Enterprise AI Control Plane

Govern every AI system. Refuse the requests you should. Prove both.

MERIDVAR discovers the AI in use across your organisation, records how each system and vendor was assessed and approved, stops the requests your policy rejects before a model is called, and keeps the evidence. It runs on your infrastructure. Nothing is sent to us.

  • Self hosted
  • Single tenant
  • No telemetry
  • Runs offline
ADMISSION GATEWAY · YOUR NETWORKNO VENDOR CLOUD
How MERIDVAR controls an AI requestRequests from people, applications, agents and MCP servers pass through the MERIDVAR admission gateway on the customer network. An admitted request reaches the model provider. A refused request stops at the gateway and the provider is never contacted. Every decision is written to a hash chained evidence log.CUSTOMER INFRASTRUCTUREMODEL PROVIDERSPeopleApplicationsAI agentsMCP serversMERIDVARSeventeen stage admission pipelineidentityPASSshadow-aiPASSprompt-dlpREFUSEthreatSKIPPEDresidencySKIPPEDvendor-riskSKIPPEDbudgetSKIPPED+ 10 MORE STAGESAnthropicOpenAIAzure OpenAIxAIADMITTED: ONE CALLREFUSED: ZERO CALLSGOVERNANCE EVIDENCE LOG · APPEND ONLY · HASH CHAINEDCLASSIFIED9f2c…a71eREVIEWEDa71e…03bdAPPROVED03bd…c45aREFUSEDc45a…e210Every decision names who made it, when and on what basis.
Illustration of documented behaviour. A refused request never contacts the model provider.

The problem

AI use has outrun AI governance.

Employees use consumer AI. Developers wire in model APIs. Business units buy AI inside SaaS. Agents act through MCP servers. Each decision was local. The exposure is not.

UNKNOWNAINo single inventory of the systems, agents and vendors in use.
UNKNOWNRiskNo shared view of data, autonomy and decisions about people.
UNKNOWNData flowsA prompt is an authorised request to an authorised service, with the data in the body.
UNKNOWNSpendConsumption spread across teams, keys and providers.
UNKNOWNAccountabilityNobody can show who approved what, on what basis, until when.

13%

of organisations reported a breach of AI models or applications.

97%

of those breached lacked proper AI access controls.

USD 670K

added to the average breach cost where shadow AI use was high.

Source: IBM, Cost of a Data Breach Report 2025.

Product walkthrough

From an unknown AI system to an auditable decision.

Follow one system through the appliance: found, owned, classified, reviewed, approved, controlled and evidenced.

MERIDVAR CONSOLEILLUSTRATIVE

AI inventory

Systems this appliance observed in traffic, or a person declared.

Support reply assistantObserved in gateway trafficCandidate
Contract summariserDeclared by an operatorDeclared
Unsanctioned chat serviceFound in an uploaded proxy logCandidate
Legacy translation botDeclared by an operatorRetired

An observation never becomes a declaration on its own. A person confirms it. An empty inventory means nothing was recorded, not that no AI is in use.

Illustrative interface with invented example data. It shows behaviour documented for the current release and is not a screenshot of a customer environment.

Who it is for

One control plane for every team that answers for AI.

CISO

Know what AI exists. Know what it is doing. Control the risk.

  • Shadow AI discovered against your sanctioned provider list
  • Prompt DLP, threat detection and residency enforced before the call
  • Agents and MCP servers registered, reviewed and risk rated
AI Security

CIO · CTO

Enable enterprise AI without losing control.

  • An OpenAI compatible endpoint your teams and SDKs already speak
  • Approved model lists, with four providers supported for live dispatch
  • A path to yes: assess, review, approve, with conditions
Product

CFO · FinOps

Make AI financially accountable.

  • A ledger of governed requests: tokens, model and actual cost
  • Spend by team and by model, over time
  • Team budgets with hard or soft caps, enforced at admission
AI FinOps

Privacy · Compliance · Legal

Turn AI governance into auditable evidence.

  • Every decision recorded with who, when and on what basis
  • Approvals that read "review required" when the facts change
  • An audit package per AI system and per vendor
AI Governance

Why now

Three trends are converging on the same gap.

01

AI adoption is decentralised.

AI arrives through employees, SaaS features, developer keys and vendor contracts at the same time. No single team sees all of it.

02

AI systems are becoming autonomous.

Agents call tools. MCP servers expose enterprise systems to models. A tool that can delete, pay or send data outside is a new kind of privileged access.

03

Accountability is now on a schedule.

EU AI Act transparency obligations have applied since 2 August 2026. Boards, auditors and regulators ask the same question: show us how AI is governed.

Why MERIDVAR

The decision, the gate and the evidence, in one place you operate.

MERIDVAR is focused where a GRC suite or a security platform is broad. Its distinction is architectural.

