Policy
Every AI interaction is checked against the policy you set. By default, nothing goes through without your authorized manager's authorization. We include what's regulated by default; you can add your own.
Pick your plan with your own keys or fully managed: tonia, +, Pro, or Enterprise. Every request passes the same three control points.
Same path, whatever the model. Every AI request from your team passes three gates. No tonia tier skips them.
Every AI interaction is checked against the policy you set. By default, nothing goes through without your authorized manager's authorization. We include what's regulated by default; you can add your own.
Before anything is sent, every message is scanned for personal data (SIN, address, phone, and more). If data is found, the request stops.
Every decision is signed, timestamped, and kept in Canada. You retain clear proof of what was allowed or blocked.
* With the Enterprise plan and on-prem execution, the log can remain on your infrastructure.
Our own models, built for on-prem execution, are in preparation.
The authorized manager sets the rules. tonia detects, decides, and keeps the proof.
Rules
The authorized manager chooses sensitive categories and the handling mode.
Detection
tonia finds regulated information before anything is sent.
Decision
The request is allowed, blocked, or redacted according to the rule.
Proof
The decision is signed, timestamped, and kept in Canada.
Summarize this client file containing SIN 123-456-789.
A SIN was detected. Nothing was sent to the provider.
BLOCKED
Category: SIN
Timestamped July 31, 2026 at 9:18 a.m.
Redaction is available only when the authorized manager allows it and the user requests it.
See detection limits →A 30-minute consultation with a tonia specialist is enough to scope your needs, the bundle, and the onboarding timeline. No commitment.