AI adoption is outrunning AI governance.
Inside most organizations, any team can call any model provider, enable any tool, or connect any MCP server — with no central record and no enforcement of policy. That's a manageable risk until it isn't: a regulated workload, an unreviewed vendor, a request nobody can explain after the fact.
AssuranceOps exists to put a control point between your applications and every AI provider they call — so policy is enforced in the request path, not discovered afterward in a postmortem.
What we believe
Fail closed by default
Anything not explicitly permitted by policy is rejected before a token is spent — not logged after the fact and forgiven.
Enforce in the request path, not after it
Policy is evaluated inline, on every request, not audited retroactively from a dashboard nobody checks.
Record everything, expose nothing extra
PII and PHI detection records the kind of data found in a request — never the value itself.
Self-hostable, always
The gateway, policy, and evidence stay in your infrastructure under an Apache-2.0 license. Only policy-approved traffic reaches an external provider.
Where we are today
AssuranceOps is pre-1.0 and is best described as a substantial functional MVP. The governance gateway, hosted OIDC administration, tenant-scoped RBAC, budgets, data protection, prompt governance, audit evidence, posture scoring, alerts, response automation, reporting, and multi-tenant operations are implemented today. Release hardening and broader platform expansion remain active work — see the roadmap.
The gateway is source-available under Apache-2.0. You can read every line of policy enforcement before you trust it with a single request.
Request deployment access.
Tell us what you need to govern and where you plan to run it.
By joining, you agree to our Privacy Policy and Terms.