Enterprise AI Control Plane
Govern every AI system. Refuse the requests you should. Prove both.
MERIDVAR discovers the AI in use across your organisation, records how each system and vendor was assessed and approved, stops the requests your policy rejects before a model is called, and keeps the evidence. It runs on your infrastructure. Nothing is sent to us.
- Self hosted
- Single tenant
- No telemetry
- Runs offline
The problem
AI use has outrun AI governance.
Employees use consumer AI. Developers wire in model APIs. Business units buy AI inside SaaS. Agents act through MCP servers. Each decision was local. The exposure is not.
13%
of organisations reported a breach of AI models or applications.
97%
of those breached lacked proper AI access controls.
USD 670K
added to the average breach cost where shadow AI use was high.
Source: IBM, Cost of a Data Breach Report 2025.
The control plane
Five questions. One record.
Governance programmes start from declared inventories, disconnected from the traffic. Security products start from traffic, disconnected from the decision. MERIDVAR keeps both in one place, on your network.
Discover
What AI is in use?
An AI inventory of systems observed in traffic or declared by people. Shadow AI discovery against your sanctioned provider list. Agent registry, MCP server inventory and endpoint agents.
Assess
How risky is it?
Versioned questionnaires for AI systems, vendors, agents and MCP servers. Rules based classification, from Low to Critical, with a reason for every factor. Unknown is never read as safe.
Approve
Who approved it, and until when?
Privacy and security reviews. Approval decided by an administrator who did not request it, on a pinned basis, with conditions and an end date.
Control
What is let through?
A seventeen stage admission gateway. Prompt DLP, threat detection, data residency, vendor requirements, budgets and approved models. A refusal never contacts the model provider.
Prove
Can we show it?
An append only, hash chained evidence log. A status per AI system and vendor that shows what changed since each decision. An audit package per subject.
Product walkthrough
From an unknown AI system to an auditable decision.
Follow one system through the appliance: found, owned, classified, reviewed, approved, controlled and evidenced.
AI inventory
Systems this appliance observed in traffic, or a person declared.
An observation never becomes a declaration on its own. A person confirms it. An empty inventory means nothing was recorded, not that no AI is in use.
Support reply assistant
The inventory record a person confirmed.
- Owner
- Head of Customer Operations
- Purpose
- Drafts replies to customer tickets for an agent to review
- Vendor
- Linked to a provider this appliance knows
- Models
- Recognised from observed requests
- Linked
- 1 agent · 1 MCP server
- Provenance
- Observed, then confirmed as declared
Risk classification High
Computed by published rules from the completed baseline assessment. The person does not choose the level.
Requires a privacy review, a security review and an approved vendor before approval can be requested.
Reviews
A reviewer's decision, with findings, conditions and a next review date.
A privacy review is not a DPIA. A security review is not a certification. The console says so on the page.
Approval Approved
Decided by an administrator who did not make the request.
- Requested by
- Operator, Customer Operations
- Decided by
- Administrator, Security
- Basis
- Classification, both reviews, vendor approval and inventory snapshot, pinned at request
- Conditions
- Block the delete tool on the linked MCP server
- Ends
- Twelve months from decision. Three years is the maximum.
If anything in the basis changed since the request, the approval is refused. The administrator approves what is in front of them.
Gateway Refused
A request carrying a national identification number, tested from the playground.
The refusal names the rule that caused it. Nothing was sent and nothing is billed.
Governance status Review required
The vendor's classification changed after approval. Nothing is revoked automatically. A person decides.
Download the audit package: every record about this system, as stored, with a statement of what the package does not prove.
Illustrative interface with invented example data. It shows behaviour documented for the current release and is not a screenshot of a customer environment.
Who it is for
One control plane for every team that answers for AI.
CISO
Know what AI exists. Know what it is doing. Control the risk.
- Shadow AI discovered against your sanctioned provider list
- Prompt DLP, threat detection and residency enforced before the call
- Agents and MCP servers registered, reviewed and risk rated
CIO · CTO
Enable enterprise AI without losing control.
- An OpenAI compatible endpoint your teams and SDKs already speak
- Approved model lists, with four providers supported for live dispatch
- A path to yes: assess, review, approve, with conditions
CFO · FinOps
Make AI financially accountable.
- A ledger of governed requests: tokens, model and actual cost
- Spend by team and by model, over time
- Team budgets with hard or soft caps, enforced at admission
Privacy · Compliance · Legal
Turn AI governance into auditable evidence.
