AI powerful enough to act.
Governed enough to trust.

Every AI capability we ship is grounded in your knowledge, bounded by your policies, overseen by your people, and logged for your auditors. That is the standard across everything Troopr Labs builds.

No training on customer data

Guardrails on every interactio

Human oversight of actions

Full audit logs

Trusted by startups and established enterprises

What governable AI means here

Agentic AI is valuable because it can reason and act. It is only enterprise-ready when four things hold.

1

Grounded, with receipts

AI responses are grounded in your organization's approved knowledge through retrieval-augmented generation, with responses traceable to their knowledge source. Not the open internet, not the model's memory.

2

Bounded by policy, always

Policy guardrails on inputs and outputs enforce your boundaries on every interaction: content filters, denied topics, and denied words or patterns. An admin-set baseline that per-agent rules can tighten but never weaken.

2

Overseen by people

AI acts within approved scope and defined permissions. Actions in connected systems run through approval workflows, and low-confidence cases escalate to humans with full context. Human oversight is built into the operating model, not bolted on.

2

Auditable end to end

Full audit logging of high-severity events with search, filter, and CSV export. Guardrail changes are testable before rollout. Enterprise AI requires proof, not promises.

No training on your data. Contractually enforced.

Never used for training

Customer data is never used to train, fine-tune, or improve any model. Your prompts and content serve your team and no one else.

API-only access to providers

Data sent to LLM providers goes via API only, never through consumer products. Providers do not retain prompts or responses beyond the time needed to generate a response, under DPAs prohibiting use for training.

Your model, your keys

Model provider selection and bring-your-own-key are supported where available, so AI runs on the providers your policies approve.

Minimized before it moves

Automatic PII detection and masking can redact sensitive data before it reaches any model. Content filtering, masking, and data minimization apply throughout.

Logged on your terms

AI interaction logs have configurable retention, and interaction logging can be disabled entirely.

Published sub-processors

Our current AI sub-processors are published at trooprlabs.com/sub-processors, with 30-day advance notice before any change.

Every AI request, step by step

STEP 1

Request received

A user's query enters the platform and is processed per your configuration, including any PII redaction settings.

STEP 2

Context retrieved

Relevant chunks are retrieved from your knowledge index. Documents are stored as one-way vector embeddings that cannot be reversed.

STEP 3

Model called via API

Query and context are sent to the configured LLM provider under a no-training, no-retention DPA.

STEP 4

Guardrails applied

The response is checked against your content filters, denied topics, and denied patterns before anything reaches the user.

STEP 5

Delivered and logged

The response is delivered with traceability to its knowledge source, and logged per your retention configuration.

Your policies, enforced on every interaction

Guardrails are the control plane between AI and your users, applied to inputs and outputs.

What guardrails protect against

✕ Accidental exposure of confidential or regulated information

✕ Restricted topics or prohibited guidance reaching end users

✕ Harmful, offensive, or policy-violating content

✕ Malicious or unsafe interactions in prompts and responses

How they are structured

Workspace baseline. Set by admins and enforced everywhere. The non-negotiable floor.

Per-agent tightening. Stricter rules can be added for specific agents. Baseline rules always remain in force, with a revert-to-baseline option for safe resets.

What you can configure

Content filters: block predefined categories in input and output

Denied topics: restricted topics defined with descriptions and examples

Denied words and patterns: exact terms or regex

Test before you ship

Every guardrail update can be tested immediately: see the original AI response, the final response after guardrails, and which rule triggered and why.

Built to the frameworks your reviewers use

NIST AI RMF

Our AI governance program is aligned with the NIST AI Risk Management Framework across its four functions. Govern: defined accountability, policy guardrails, and admin-controlled baselines. Map: AI capabilities scoped to defined tasks with documented data flows. Measure: guardrail testing, resolution and coverage analytics, and interaction logging. Manage: human oversight, escalation paths, incident response, and continuous review.

EU AI Act

Our AI systems, controls, and documentation are built to meet the EU AI Act's requirements as they apply to our services, including transparency for AI systems that interact with people, human oversight, logging, and technical documentation, and to support our customers' obligations as deployers.

ISO/IEC 42001

ISO 42001 certification is on our compliance roadmap, extending our ISO 27001 certified management system to AI management. Our SOC 2 Type II and ISO 27001 posture already covers the infrastructure every AI feature runs on. See Security and Compliance.

The questions AI governance teams ask

Do you train models on our data?

No. Customer data is never used to train, fine-tune, or improve any model, and every LLM provider we use is under a DPA prohibiting it.

Which model providers do you use?

Our current AI sub-processors are published at trooprlabs.com/sub-processors, with 30-day advance notice before any change. Provider selection and bring-your-own-key are supported where available.

Do providers retain our prompts?

No. Access is API-only, and providers do not retain prompts or responses beyond the time necessary to process each request.

Can we enforce one AI policy across everything?

Yes. An admin-set workspace baseline applies to all agents, and per-agent rules can tighten but never weaken it.

Can we test safety policies before enabling them?

Yes. Built-in testing shows the original response, the post-guardrail response, and which rule triggered.

Can AI take actions on its own?

AI operates within approved scope and the permissions of connected systems. Actions run through approval workflows and safeguards, and low-confidence cases escalate to a human with full context.

How do we audit AI configuration changes?

Audit logs cover high-severity events including agent and policy changes, with search, filter, and CSV export.

Can we disable AI interaction logging?

Yes. Retention is configurable and logging can be disabled entirely.

Does PII reach the model?

Where enabled, automatic PII detection and masking redacts sensitive data before it is sent to any provider. Redaction operates on a best-efforts basis, as no automated system guarantees complete removal.

How does this support our EU AI Act obligations?

We provide the transparency, human oversight, logging, and technical documentation deployers need, and our systems are built to meet the Act's requirements as they apply to our services. Contact security@trooprlabs.com for documentation.

Security & AI governance,
trusted by top enterprises

  • SOC 2 Type II + ISO 27001 compliant; GDPR compliant
  • TLS 1.2+ in transit, AES-256 at rest, keys via AWS KMS
  • AI Guardrails for inputs/outputs + full audit logs
  • Regular scans + pen tests (NDA), tested backups + IR plan
  • 99.9% uptime for 6 years, proven at enterprise scale