The operating platform for agentic AI. Four deterministic engines, one hash-chained audit log.
HEX 165 governs the AI execution layer through four integrated engines: Governance, Compliance, STPM and TOPAS. Together, they enforce policy, assess regulatory alignment, monitor runtime behaviour, control token flow, optimise inference cost and record every material event to a hash-chained audit log.
Every agent call is governed, scanned, monitored, priced and evidenced by design.
Enterprise control plane for governed agentic AI. Buyers: CISO, General Counsel, CFO and Head of AI.
The Governance Engine is the day-to-day control plane for agentic AI in regulated environments. It turns organisational policy into enforceable runtime controls, authored as code, versioned in source control and applied to every agent call.
It governs who or what is acting, what data is in scope, which model can be used, what budget applies, when human approval is required and what evidence must be retained.
Where the Compliance Engine verifies what the regulator expects, the Governance Engine controls what the organisation actually allows AI to do.
Multi-framework compliance assessment for agentic AI systems. Buyers: Chief Compliance Officer, Data Protection Officer, AI ethics committee and internal audit.
The Compliance Engine is a read-only scanner and deterministic rules engine for regulated AI estates. It maps agent code, architecture and documentation against all supported compliance frameworks (including the EU AI Act, DORA, GDPR and NIST AI RMF) in a single assessment.
It identifies regulatory gaps, cross-framework obligations and architecture-level risks unique to agentic systems, then traces every finding back to the relevant framework, article, control or evidence requirement.
No machine learning interprets the rules. No probabilistic reasoning determines compliance. The engine is deterministic, repeatable and auditable line by line.
We have now built these frameworks into the engine. The Compliance Engine covers 16 frameworks across UK, EU, US and international standards, evaluated together in a single scan.
Sovereign Threat Protection and Monitoring for sensitive AI and data environments. Buyers: Head of SecOps, CISO and regulated operations teams.
The STPM Engine provides privacy-preserving runtime security for UK / EU-controlled environments. It is designed for workloads where conventional telemetry can itself become a source of exposure, revealing sensitive file names, folder paths, command arguments, user identities, network destinations or the subject matter of an investigation.
STPM detects abnormal runtime behaviour close to source, minimises and anonymises sensitive context before telemetry leaves the monitored asset, and routes high-impact response or evidence reveal through human-authorised controls.
The engine supports open standards including OpenTelemetry / OTLP, OCSF, Sigma, OPA / Rego, SPIFFE / SPIRE and mTLS, enabling interoperability without compromising the sovereign operating region.
The result is runtime protection without turning monitoring data into a second data leak.
Token, Optimisation, Policy, Auditability and Security. Buyers: CFO, Head of AI and platform owner.
The TOPAS Engine is the token-control, routing and payload-efficiency layer of HEX 165. It is designed to address the emerging challenge of AI cost overspend: large-context models make agentic AI more capable, but every additional token increases cost, latency, cache pressure and governance exposure.
TOPAS governs the token stream before it reaches the model. It measures cost per completed task, routes requests to the lowest-cost compliant model path, optimises context layout, reduces repeated or structured payloads through GOT (Group of Tokens), and preserves accuracy through restore and validation controls.
It does not just report AI spend after the fact. It actively controls inference cost, token flow, payload efficiency, residency and value realisation, with every optimisation decision written to the immutable audit log.
* Target savings, based on internal benchmarks where provider caching or suitable structured payloads apply. Actual figures vary by workload.