- Every decision recorded with who, when and on what basis
- Approvals that read "review required" when the facts change
- An audit package per AI system and per vendor
Why now
Three trends are converging on the same gap.
01
AI adoption is decentralised.
AI arrives through employees, SaaS features, developer keys and vendor contracts at the same time. No single team sees all of it.
02
AI systems are becoming autonomous.
Agents call tools. MCP servers expose enterprise systems to models. A tool that can delete, pay or send data outside is a new kind of privileged access.
03
Accountability is now on a schedule.
EU AI Act transparency obligations have applied since 2 August 2026. Boards, auditors and regulators ask the same question: show us how AI is governed.
Why MERIDVAR
The decision, the gate and the evidence, in one place you operate.
MERIDVAR is focused where a GRC suite or a security platform is broad. Its distinction is architectural.
No vendor cloud
There is no MERIDVAR control plane in our cloud and no telemetry. Prompt content is inspected, and evidence is kept, on your own infrastructure. No new data processor enters the path.
Governance tied to a gate that can refuse
The record of what was approved and the gateway that admits or refuses requests live in the same appliance and write to the same evidence log.
Decisions that go stale visibly
An approval keeps the basis it was granted on. When an answer, a vendor decision or a classification changes, it reads "review required", with the reasons.
Customer controlled by design
Self hosted, single tenant and offline capable, with signed licences and signed updates verified on the appliance. See the deployment model
| Category | What it does well | Where MERIDVAR sits |
|---|---|---|
| AI governance platforms | Programme workflow, policy content, model risk | Governance tied to observed traffic and to a gate that can refuse, run by the customer |
| AI security platforms | Broad AI threat coverage, from models to agents | Focused on admission control, with no vendor in the data path and the governance record included |
| SSE, CASB and SASE | Inline access control at network scale | Complementary: AI specific governance, evaluated on your network |
| DSPM and data security | Finding and protecting data at rest | Complementary: governs decisions about AI systems and the prompt itself, before the call |
| LLM gateways and AI FinOps | Routing, caching, developer adoption | Spend by team and model beside the security and governance decision |
| GRC platforms | Enterprise wide risk and control libraries | The AI specific record a GRC programme can draw on |
Where a buyer is comfortable with cloud processing, an incumbent platform is often the right choice. MERIDVAR is built for the buyer who will not add a vendor cloud to the AI data path.
Architecture
The control plane runs where you run it.
One appliance between your callers and your model providers. Five connected stages. One record for every team.
Outcomes
What changes when AI has a control plane.
Less unmanaged exposure
Sensitive identifiers are caught before they leave. Unsanctioned providers are seen, then blocked if you choose.
A real inventory
Every AI system has an owner, a purpose, a vendor and a status, whether it was observed or declared.
Adoption with a path to yes
Teams get a defined route to approval instead of a blanket no, and approvals carry conditions and an end date.
Spend with an owner
Cost per team and per model, with budgets enforced at the point of admission.
Evidence on request
Answer an auditor with the record of what was decided, by whom and when, not with a reconstruction.
Less friction between teams
Security, IT, privacy, finance and the business read the same status for the same system.
Global governance
Evidence that travels across frameworks.
MERIDVAR helps organisations operationalise governance controls and generate evidence relevant to the frameworks they answer to. Whether an organisation is compliant remains its own determination.
See the mapping by territory| Framework | In the product today |
|---|---|
| EU AI Act | Control mapping with computed status |
| NIST AI RMF | Control mapping with computed status |
| ISO/IEC 42001 | Control mapping with computed status |
| GDPR, DORA, NIS2, LGPD | Relevant evidence. Not mapped as frameworks. |
Trust
Built for the buyer who reads the architecture first.
Deployment
A single tenant appliance on your infrastructure. One appliance, one organisation.
Data handling
No raw identifier is stored. Findings keep masked samples. Provider keys never return to the browser.
Access control
Admin, operator and viewer roles, checked on the server. The approver is never the requester.
Auditability
An append only, hash chained log. A record edited on disk reads as an evidence mismatch.
For investors
Building the control layer for the AI economy.
Every enterprise that adopts AI needs to know what it runs, decide what is allowed, enforce that decision and prove it. That is a new control layer, with several budget owners and a record that compounds.
Investor overviewSee MERIDVAR refuse a request on your own network.
A working session with the founder. We install the appliance with you, route a test request and walk through the evidence it leaves behind.