Skip to content
Regulayer™Human Control for AI
Book a live demo

13 of 14

SDKontrol

SDKontrol unlocks markets that cloud-dependent AI cannot enter.

The control boundary between vendor and customer
The control boundary between vendor and customer

What it does

That is the market SDKontrol unlocks: the buyer that said no because the data would have to leave.

The model travels. The data stays. The vendor ships its model sealed inside the customer's environment, and the control travels with it. No API. No phone-home. It keeps working with no signal.

The model is sealed where its source cannot be read. Every answer is checked before it returns. A signed record is made as it works. There is no path out. That combination is what SDKontrol ships, in one file.

The buyer of SDKontrol is the vendor. What the vendor buys is access to environments it could not previously serve. Validation, procurement and model-risk review still apply; this removes the egress objection, not the others.

What it covers

Pharma and biotech21 CFR Part 11, EU GMP Annex 11. The model runs inside the validated system, and signed records feed the audit trail Annex 11 already requires.
Defense and federalPrograms whose policies forbid any outbound path. The model and its answers stay inside the boundary, and the security officer verifies records offline.
Financial servicesSEC and FINRA supervision, data residency, bank secrecy. No signal, no position, no client identifier crosses the wire.
HealthcareHIPAA audit controls over ePHI. The chart never leaves the estate; the record of what the system did is still provable.
Where there is no signalA clinic in a region with intermittent connectivity. A field response after the network went down with the power.

In practice

Release a batch

A pharma company's batch-release AI cannot send its data to an external model service. With SDKontrol the model runs inside the validated system, sealed, and signed records feed the audit trail Annex 11 already requires. The data never leaves.

Why it matters

Intelligence does not require infrastructure. Some regulated, sovereign, on-premises, edge and connectivity-constrained environments cannot send sensitive data to an external model service. SDKontrol brings the model and its control into the customer-controlled environment instead.

Both problems at once

SDKontrol can open deployments that cloud-dependent architectures cannot support.

The control ordinarily sits inside the vendor’s product, so it answers to the vendor. SDKontrol removes both problems at once. The vendor ships its model sealed inside the customer’s environment, runs every inference through the gate, and writes a record for each decision, signed as it is written. The customer gets the evidence. This can make additional customer environments technically addressable.

Licensed as infrastructure

Governed intelligence inside the customer’s environment.

SDKontrol is the runtime engine, licensed as infrastructure. It runs any model, yours or a third party's, sealed and local inside the buyer's own environment, architected to make no outbound call, and it signs a record for every decision. The claim is structural, not a policy promise.

AI moves to where the data already is.

Enormous capability compressed into a sealed, portable file. The intelligence is portable. The infrastructure is the buyer’s.

What the license carries

  1. The kernel and the gate. Control outside the governed model, integrated into your stack without moving the trust boundary. After integration the control continues to answer to the customer, not to you, and not to us.
  2. Fails closed. Run it without a current license, or pry it open, and it fails closed. Sealing raises the cost of extracting the model, but it is not theft-proof against a host that fully controls its own hardware.
  3. Regulayer™ supplies the evidence. Your auditor, regulator or court makes the determination.

Where infrastructure is not the given

Governed AI does not have to depend on infrastructure the customer does not control.

The sealed deployment was built for the bank that would not let a model call home. The same property answers a larger question: what happens where the cloud is not a given at all.

A school system that cannot lawfully send a child's work to another country. A regulator in a jurisdiction with no domestic hyperscaler region. In each of them the ordinary answer is that governed AI is unavailable, because control was sold as a service that has to be reachable.

Regulayer™ runs where it is installed. That is the same engine the regulated buyer licenses, working in the place the cloud has not reached, and it is why the independence proposition is not a privacy footnote. Your authority does not have to live in somebody else's cloud.

Deployment

It runs on your machines, and enforcement and evidence signing require no network egress.

Regulayer™ operates within the customer-controlled environment. Ordinary enforcement and evidence signing do not require network egress, and the underlying work is not sent to Regulayer™. Where independent time evidence is used, the underlying content remains within the customer environment.

Control before consequence

Drift Control holds a consequential answer until current authority resolves it. FailStop holds a consequential action. SDKontrol carries the same control into a vendor’s own product.

See it in the films

Works with

All engines

Illustration. Sample actions.