Regulayer Enterprise licensing

SDKontrol · a Regulayer surface

The governance sits inside the vendor's product, so it answers to the vendor.

SDKontrol is the runtime engine, licensed as infrastructure. It runs any model, yours or a third party's, sealed and local inside the buyer's own environment, architected to make no outbound call, and it signs a record for every decision. The model travels. The data stays.

The wall

For two decades the answer in regulated markets was the same. The vendor could not promise the data would not leave, so the buyer said no. Banking, pharma, defense, healthcare, legal, semiconductor. The dealbreaker was always the outbound call.

SDKontrol removes it. The vendor ships its model sealed inside the customer's environment, runs every inference through the gate, and produces a signed record for every decision. The customer gets the evidence. The vendor gets the customer it could not reach before.

The buyer of SDKontrol is the vendor. What the vendor buys is the customers it could not reach. Validation, procurement and model-risk review still apply; this removes the egress objection, not the others, and it is honest about that.

The same wall, in five markets

Pharma and biotech

21 CFR Part 11, EU GMP Annex 11. The model runs inside the validated system, and signed records feed the audit trail Annex 11 already requires.

Defense and federal

Programs whose policies forbid any outbound path. Model and inference stay inside the boundary, and the security officer verifies records offline.

Financial services

SEC and FINRA supervision, data residency, bank secrecy. No signal, no position, no client identifier crosses the wire.

Healthcare

HIPAA audit controls over ePHI. The chart never leaves the estate; the record of what the system did is still provable.

Legal

Privileged work product stays inside the boundary, so there is no third-party custody for a court to read into a waiver.

What the licence carries

The kernel and the gate

Governance outside the governed model, integrated into your stack without moving the trust boundary. After integration the control layer continues to answer to the customer, not to you, and not to us.

The record format and the open verifier

Every decision signed into the versioned record format, verifiable by anyone holding the file, permanently, with nothing from us. Older records never stop verifying; newer records are never rejected by older verifiers.

Readable source

The source ships readable, so the customer's security function can satisfy itself line by line. Reading is granted under licence; redistribution and derivative works are not.

Deployment

It runs on your machines, and nothing of the work leaves the building.

The kernel binds the loopback interface and refuses any client that is not local. The signing key is generated on your own machine on first run and never leaves it. In the default mode there is no outbound call of any kind. Where independent time is required, a single cryptographic digest goes to a public timestamp authority, never the file and never its contents. The source ships readable, so your own security function can satisfy itself line by line.

Every answer your security function will ask for, on one page you can forward

The estate

Part of the filed estate: eighteen patent filings and a PCT. Patent pending across the estate.

Licensing begins with the problem, not the product.

Describe the system, what it decides, and what it would cost you to be unable to prove it. A written scope follows before any call.

Ways to begin:

hello@regulayer.com