// THE GOVERNANCE LAYER FOR AI

Compliance you can prove.

OAG is the governance layer that sits between your AI and the models it runs on. It audits your codebase against 24 regulatory frameworks and seals the evidence with a cryptographic root — continuously, not once a year. No binders. No consultant opinions. When the regulator asks, you answer in minutes.

Run a free audit
Live audit · 7 evidence sections · cryptographically sealed
AUDIT EVIDENCESEALED
Repositoryacme/payments-api
Analysed412 modules · 6 languages
FrameworksISO 42001 · EU AI Act
Findings3 critical · 7 major
SealVerified · tamper-evident
Elapsed94 seconds
Tamper-evident · Court-admissible format

// THE EXPOSURE

The risk isn't the AI.
It's the paper trail you don't have.

Boards are personally exposed. Regulators no longer accept policy PDFs — they want verifiable evidence tied to the code that actually runs.

01

Regulations are live, not theoretical

The EU AI Act enforces with fines up to €35M or 7% of global turnover. Malaysia's AI Act 2026, Singapore's Agentic AI framework and ASEAN DEFA are all in force. "We didn't know" is no longer a defence.

02

Your evidence lives in binders, not in code

Consultants produce gap analyses. Regulators want proof that the controls exist in the running system — traceable from policy clause to source line. A PDF cannot be cross-examined. A Merkle root can.

03

Manual audits freeze engineering for months

A traditional compliance review consumes a quarter of engineering time and is stale the day it ships. Code changes hourly; binders don't.

04

Every AI decision is a liability decision

When a model denies a loan or routes a patient, the question in court is: who governed that decision, and can you prove it? Provenance is now a board-level asset.

// THE INSTRUMENT

One repository in. One sealed report out.

OAG Audit is the product your compliance officer can put in front of a board — and a regulator.

LIVE · OAG AUDIT ENGINE

OAG Audit

Submit a GitHub, GitLab or Bitbucket repository. OAG's digestion engine parses the codebase at the AST level — TypeScript, Python, Java, COBOL, VB6, C++ and more — then executes 24 regulatory frameworks against what it finds.

  • Findings mapped to specific clauses, with severity
  • Remediation guidance per finding, not generic advice
  • Merkle-sealed evidence pack — tamper-evident by construction
  • Executive summary written for boards, engineers and counsel
  • Async by design: submit, poll, retrieve. Fits CI/CD.
FREE 3/mo · PRO 50/mo · ENTERPRISE ∞
LIVE AUDIT CONSOLE
Awaiting submission. Reports typically complete in ~90 seconds.

Demo routes to the OAG Audit API. Prefer a walkthrough?

// THE PLATFORM

Everything you need to govern AI — in one connected platform.

Each capability is an independent, auditable module. Subscribe to what you need today; compose the rest as you scale.

Code Audit Engine

Repository-level compliance audits, sealed as evidence.

  • AST-level analysis across 8+ languages, COBOL and VB6 included
  • Findings mapped to specific clauses, with severity and remediation
  • Async API — submit, poll, retrieve. CI/CD friendly.

Evidence Sealing

Tamper-evident cryptographic proof your evidence is intact.

  • Every report chained into a verifiable audit trail
  • Any post-hoc alteration is mathematically detectable
  • Court-admissible format, independently verifiable

Reviewer Gate

Deterministic human-in-the-loop control before execution.

  • Policy-driven auto-approve, auto-reject, or escalate
  • Humans govern at the constitutional level
  • Every decision logged and attributable

AI Firewall

Pre-inference interception for the threats models can't see.

  • Prompt-injection and adversarial-pattern blocking
  • PII masked before content reaches any model
  • Threat patterns mapped to MITRE ATLAS

Legacy Migration

Modernise legacy estates without a big-bang rewrite.

  • COBOL, VB6 and C++ re-emitted as governed TypeScript
  • Incremental, module by module
  • CICS / VSAM / BMS emulation included

Multi-Provider Gateway

Any model, any provider — with automatic failover.

  • Alibaba (Qwen), Anthropic, Google, local Ollama
  • Cross-provider fallback, no lock-in
  • One API surface for your whole estate

// LIVE PROOF — READ FROM OUR OWN REGISTRY

Governed by the same core we sell.

These figures are read from OAG's own registry. The platform that audits you is itself audited, sealed and versioned.

2,368governed code modules
322,902isolated decision routes
24frameworks as executable code
33governed releases, sealed

// TRUST

Built for the industries where proof is non-negotiable.

FINANCIAL SERVICES HEALTHCARE PUBLIC SECTOR LEGAL INSURANCE
“The evidence trail is what sold our board. We went from a binder nobody trusted to a report a regulator can verify itself.”
Design PartnerChief Compliance Officer, Financial Services
“Ninety seconds from repository to sealed findings. Our last compliance review took a quarter of engineering time.”
Design PartnerChief Technology Officer, Regulated SaaS
ISO/IEC 42001 ALIGNED EU AI ACT MAPPED NIST AI RMF MAPPED MALAYSIA AI ACT 2026

// HERITAGE

Thirty years of compliance, distilled into runtime.

1995

BS 7799 — the binder era

Controls on paper, audited by humans, stale on arrival.

2005

ISO/IEC 27001 — the process era

Structured audits. The gap between documented and actual remained.

2015

DevSecOps — the pipeline era

Checks at the gate. Governance stopped the moment code deployed.

2026

OAG — the constitutional era

Governance compiled into every route and every decision. Verifiable at runtime, sealed by Merkle root.

"Humans govern at the constitutional level. Machines execute at the operational level." — THE OAG CONSTITUTION

// ARCHITECTURE

Three layers. One plane of accountability.

OAG is not an LLM and not an IDE. It is the governance layer between them.

LAYER 3 · CONSUMERS AI Applications — copilots, agents, internal tools, legacy estates in migration
↕  secure routing · request addressing · safety-integrity enforcement
LAYER 2 · OAG CORE Governance plane — 322,902 decision routes · human review gates · PII masking · tamper-evident audit chain · intelligent caching
↕  provider-agnostic · no lock-in
LAYER 1 · PROVIDERS Model providers — Alibaba (Qwen) · Anthropic · Google · local Ollama

Put your next audit
beyond dispute.

Three free audits a month. No credit card. Ninety seconds to evidence.

ENTERPRISE & SELF-HOSTED: me@jhosen.com