Valdra/AI Governance

Governance that runs
at the moment of the call

Registries and risk classifications govern AI on paper. The Valdra AI Gateway governs it in practice. Route your applications' AI calls through Valdra and every request is checked against your policy before it reaches a model — blocking prompt-injection and jailbreak attempts, stopping secrets and personal data from leaking out, and recording every call for audit. Start in monitor mode to see exactly what would be blocked, then switch to enforce when you're ready — without changing a line of application code.

AI Governance
EU AI Act · ISO 42001 · NIST AI RMF · AIDA
4 AI systems governed
0
Prohibited
1
High-risk
2
Limited
1
Minimal
1 system needs a FRIA
Annex IV docs auto-generated
2 shadow-AI tools detected
Built for Canadian businesses
421+Entity Types
95%+F1 Accuracy
0 bytesData Retained
🍁Canadian Servers
PIPEDACertified
€35M

maximum EU AI Act fine — or 7% of global turnover, whichever is higher

1 EU AI Act, Article 99

Start Free Assessment
AI Systems Registry
EU AI Act · ISO 42001 tiers
4 systems
Resume Screener
Internal · GPT-4o
High-risk
Support Copilot
Intercom Fin
Limited
Churn Predictor
Internal · XGBoost
Minimal
Doc Summarizer
Claude
Limited

Every AI system, classified and tracked.

Register every AI system your organization builds or buys, then auto-classify each one against the EU AI Act, ISO 42001, and NIST AI RMF. Prohibited, high-risk, limited, or minimal — you always know your exposure and exactly what each tier requires.

Request a demo
EU AI Act Risk Classifier
Resume Screener · automated hiring
Classification
High-Risk
Annex III §4 — employment & worker management
Conformity assessment required
Human oversight mandated
Technical documentation (Annex IV)
Obligations Map2 of 5 met
Technical documentation (Annex IV)
Risk management system
Human oversight measures
Transparency notice to users
Post-market monitoring plan

Documentation that writes itself.

Annex IV technical files, model cards, and Fundamental Rights Impact Assessments generate from your system data — then flag for refresh the moment a model changes. The evidence regulators ask for, without the blank page.

Request a demo

Additional features

Request a demo

Monitor, Then Enforce

Adopt with zero risk. Monitor mode logs every request your policy would have blocked without touching a single call — so you prove the value before you enforce anything.

Prompt-Injection & Jailbreak Defense

Every prompt is inspected for injection, jailbreak, and instruction-override attempts — including the paraphrased and obfuscated ones — and blocked or flagged per your policy.

Data-Loss Prevention

Stop secrets, API keys, credentials, and your own confidential terms from ever leaving in an AI prompt — catching what personal-data redaction alone does not.

Automatic PII Redaction

Personal information is stripped from prompts before the model sees it and restored in the response, so your customers' data stays under your control.

Model Allow-Lists

Decide exactly which AI models your organization is permitted to use and block everything else at the gateway — the end of ungoverned model sprawl.

Runtime Usage Dashboard

See every governed AI call — volume, blocks, would-blocks, threats caught, data-loss events, and redactions — trended over time in one view.

Audit-Ready Export & Alerts

Export the full governance log for your auditors or SIEM, and get a real-time alert in Slack or Teams the moment the gateway blocks a call.

Policy Test Console

Paste any prompt and see exactly what the gateway would do under your current policy — before it ever hits production. Tune enforcement with instant, safe feedback.

Frequently asked questions

What is an AI gateway?

An AI gateway sits between your applications and the AI models they call and applies your governance policy to every request in real time. Instead of trusting each app to behave, you route AI calls through one governed checkpoint that can inspect prompts, block unsafe or non-compliant requests, redact personal data, and log everything for audit. Valdra's gateway does all of this without you changing your application code.

How is this different from an AI registry or risk classification?

A registry and risk classification govern AI on paper — they document the systems you have and the rules that apply. A gateway governs AI in practice — it enforces those rules on live traffic, at the moment each call is made. Valdra gives you both: design-time governance (registry, classification, documentation) and runtime governance (the gateway) in one platform.

Will turning it on break my application?

No. The gateway starts in monitor mode, which logs what your policy would have blocked but lets every request through unchanged — so you see the value with zero risk to production. When you're confident, you switch to enforce. You can test any prompt in the policy console beforehand to see exactly what would happen.

Does the gateway keep my data in Canada?

Yes. Personal information is redacted from prompts before they leave your governed path, every call is logged in your own Valdra tenant, and Canadian data stays in Canada. The whole point of the gateway is to keep sensitive data — secrets, credentials, personal information — from leaking into AI calls in the first place.

Get compliant and build trust

Join hundreds of Canadian organizations using Valdra to automate their privacy obligations — no consultants required.

Start Free — No credit card required

🍁 Canadian data residency · PIPEDA compliant · SOC 2 in progress

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.

AI Gateway — Runtime AI Governance & Guardrails | Valdra