AI governance
See and control every AI interaction, with signed evidence for ISO 42001 and the EU AI Act.
Joopler governs AI usage across four capture modes that all feed the same signed evidence ledger, so enforcement and evidence are one action.
The four capture modes
- Reverse-proxy gateway. Point your apps and agents at the Joopler gateway. It applies model policy, data-loss protection, prompt-injection detection, and output inspection, and records a signed event for each call.
- Inline egress proxy. A network-path proxy your devices and agent runtimes point at. See the egress quickstart.
- Log ingest. Bring in AI-traffic visibility from your secure web gateway or proxy logs for coverage without changing the path.
- Agent and tool-call logging. Capture agent and MCP tool calls so autonomous activity is inventoried and governed like any other AI usage.
Already run your own AI gateway or proxy? Keep it, and use Joopler as the policy and evidence layer on top. See Bring your own gateway.
What you get
- Shadow-AI discovery from your identity graph, so unsanctioned tools surface and can be sanctioned or blocked.
- A unified AI asset inventory across discovery, gateway usage, and connectors.
- EU AI Act risk tiers on every AI asset (prohibited, high, limited, minimal), suggested from how the tool is used, so your inventory doubles as an AI Act register.
- Data-loss protection on prompts, including secret and card detection.
- A verifiable no-training proof chain recorded in the signed ledger.
Every inspected interaction becomes a signed, timestamped, hash-chained evidence record, so your AI governance is provable, not asserted. This is also how Joopler produces the evidence for ISO/IEC 42001 and EU AI Act controls. See Frameworks.
Observe vs enforce
Seeing your AI usage - logging, shadow-AI discovery, the asset inventory - is
available on every plan. Actively enforcing on it (blocking on a secret, prompt
injection, or data classification, and redact-and-forward) is a Growth-plan feature.
Below Growth the gateway records everything but does not block, and the
ai-dlp-enforced control stays open with a prompt to upgrade.