Everything you need to deploy, operate, and govern DataStrict.
Search the knowledge base or browse by category - getting started, the platform, security and compliance, your account, data privacy, and billing. When you need a person, our team is one click away.
Point your application at the DataStrict gateway instead of calling the model directly. It evaluates each request against policy, forwards what's permitted, inspects the response, and records the decision - no model fine-tuning or SDK rewrite required.
Minutes. You author a policy as code, validate it in Simulation against real or synthetic traffic, then promote it to enforcing. The Quickstart in the docs walks through it end to end.
No. The gateway is a thin layer in the request path. Your teams keep building the way they do; governance is applied at the boundary.
Deny or redact classes of data (PII, secrets), scope which tools an agent may call, bind decisions to identity, purpose, and jurisdiction, and escalate ambiguous cases to a model-graded review.
Yes. Most requests resolve on deterministic rules in microseconds with no model call. Only genuinely ambiguous requests escalate to a judge, so you pay that cost exactly where it's warranted.
It's model-agnostic. Because enforcement happens at the boundary, you can switch providers, run several at once, or self-host, and your governance travels with you.
Yes. Simulation replays real or synthetic traffic against a candidate policy and reports exactly what it would allow, redact, block, or escalate - before a single live request is affected.
Through the Control Atlas, which maps frameworks like the EU AI Act, NIST AI RMF, SOC 2, HIPAA, and GDPR to concrete, enforced controls with an immutable audit trail.
Every adjudicated decision is written to an append-only, hash-chained ledger at the moment it's made - tamper-evident evidence an auditor can verify independently.
DataStrict is built to operate within SOC 2, ISO 27001, HIPAA, and EU AI Act expectations. See the Compliance page for what each framework means and how the platform helps.
Via Google, Microsoft, or your enterprise SSO. Access is identity-bound, so every action is attributable.
Yes. Access is deny-by-default and scoped to purpose. Roles and tool grants are evaluated at runtime against policy and revocable in real time.
Use the 'Forgot?' link on the sign-in page, or contact your workspace administrator if your organization uses SSO.
No. DataStrict evaluates and enforces in-line. The ledger records the decision, the policy version, and the finding type - the evidence of governance - not the underlying content.
Region and residency are expressed as policy (region-lock, field-level masking), so data handling follows the jurisdiction you define.
PII is detected at the boundary and blocked or redacted per policy, on both the request into a model and the response out of it.
Plans scale with usage and enterprise requirements. See the Pricing page for the current tiers, or contact sales for an enterprise quote.
Yes - request a demo and we'll set you up to evaluate DataStrict against your own traffic.
Workspace administrators can manage billing from account settings; for changes, contact our support team.
Our team is here to help with anything the help center didn't cover.
Contact our support team