No vendor cloud

There is no MERIDVAR control plane in our cloud and no telemetry. Prompt content is inspected, and evidence is kept, on your own infrastructure. No new data processor enters the path.

Governance tied to a gate that can refuse

The record of what was approved and the gateway that admits or refuses requests live in the same appliance and write to the same evidence log.

Decisions that go stale visibly

An approval keeps the basis it was granted on. When an answer, a vendor decision or a classification changes, it reads "review required", with the reasons.

Customer controlled by design

Self hosted, single tenant and offline capable, with signed licences and signed updates verified on the appliance. See the deployment model

CategoryWhat it does wellWhere MERIDVAR sits
AI governance platformsProgramme workflow, policy content, model riskGovernance tied to observed traffic and to a gate that can refuse, run by the customer
AI security platformsBroad AI threat coverage, from models to agentsFocused on admission control, with no vendor in the data path and the governance record included
SSE, CASB and SASEInline access control at network scaleComplementary: AI specific governance, evaluated on your network
DSPM and data securityFinding and protecting data at restComplementary: governs decisions about AI systems and the prompt itself, before the call
LLM gateways and AI FinOpsRouting, caching, developer adoptionSpend by team and model beside the security and governance decision
GRC platformsEnterprise wide risk and control librariesThe AI specific record a GRC programme can draw on

Where a buyer is comfortable with cloud processing, an incumbent platform is often the right choice. MERIDVAR is built for the buyer who will not add a vendor cloud to the AI data path.

Architecture

The control plane runs where you run it.

One appliance between your callers and your model providers. Five connected stages. One record for every team.

REFERENCE ARCHITECTURESINGLE TENANT APPLIANCE
MERIDVAR reference architectureCallers on the customer network reach AI providers through the MERIDVAR appliance, which runs five connected stages: discover, assess, approve, control and prove. Security, privacy, risk, finance and audit teams read one shared record. Nothing leaves the customer network to MERIDVAR.YOUR NETWORKOUTSIDE YOUR NETWORKPeopleTokens per personAI applicationsOpenAI compatible APIAI agentsSigned identitiesMCP serversDeclared inventoryUnmanaged trafficPAC and proxy captureMERIDVAR applianceOne organisation. One appliance. No control plane in our cloud.DISCOVERInventory · shadow AI01ASSESSQuestionnaires · risk rules02APPROVEReviews · approvals03CONTROLAdmission gateway04PROVEEvidence log · audit package05Model providersAnthropic · OpenAI · Azure OpenAI · xAISelf hosted modelsYour own endpointSaaS AI servicesSeen through logsADMITTED REQUESTS ONLYNO TELEMETRY TO MERIDVARRUNS WITHOUT INTERNET ACCESSONE SHARED RECORDSecurityPrivacyRisk and complianceFinanceAuditVisibility, policy, control, evidence and spend, read from the same appliance by every team that answers for AI.
Controls apply to traffic routed through the gateway. Visibility of other traffic depends on uploaded logs, endpoint agents and declarations.

Outcomes

What changes when AI has a control plane.

Less unmanaged exposure

Sensitive identifiers are caught before they leave. Unsanctioned providers are seen, then blocked if you choose.

A real inventory

Every AI system has an owner, a purpose, a vendor and a status, whether it was observed or declared.

Adoption with a path to yes

Teams get a defined route to approval instead of a blanket no, and approvals carry conditions and an end date.

Spend with an owner

Cost per team and per model, with budgets enforced at the point of admission.

Evidence on request

Answer an auditor with the record of what was decided, by whom and when, not with a reconstruction.

Less friction between teams

Security, IT, privacy, finance and the business read the same status for the same system.

Global governance

Evidence that travels across frameworks.

MERIDVAR helps organisations operationalise governance controls and generate evidence relevant to the frameworks they answer to. Whether an organisation is compliant remains its own determination.

See the mapping by territory
FrameworkIn the product today
EU AI ActControl mapping with computed status
NIST AI RMFControl mapping with computed status
ISO/IEC 42001Control mapping with computed status
GDPR, DORA, NIS2, LGPDRelevant evidence. Not mapped as frameworks.

Trust

Built for the buyer who reads the architecture first.

Deployment

A single tenant appliance on your infrastructure. One appliance, one organisation.

Data handling

No raw identifier is stored. Findings keep masked samples. Provider keys never return to the browser.

Access control

Admin, operator and viewer roles, checked on the server. The approver is never the requester.

Auditability

An append only, hash chained log. A record edited on disk reads as an evidence mismatch.

See the deployment model

For investors

Building the control layer for the AI economy.

Every enterprise that adopts AI needs to know what it runs, decide what is allowed, enforce that decision and prove it. That is a new control layer, with several budget owners and a record that compounds.

Investor overview

See MERIDVAR refuse a request on your own network.

A working session with the founder. We install the appliance with you, route a test request and walk through the evidence it leaves behind.