Governed AI infrastructure · Private beta
The boundary between
permission and consequence.
AI agents are being deployed with access to APIs, payments, email and code execution — with no governance layer. No proof of who authorised what. No record of what happened. Eden Control is the infrastructure that proves every AI action was authorised — and preserves what happened afterwards in a record anyone can verify.
The world needs this
Three reasons this cannot wait.
AI agents have no seatbelt
Companies are racing to give AI agents access to production systems, bank accounts, email, and code execution. There is no standard for proving what was authorised, by whom, and within what limits. The equivalent of deploying self-driving cars without brakes — not because nobody thought of it, but because nobody has built the infrastructure.
Liability evaporates without a record
When an AI agent makes a consequential mistake, the question is always: who authorised this? Without an authority record, the answer is nobody — and everybody. Organisations need durable, independently verifiable proof of who decided what.
Regulation is coming — infrastructure is not ready
The EU AI Act, UK framework, and US executive orders all point to mandatory AI governance. Compliance today means paperwork, not infrastructure. Eden Control makes governance real-time, auditable and machine-verifiable.
How it works
AI proposes. Authority decides. Evidence survives.
Every consequential AI action requires an authority envelope before it can execute. The system checks the envelope against deterministic patterns. If clear: Allow. If uncertain: Investigate — routed to a human reviewer with an expiry. If blocked: Deny — fail-closed, no exceptions. Every outcome produces a cryptographic receipt. No valid authority, no action.
Exact-action authority
Bind principal, agent, action, purpose, budget and expiry into a cryptographic authority envelope. No envelope, no action.
Contestable Investigate
Route uncertainty to named human reviewers with evidence, expiry, dissent and a fail-closed timeout. Hesitation is the control.
Portable outcome proof
Authority, decision, execution and outcome connected in a single receipt. Offline-verifiable by anyone. No trust in the system required.
Current proof posture
Clear status beats inflated claims.
We publish what is built, what is under test, and what remains a release gate.
Operator shell
Separate Control shell with explicit tenant context, routed gateway domain, and Google identity verification at the API boundary.
Ternary gate engine
1,219 deterministic gates across legal, development, operations and shared domains. Every action checked. Uncertainty holds.
Portable authority envelope
Exact-action delegation with offline-verifiable outcome receipts. Hardening for external audit is the active programme.
External assurance
Independent penetration testing and published bypass-resistance evidence remain explicit release gates. We will not claim security we have not proven.