The AI governance platform

See every AI action. Govern every one.

Discover your AI, enforce policy at runtime, and generate audit-ready evidence for all AI systems. Built for security and compliance teams running AI at scale.

Portfolio › claims-copilot › Trace

Task: assess & settle claim #NW-88213

Chain verified · 0 gaps
Trace
tr_4b8e…7d0
Actor
claims-copilot
Spans
7
Duration
4.8s
Outcome
1 action denied
Trace tree 7 spans
agentplan: assess & settle claim4.8s
llmclassify claim validityallow
retrievalfetch policy & claim historyallow
toolread claims_db: NW-88213allow
llmdraft settlement + payoutreview
toolexternal_send: email payoutdenied
file_opwrite audit note to case fileallow
Span detail seq 6 · tool
Denied

Held before it ran. An external_send action on a high-risk system, carrying PII, crossed the policy's needs-review line with no human sign-off present.

Policy
P-12 · v3
Decided by
automated_guardrail
Enforcement
enforce
Fail mode
fail-closed
Action class
external_send

Policy

P-12 · high-risk external actions require human review

Express the human-review expectation in plain terms.

Enforce
If actionexternal_send and dataPIIorsecret
Or actiondestructiveorspend_affecting
On targetrisk_tier = high
Thenreview · route to human

Enforcement mode

ShadowWarnEnforce

Deterministic checks are safe to arm. Probabilistic checks ship shadow-first.

Fail behavior

Fail-closedFail-open + alert

Security-critical rules, PII egress and destructive actions, fail closed.

Applies to (opt-in)

High-risk tierAll systems

Enforcement never fires on a path you did not enable.

v3 · edited by R. Bindal · every create and edit is ledger-logged and attributable

Evidence

Evidence & auditor workspace

Walk the controls. Evidence is pre-mapped, no query language.

Export pack

ISO 42001 · AI management system

Audit period locked · 2026-04-01 to 2026-06-30 · 26 controls

Fresh

22

Stale

3

Gaps

1

ISO 42001 84% SOC 2 92% ISO 27001 88% NIST AI RMF 71%

A.6.2.6

Human oversight over high-risk AI actions

Evidence: policy_decision review records · recipe refreshed 2d ago

ISO 42001 A.6.2.6SOC 2 CC7.3EU AI Act Art.14
3 exceptions

A.7.4

Automatic logging of AI system operation

Evidence: tamper-evident trace ledger · 1.28M spans, 0 gaps

ISO 42001 A.7.4EU AI Act Art.12SOC 2 CC7.2
complete

Live demo

The plan, the generations, the tool calls, and the decision on each one, including the action that was held back before it ran.

The problem

AI usage is outpacing governance, creating gaps in security and compliance.

01

Policy in place, no evidence of what the agent did

GRC platforms evidence that a policy exists. None show it was called and applied to a live AI action, which is what audits, questionnaires and incidents demand.

02

AI observability is not built for SecOps

Observability is built for developers debugging models. Instrumented per app, it leaves no shadow AI detection, no security detections, no standard dashboard, and logs that can be changed.

03

Agents acting without a check at the moment of action

Agents call tools and compose them in ways nobody specified, with no authorization at call time. Perimeter controls see traffic, not intent, so permitted steps still reach unapproved outcomes.

04

Every team owns a slice. No one owns the chain.

One AI action can be a security, privacy and compliance incident at once. SOC and GRC work in separate tools, with no shared context and no shared authority, so detection lags.

Introducing Mungo Labs

Unified data and controls platform for governing AI at runtime.

One tamper-evident record of all AI activity in your organisation: searchable for audits and investigations, monitored for policy violations, and exportable as auditor-ready evidence.

Unified audit trail.

Prove to auditors and regulators with a normalized, append-only, hash-chained and signed ledger of every AI call.

Human decisions, on the record.

Every human-in-the-loop approval, override and escalation is a signed entry in the same trail. Pull the answer by control.

Auto-collection of evidence.

Risk and evidence tied to controls across frameworks, exported as verifiable bundles. SOC 2, ISO 27001 and ISO 42001 at launch.

