AI powerful enough to act.
Governed enough to trust.
Every AI capability we ship is grounded in your knowledge, bounded by your policies, overseen by your people, and logged for your auditors. That is the standard across everything Troopr Labs builds.
No training on customer data
Guardrails on every interactio
Human oversight of actions
Full audit logs
Trusted by startups and established enterprises


What governable AI means here
Agentic AI is valuable because it can reason and act. It is only enterprise-ready when four things hold.
1
Grounded, with receipts
AI responses are grounded in your organization's approved knowledge through retrieval-augmented generation, with responses traceable to their knowledge source. Not the open internet, not the model's memory.
2
Bounded by policy, always
Policy guardrails on inputs and outputs enforce your boundaries on every interaction: content filters, denied topics, and denied words or patterns. An admin-set baseline that per-agent rules can tighten but never weaken.
2
Overseen by people
AI acts within approved scope and defined permissions. Actions in connected systems run through approval workflows, and low-confidence cases escalate to humans with full context. Human oversight is built into the operating model, not bolted on.
2
Auditable end to end
Full audit logging of high-severity events with search, filter, and CSV export. Guardrail changes are testable before rollout. Enterprise AI requires proof, not promises.
No training on your data. Contractually enforced.
Never used for training
Customer data is never used to train, fine-tune, or improve any model. Your prompts and content serve your team and no one else.
API-only access to providers
Data sent to LLM providers goes via API only, never through consumer products. Providers do not retain prompts or responses beyond the time needed to generate a response, under DPAs prohibiting use for training.
Your model, your keys
Model provider selection and bring-your-own-key are supported where available, so AI runs on the providers your policies approve.
Minimized before it moves
Automatic PII detection and masking can redact sensitive data before it reaches any model. Content filtering, masking, and data minimization apply throughout.
Logged on your terms
AI interaction logs have configurable retention, and interaction logging can be disabled entirely.
Published sub-processors
Our current AI sub-processors are published at trooprlabs.com/sub-processors, with 30-day advance notice before any change.
Every AI request, step by step
STEP 1
Request received
A user's query enters the platform and is processed per your configuration, including any PII redaction settings.
STEP 2
Context retrieved
Relevant chunks are retrieved from your knowledge index. Documents are stored as one-way vector embeddings that cannot be reversed.
STEP 3
Model called via API
Query and context are sent to the configured LLM provider under a no-training, no-retention DPA.
STEP 4
Guardrails applied
The response is checked against your content filters, denied topics, and denied patterns before anything reaches the user.
STEP 5
Delivered and logged
The response is delivered with traceability to its knowledge source, and logged per your retention configuration.
Your policies, enforced on every interaction
Guardrails are the control plane between AI and your users, applied to inputs and outputs.
What guardrails protect against
✕ Accidental exposure of confidential or regulated information
✕ Restricted topics or prohibited guidance reaching end users
✕ Harmful, offensive, or policy-violating content
✕ Malicious or unsafe interactions in prompts and responses
How they are structured
Workspace baseline. Set by admins and enforced everywhere. The non-negotiable floor.
Per-agent tightening. Stricter rules can be added for specific agents. Baseline rules always remain in force, with a revert-to-baseline option for safe resets.
What you can configure
✓ Content filters: block predefined categories in input and output
✓ Denied topics: restricted topics defined with descriptions and examples
✓ Denied words and patterns: exact terms or regex
Test before you ship
Every guardrail update can be tested immediately: see the original AI response, the final response after guardrails, and which rule triggered and why.
Built to the frameworks your reviewers use
NIST AI RMF
Our AI governance program is aligned with the NIST AI Risk Management Framework across its four functions. Govern: defined accountability, policy guardrails, and admin-controlled baselines. Map: AI capabilities scoped to defined tasks with documented data flows. Measure: guardrail testing, resolution and coverage analytics, and interaction logging. Manage: human oversight, escalation paths, incident response, and continuous review.
EU AI Act
Our AI systems, controls, and documentation are built to meet the EU AI Act's requirements as they apply to our services, including transparency for AI systems that interact with people, human oversight, logging, and technical documentation, and to support our customers' obligations as deployers.
ISO/IEC 42001
ISO 42001 certification is on our compliance roadmap, extending our ISO 27001 certified management system to AI management. Our SOC 2 Type II and ISO 27001 posture already covers the infrastructure every AI feature runs on. See Security and Compliance.
The questions AI governance teams ask
No. Customer data is never used to train, fine-tune, or improve any model, and every LLM provider we use is under a DPA prohibiting it.
Our current AI sub-processors are published at trooprlabs.com/sub-processors, with 30-day advance notice before any change. Provider selection and bring-your-own-key are supported where available.
No. Access is API-only, and providers do not retain prompts or responses beyond the time necessary to process each request.
Yes. An admin-set workspace baseline applies to all agents, and per-agent rules can tighten but never weaken it.
Yes. Built-in testing shows the original response, the post-guardrail response, and which rule triggered.
AI operates within approved scope and the permissions of connected systems. Actions run through approval workflows and safeguards, and low-confidence cases escalate to a human with full context.
Audit logs cover high-severity events including agent and policy changes, with search, filter, and CSV export.
Yes. Retention is configurable and logging can be disabled entirely.
Where enabled, automatic PII detection and masking redacts sensitive data before it is sent to any provider. Redaction operates on a best-efforts basis, as no automated system guarantees complete removal.
We provide the transparency, human oversight, logging, and technical documentation deployers need, and our systems are built to meet the Act's requirements as they apply to our services. Contact security@trooprlabs.com for documentation.
Security & AI governance,
trusted by top enterprises
- SOC 2 Type II + ISO 27001 compliant; GDPR compliant
- TLS 1.2+ in transit, AES-256 at rest, keys via AWS KMS
- AI Guardrails for inputs/outputs + full audit logs
- Regular scans + pen tests (NDA), tested backups + IR plan
- 99.9% uptime for 6 years, proven at enterprise scale
