Governance Compliance STPM TOPAS Frameworks
HEX 165

The sovereign operating platform that runs on the Inference Distribution Network (IDN)

HEX 165 governs the AI execution layer through four integrated engines: Governance, Compliance, STPM and TOPAS. Together, they enforce policy, assess regulatory alignment, monitor runtime behaviour, control token flow, optimise inference cost and record every material event to a hash-chained audit log.

Every agent call is governed, scanned, monitored, priced and evidenced by design.

Engine 01

Governance Engine

Enterprise control plane for governed agentic AI. Buyers: CISO, General Counsel, CFO and Head of AI.

The Governance Engine is the day-to-day control plane for agentic AI in regulated environments. It turns organisational policy into enforceable runtime controls, authored as code, versioned in source control and applied to every agent call.

It governs who or what is acting, what data is in scope, which model can be used, what budget applies, when human approval is required and what evidence must be retained.

Where the Compliance Engine verifies what the regulator expects, the Governance Engine controls what the organisation actually allows AI to do.

  • Policy engine: declarative policy as code, evaluated on every call. The same text always produces the same authorisation.
  • Access controls: each agent has an identity, scope, clearance band and budget. Out-of-scope requests fail closed with a reason written to the audit log.
  • Model version control: every version pinned to a signed manifest with a delta scan. Rollback is one click.
  • TokenOps via TOPAS, real-time cost per agent, workflow, business unit and model. Budgets enforced in policy, not at quarterly review.
  • Human-in-the-loop: configurable sign-off thresholds, reviewer routing with full call context, and SLA monitoring.

At a glance

5
Governance capability areas
1-click
Model rollback
Real-time
TokenOps cost telemetry
Hash-chained
Immutable audit, independently verifiable
Engine 02

Compliance Engine

Multi-framework compliance assessment for agentic AI systems. Buyers: Chief Compliance Officer, Data Protection Officer, AI ethics committee and internal audit.

The Compliance Engine is a read-only scanner and deterministic rules engine for regulated AI estates. It maps agent code, architecture and documentation against all supported compliance frameworks (including the EU AI Act, DORA, GDPR and NIST AI RMF) in a single assessment.

It identifies regulatory gaps, cross-framework obligations and architecture-level risks unique to agentic systems, then traces every finding back to the relevant framework, article, control or evidence requirement.

No machine learning interprets the rules. No probabilistic reasoning determines compliance. The engine is deterministic, repeatable and auditable line by line.

  • One scan covers all 16 supported frameworks, with 42 cross-reference mappings so one finding can satisfy several frameworks at once.
  • 15 agentic risk flags catch architecture issues the legal checklists do not name, such as dynamic agent spawning and missing stop mechanisms.
  • Runs as a Docker container, an npm terminal command, or an MCP server for Claude Desktop and Cursor. Offline scanning supported.
  • Raw code, documents and data never leave your environment. Only structural metadata is transmitted, over TLS.
  • Every finding cites the article, paragraph and source URL. Output in HTML, JSON or PDF.

At a glance

16
Frameworks supported, one scan
648
Criteria across the core frameworks
15
Agentic risk flags
42
Cross-reference mappings
Compliance coverage

Supported regulatory frameworks

We have now built these frameworks into the engine. The Compliance Engine covers 16 frameworks across UK, EU, US and international standards, evaluated together in a single scan.

Engine 03

STPM Engine

Sovereign Threat Protection and Monitoring for sensitive AI and data environments. Buyers: Head of SecOps, CISO and regulated operations teams.

The STPM Engine provides privacy-preserving runtime security for UK / EU-controlled environments. It is designed for workloads where conventional telemetry can itself become a source of exposure, revealing sensitive file names, folder paths, command arguments, user identities, network destinations or the subject matter of an investigation.

STPM detects abnormal runtime behaviour close to source, minimises and anonymises sensitive context before telemetry leaves the monitored asset, and routes high-impact response or evidence reveal through human-authorised controls.

The engine supports open standards including OpenTelemetry / OTLP, OCSF, Sigma, OPA / Rego, SPIFFE / SPIRE and mTLS, enabling interoperability without compromising the sovereign operating region.

The result is runtime protection without turning monitoring data into a second data leak.

  • Kernel-level eBPF telemetry on endpoints, servers and containers. It extracts behavioural features, never raw file content.
  • Local anonymisation at source: salt-based hashing and tokenisation of file names, paths, user identities and network destinations.
  • Autonomous detection with UEBA and behavioural baselines, MITRE ATT&CK mapped, running inside the sovereign boundary. Offline mode supported.
  • No automatic remediation. High-impact response, evidence reveal and de-anonymisation route through human authorisation.
  • Encrypted at rest and in transit with UK / EU-managed HSM keys. Immutable audit log.

At a glance

eBPF
Kernel-level, near-zero overhead
At source
Anonymised before any export
Offline
No external telemetry dependency
NCSC
Aligned by design
Engine 04

TOPAS Engine

Token, Optimisation, Policy, Auditability and Security. Buyers: CFO, Head of AI and platform owner.

The TOPAS Engine is the token-control, routing and payload-efficiency layer of HEX 165. It is designed to address the emerging challenge of AI cost overspend: large-context models make agentic AI more capable, but every additional token increases cost, latency, cache pressure and governance exposure.

TOPAS governs the token stream before it reaches the model. It measures cost per completed task, routes requests to the lowest-cost compliant model path, optimises context layout, reduces repeated or structured payloads through GOT (Group of Tokens), and preserves accuracy through restore and validation controls.

It does not just report AI spend after the fact. It actively controls inference cost, token flow, payload efficiency, residency and value realisation, with every optimisation decision written to the immutable audit log.

  • Real-time token cost telemetry and chargeback per agent, workflow, business unit and tenant.
  • Sovereignty-aware routing: residency constraints enforced as priority, followed by policy, accuracy, SLA and cost optimisation. Sovereign-flagged requests are region-bound and never leave the boundary.
  • Reversible payload compression for structured data such as logs, JSON tool outputs, database results and file trees.
  • An accuracy harness gates every optimisation against a full-context reference, so savings are never reported where output fails quality checks.
  • An ROI view compares the cost of an AI task against the equivalent human effort, with the result written to the audit log.

Explore the TOPAS Engine

At a glance

100%
Of model calls priced before and after
20–40%
Cache-aligned saving on repeated workflows*
50–80%
Token reduction on suitable structured payloads*
100%
Sovereign-tagged requests kept in boundary

* Target savings, based on internal benchmarks where provider caching or suitable structured payloads apply. Actual figures vary by workload.

See HEX 165 in action

Book a 45-minute discovery session. We map one regulated workflow against the engines you need.

Book a Demo