Policy
Every AI interaction is checked against the policy you set. By default, nothing goes through without your authorized manager's authorization. We include what's regulated by default; you can add your own.
Two offers: your own keys, or tonia as the provider. Every request passes the same three control points, outside the model.
Same path, whatever the model. The rules live outside the model. Every AI request from your team passes three gates. No tier skips them.
Every AI interaction is checked against the policy you set. By default, nothing goes through without your authorized manager's authorization. We include what's regulated by default; you can add your own.
Before anything is sent, every message is scanned for personal data (SIN, address, phone, and more). If data is found, the request stops.
Every decision is signed, timestamped, and kept in Canada. You retain clear proof of what was allowed or blocked.
* With the Enterprise plan and on-prem execution, the log can remain on your infrastructure.
Our own models, built for on-prem execution, are in preparation.
The authorized manager sets the rules. detects, decides, and keeps the proof.
Rules
The authorized manager chooses sensitive categories and the handling mode.
Detection
finds regulated information before anything is sent.
Decision
The request is allowed, blocked, or redacted according to the rule.
Proof
The decision is signed, timestamped, and kept in Canada.
Summarize this client file containing SIN 123-456-789.
A SIN was detected. Nothing was sent to the provider.
BLOCKED
Category: SIN
Timestamped July 31, 2026 at 9:18 a.m.
Redaction is available only when the authorized manager allows it and the user requests it.
See detection limits →A 30-minute consultation with a specialist is enough to scope your needs, the bundle, and the onboarding timeline. No commitment.