant prompts. CMMC Level 3 enforces NIST 800-171 controls over CUI-handling AI workflows. HIPAA Security Rule treats PHI flowing to a non-BAA model provider as an incident.
Your existing stack has a gap. ModelCop fills it.
Baselines every NHI's normal cadence. Surfaces scope drift, off-hours bursts, geo anomalies, and burst-traffic patterns that precede compromise.
Maintains the human-to-NHI link. Auto-suspends orphaned identities when an owner departs. Recovers ownership after M&A. Watches the lineage continuously.
Measures granted-versus-used permissions per identity. Reclaims 38 to 62 percent of scopes in the first 90 days. One-click application from the dashboard.
Vault-bound credential lifecycle. Detects in-code secrets, shared PATs, stale rotations. Triggers safe rotation flows that won't break production.
Intent-to-scope intelligence for JIT access requests. Translates "investigate the May incident" into the minimum scope set, the right approver chain, and a time-bound grant.
Point an agent's provider base URL at ModelCop. Every request is classified and checked against your policy before it's forwarded — a policy-violating prompt is blocked, the agent receives a native API error, and a forensic record is written. OpenAI- and Anthropic-compatible today.
Governs traffic routed through ModelCop · transparent network enforcement available per environment
Every AI security event traces back to the non-human identity that executed it and the accountable human chain behind it: owner → manager → department. Kill-chain, force-graph, and blast-radius views make the attribution legible in seconds.
Event → NHI → human owner · forensic detail on every node
ModelCop flags likely-critical assets from the sensitive data interacting with them, then traces which non-human identities can reach each one. A preliminary identification for your SMEs to validate — not an autonomous determination — so the human judgment stays where it belongs.
Correlation-driven · SME-validated · priced against the value you set
Every NHI and data class is priced to a dollar-denominated risk figure. Instead of a wall of "high / medium / low," your board sees exposure ranked by what a breach of each identity would actually cost — the language risk committees and CFOs already speak.
Per-identity · per-data-class · board-ready
Attestation status across your controls, each row linked to the source data that proves it — not a spreadsheet someone updated last quarter. Walk an auditor through exactly how a control is satisfied, where the gaps still are, and export the whole thing as audit-grade evidence packs mapped to the frameworks that matter.
Live evidence · control-to-source linkage · regulator-mapped export
ModelCop reclaims 38–62% of over-provisioned access in the first 90 days — real licenses and standing privilege handed back — and prices the exposure it removes in dollars. Set both against the per-NHI price and the platform funds itself: the access it recovers and the risk it retires are measured in the same currency as its cost.
Reclaimed scope + retired exposure − platform cost · the math is yours to run
| Capability | ModelCop | Astrix | Aembit | Oasis | Token Sec. |
|---|---|---|---|---|---|
| NHI correlation across 9 identity types | ●● | ● | ◐ | ● | ● |
| Native credential broker (Aembit class) | ●● | ◐ | ●● | ◐ | ○ |
| Ephemeral identities + JIT (Oasis class) | ● | ◐ | ● | ●● | ○ |
| Approval-chain workflow (built-in) | ●● | ◐ | ◐ | ◐ | ◐ |
| Multi-industry pre-built packs | ●● | ○ | ○ | ○ | ○ |
| Five-specialist agent fabric (LLM-backed) | ●● | ○ | ○ | ○ | ◐ |
| Audit-grade regulator-mapped PDFs | ●● | ◐ | ○ | ◐ | ◐ |
| ITSM / SIEM / Slack / PagerDuty outbound | ● | ● | ● | ● | ● |
| Read connectors (Okta, Vault, GitHub) | ● | ● | ● | ● | ● |
| Sovereign deployment (planned — residency-aware policy today) | ◐ | ○ | ◐ | ○ | ○ |
Diversified banking, wealth, insurance, and lending. AI fraud-triage agents, KYC pipelines, trade-surveillance copilots. Shadow GPTs touching PCI data. The full Fortune-500 NHI portfolio with its full attack surface.
Hospital network, ambulatory clinics, labs, research. PHI-touching AI scribes, FHIR clients, controlled-substance pharmacy workflows. Discharge-summary copilots that must not leak across patient contexts.
Multi-modal freight, customs brokerage, cross-border data. ITAR manifest verifiers, EDI integration accounts, carrier API consolidation. Owner-departed orphans inherited from a decade of acquisitions.
DoD prime contractor and subcontractors. CUI-handling service accounts, GovCloud-segmented AI agents, classified-repo PATs. CMMC L3 ready out of the box. ITAR + DFARS coverage in the seed.
Risk management for high-risk AI systems. Identification, estimation, mitigation, residual-risk.
Cybersecurity Program for financial-services covered entities. 500.7, 500.14, 500.16, 500.17.
IT General Controls for non-human identities touching financially-relevant systems. AC, CM, OPS.
§164.308 administrative + §164.312 technical safeguards. HITRUST CSF v11 mappings.
NIST SP 800-171 Rev. 2. AC.L2-3.1.x, IA.L2-3.5.x, AU.L2-3.3.x control families.
Three-lines-of-defense model. AI/NHI risk reporting to the board.
Export-controlled data segregation, GovCloud routing, manifest verification.
First international standard for AI management systems. ISMS-style certification.
Govern, Map, Measure, Manage. NHI-aware extension to traditional AI RMF.
FFIEC AIO · MITRE ATLAS · OWASP LLM Top 10 · GLBA · PCI-DSS · FedRAMP · ISO 27001 · SOC 2
Every number below is editable and every assumption is shown. We don't hide a multiplier — we give you the inputs and the formula, and let the arithmetic make the case.
We bring the demo on a laptop, running locally — no security review required to take the meeting. Twenty minutes of platform walk-through. Twenty-five minutes of discussion around your environment. If we don't earn a second meeting, we won't waste yours.