Every policy decision is a piece of evidence.

Each guardrail decision is logged as evidence in its own right, for example a blocked PII-exfiltration attempt.

An auditor workspace.

Views by control and by exception, so a reviewer enters where the risk is rather than paging through everything.

What the auditor sees

Entries
2,481,903
Chain
continuous · 0 gaps
Signature
valid
Control
ISO 42001 · A.7.4
Manifest
sha256:4c1a…9e02
Corrections
forward-only · 12
AI discovery and inventory.

Automatic discovery of models, agents, MCP tools and AI apps across your estate, both sanctioned and shadow.

Detections into your SIEM.

Detection events carry risk context and a deep link into the tamper-evident trail, delivered into your SIEM.

Policy enforcement at runtime.

Deterministic policy enforcement by identity, scope and arguments, evaluated before the action runs.

Human-in-the-loop for risky actions.

Pre-execution policy checks and programmatic human approvals for destructive or high-risk actions.

Structured investigation.

When an incident lands, analysts replay the session step by step: intent, authorized scope, policy decision, execution, outcome, and reach root cause from a structured record, instead of losing hours in vast, unstructured logs.

Detection event

Rule
out-of-scope access
Actor
fraud-triage-rag
Action class
external_send
Risk tier
high
Decision
routed to human
Trail
tr_2a10…9c4

Deduplicated and enriched, not flooded. The deep link opens the full chain: intent, authorized scope, decision, execution, verified result.

Privacy before custody.

PII and secrets are redacted, tokenized and signed inside your trust boundary, before anything reaches Mungo's core.

Data residency.

Processing in the geographies you choose, cloud or self-hosted.

An audit trail that complies with privacy regulation.

Data erasure removes the payload but keeps the hash, so you can honour a deletion request without breaking the chain that proves what happened.

Fail closed on privacy.

A redaction failure quarantines the data rather than letting it through.

Redaction, at the edge

Fields redacted
1,204
Tokenized
at the edge
Plaintext held
none
Detokenizations
3 · role-gated
Reason required
yes
On failure
quarantine

Every detokenization requires a privileged role, a stated reason, and its own ledger entry. Access to the real value is itself an auditable event.

How it works

Five controls, one data record.

Mungo sits where your AI already runs. It finds what's running, records each action as it happens, checks it against the policy you authored, catching the AI risks as they surface at runtime, and writes the result to a trail you can hand to an auditor.

01 CaptureEvery AI action recorded at source, across Claude, OpenAI, Copilot, Cursor and more.
02 Tamper-evident ledgerAppend-only, hash-chained and signed. Raw data stays inside your environment. Mungo holds hashes and metadata.
03 Unified action centerOne shared record and one workflow across security, compliance and privacy.
Discover

Every model, agent, MCP tool and AI app across the estate, sanctioned and shadow alike, with a risk tier on each.

Detect

OWASP LLM risks and out-of-scope behavior flagged as they happen: PII egress, prompt injection, toxic or biased output, permission drift.

Investigate

Replay any incident end to end and reach root cause from a structured record, not a wall of raw logs.

Prove

Auditor-ready evidence packs, cross-mapped across frameworks, exported with a manifest anyone can check.

Enforce

Guardrails you author, evaluated at the moment of the call. Warn-and-assist first, enforcing only where your policy says so.

The loop closes: what you enforce shapes what's captured next

Attestation proves a control exists. This record proves it ran.

Deployment

Built to deploy without disruption.

Deploy with zero re-instrumentation.Attach through the paths already in your stack.

Warn-and-assist mode by default.Observe first, and enforce only when you choose to.

Seamless integration into your existing stack.Your SIEM, your identity provider.

Cloud or self-hosted deployment.Processing pinned to the geographies you choose.

Enterprise-grade security from day 1.Customer-held keys, disclosure-tier access control, fail-closed on privacy.

Get started

See every AI action. Govern every one.

A conversation about your AI estate, the governance gaps in it, and what evidence you would need to close them.

Book a discovery call