Enkrypt AI, implemented and run by the people who set the guardrails
Enkrypt AI tests, protects and governs the AI your organisation runs: red-teaming that finds how a model or an agent can be turned, guardrails that approve, modify or block what it does at runtime, and a policy engine that turns your governance documents and the frameworks you answer to into controls that produce their own evidence. Kode-1 is an Enkrypt AI partner in Australia and the APAC region. We assess with it, deploy it, tune it to your use cases, and run the program that keeps the AI you ship defensible.
What Enkrypt AI does
Enkrypt AI secures the AI an organisation builds and buys, and it is built around agents. Red-teaming attacks a model, an assistant or an agent the way an adversary would, through the tools and sources it talks to, and returns a register of what broke with the fix. Guardrails sit in the path at runtime and approve, modify or block a prompt, an answer or an action, with every decision logged. The policy engine turns your governance documents and frameworks into the controls those guardrails enforce, each traced to its clause. Around them sit a data risk audit and a gateway and scanner for the servers that give agents their tools.
Where it earns its place
Enkrypt AI suits organisations that look like these.
Agents with real credentials
Assistants and agents that can act on systems, and a security team with no way to see or limit what they do at runtime.
AI in front of customers
An assistant answering the public, where one toxic or deceptive reply is a headline and one leaked record is a breach.
A regulated industry
Financial services, health or government, where the AI obligations already exist and the evidence has to be produced on demand.
Several frameworks at once
ISO 42001, the NIST AI RMF, the EU AI Act and a regulator's guidance, each read by a different team and none turned into a control.
Many models, many providers
Teams building on whichever model suits them, and a security function that needs one set of controls across all of them.
A security team without an AI playbook
Capable people who can see a server get breached and cannot yet see a model get persuaded.
What Kode-1 adds
Assess
- The AI Risk Assessment run with the platform's red-teaming, so the register is built from what actually broke rather than from interviews
- The inventory of AI in use, sanctioned and not, that the assessment starts from and the platform cannot supply on its own
- A board-ready summary of exposure, in the shape the frameworks you answer to expect
Deploy
- Guardrails wired into the sanctioned path to production, so the safe route is also the quick one
- Your policies and frameworks loaded into the policy engine and turned into controls with owners and approvals
- Integration with identity, so enforcement knows who is asking, and with security operations, so AI activity is signal rather than noise
Operate
- A retesting rhythm, because the models change, the attacks change and last quarter's pass means little
- Tuning of guardrails against real traffic, so they hold without being switched off by a frustrated team
- Managed operation under agreed service levels if you would rather we ran it with you
License
- Licensing through Kode-1 or directly with the vendor, whichever suits your procurement
- Sizing against the AI you actually run, and right-sizing as the estate grows
- One accountable partner for the platform and the program, rather than a reseller and a consultancy who each point at the other
How we deploy it
Six steps, in this order.
- 01
Inventory
Every model, assistant, agent and embedded vendor feature in use, what each can reach, and who owns it.
- 02
Red-team
The systems you are about to rely on attacked the way an adversary would, and a register of what broke with the fix beside it.
- 03
Guardrail
Runtime enforcement placed on the sanctioned path, tuned against real traffic until it holds without friction.
- 04
Codify
Your policies and frameworks turned into controls with owners, reviewers and an approval before production.
- 05
Wire
Identity and security operations connected, so enforcement knows who is asking and the SOC can see and act on AI activity.
- 06
Report
Exposure, decisions and progress reported on a rhythm a board, an auditor or a regulator will accept as evidence.
Who it suits, and who it does not
Enkrypt AI suits an organisation with AI in production or about to be: agents that can act, assistants in front of customers or staff, more than one model or provider, and a regulator, auditor or client asking how it is governed. The more autonomy the AI has, the more the runtime layer is worth. It is less compelling for a single internal assistant with no tools, no customer contact and no regulated data, where a sanctioned enterprise account and a short usage policy may be enough, and we will say so rather than deploy a platform into a problem that does not need one. The same applies where the gap is inventory rather than enforcement: a platform cannot protect AI nobody has listed, which is why the work starts with the inventory whether or not the platform follows.
A chosen partner, and still independent advice
Our AI security page names no vendor. The advice answers to your outcome, and the tooling test we publish there applies to every platform, including this one. We chose Enkrypt AI because it passes that test for agentic systems, and because being close to the product sharpens what we can tell you about it. Where it is the right fit we will say so, deploy it, and stand behind the result. Where it is not, you will hear that first.
Agent Red Teaming, Agent Guardrails and Agent Policy Engine
Each card names the problems that product answers, and links to the page on this site that describes the problem without naming a platform.
Agent Red Teaming
Adversarial testing of models, agents, retrieval and the tools they call, before they reach production and on a schedule afterwards.
- Prompt injection, including instructions smuggled in through documents, web content and tool results
- Jailbreaks and refusal bypass, across text, audio and images
- Agents whose goal is redirected mid-task, or that loop and drift outside what they were built to do
- Unsafe delegation between agents, and poisoned memory or retrieval sources
- Findings with reproduction steps and a fix, and a pre-release gate in the pipeline so they stay fixed
Agent Guardrails
Runtime enforcement between your AI and the world: a prompt, an answer or an agent's action is approved, modified or blocked, without friction your users notice.
- Injection that arrives at runtime, after testing, through the content a model reads
- Personal, health or payment data in prompts and answers that should never have been there
- Toxic, deceptive or off-brand output reaching a customer
- Tool misuse, over-broad permissions and one unsafe action cascading into the next
- An enforcement log an auditor will accept as evidence of control
Agent Policy Engine
Governance and regulation turned into controls: policy text in, enforceable controls out, each traced to the clause it came from and the place it is enforced.
- AI policy that lives in a document nobody can point a control at
- ISO 42001, the NIST AI RMF and the EU AI Act applying at once, with three sets of evidence to assemble
- Controls with no owner, no reviewer and no approval before they reach production
- An audit answered by hand each time, from screenshots and good intentions
- Rules for what an agent may do, written once and enforced everywhere it runs
Start with a conversation
Choose how you want to begin. A partner replies within one business day.
Before you enquire
Only where you want it to. Guardrails are placed on the sanctioned route to production and tuned against real traffic, and the platform is built to enforce without a delay users notice. Red-teaming and the policy engine sit beside the path, not in it.
It works across model stacks, including agents built on more than one provider and the tools and retrieval sources they call. Tell us what you run and we will confirm coverage against it in the demo.
Either. Some organisations prefer one accountable partner for the platform and the program; others have procurement arrangements with the vendor already. We size the licence against the AI you run either way, and our advice on the platform does not change with where the invoice comes from.
Those controls see a request as traffic and a document as data. They do not see that a model is being persuaded, that an agent is about to take an action nobody authorised, or that an answer is confidently wrong. This layer sees exactly those things, and hands what it sees to the security team you already have.
Yes. Submit the RFI, RFP or RFQ through the form, we reply with where to send the documents, and we respond within the timeframe your process sets, with licensing, implementation and managed-service pricing in one proposal, a reference architecture for your estate, and answers written by the engineers who would do the work.
Yes. Managed operation covers the retesting rhythm, guardrail tuning, control changes as your policies and the frameworks move, and reporting, under agreed service levels. You can start with the assessment and deployment, run the program with us, and decide later whether to keep it in-house or leave it with us.
The AI security page describes the problem and the six things that have to be true, whatever tooling you choose. This page is about one platform we bring when it fits. Start there if you are still deciding whether the problem applies to you; start here if you are already evaluating this platform or have chosen it.