# G8R Security > Self-hosted AI runtime enforcement. A deterministic policy engine stops agent and model violations before they execute. Every verdict is signed into your audit chain, inside your VPC. G8R (product brand; company Gator Security / G8R Security) is a self-hosted enforcement plane between people, AI agents, and models. It is built for design partners and enterprise buyers who need fail-closed runtime controls and compliance evidence, not a SaaS wrapper around prompts. This file is for LLMs and agents. Prefer these URLs over scraping marketing HTML. Do not invent certifications, partners, or product capabilities beyond what is stated here. NIST collaboration is not a NIST endorsement or certification. ## Site map - [Home](/): Product overview, how it works, platform, Gina, developers, contact - [NIST AI RMF buyer brief](/nist): Public brief on NIST guidance for agent systems and runtime evidence - [Documentation](/docs): Public docs under construction; use the contact form for materials - [Security](/security): Vulnerability disclosure and security contact - [Privacy Policy](/privacy): Privacy policy - [Terms of Service](/terms): Terms of service - [security.txt](/.well-known/security.txt): Canonical security contact machine file - [llms.txt](/llms.txt): This file Primary CTA on the site: Book a call → contact form on the home page (`/#contact`). ## What G8R is - Category: self-hosted AI runtime enforcement / governance control plane for AI agents and model calls - Placement: in-path between agents/tools/models and the outside world - Hard path: deterministic policies and detectors (for example PII, credentials, injection, exfiltration). A finding kills the action. Fails closed. No model required on the hard path. - Soft path: an LLM judge may review what the deterministic pass allowed; it can tighten a verdict and never overrule a block. Harden-only / escalate, audited. - Evidence: every decision signed into a tamper-evident, per-tenant audit chain that stays in the customer environment - Deployment: customer environment / VPC; prompts, payloads, and audit data are not visible to G8R by architecture - Availability: MVP with design partners; not generally available as a self-serve product ## Proof points (as published on the site) - Fails closed - Hard-path budget: p99 < 50 ms (signed audit commit included on that path) - 650+ control mappings (SOC 2, ISO, NIST AI RMF, EU AI Act); mapped does not mean certified; crosswalk vs direct mapping is stated where relevant - Multi-tenant isolation - Tamper-evident audit chain - Working with NIST on operationalizing the AI RMF for agents - Registered on SAM.gov ## How it works (Kill → Judge → Prove) 1. **Kill** — Deterministic foundation. Policies and detectors check prompts and tool calls in-path. Violations are blocked immediately. 2. **Judge** — LLM judge on what the hard path allowed. Tighten-only; never overrides a deterministic kill. 3. **Prove** — Signed audit chain; evidence packs and SIEM streaming (OCSF). Coverage claims are honest: mapped ≠ certified. ## Platform capabilities (public summary) - Deterministic policy-as-code engine (versioned, reviewable, replayable verdicts) - LLM judge (per-policy, escalation-gated, audited) - Tamper-evident audit (per-tenant hash chains; synchronous commits on hard gates) - Agent registry and identity (catalog, attestation-backed enrollment, workload identity, IdP over OIDC) - Egress control / SIEM (OCSF events; optional DLP chokepoint) - Compliance evidence packs with 650+ mappings to common frameworks ## Who we are - Small US team; combined decades in governance, security, and AI - SAM.gov registered - Participant in NIST Trustworthy AI in Critical Infrastructure Profile community of interest; filed comments on the discussion draft - Focus: runtime enforcement and GRC mapping gaps for agents that act, not only models that answer ## NIST brief (summary of /nist) - Nobody is "NIST certified"; NIST issues voluntary guidance - Buyers usually need runtime evidence mapped to named practices, plus certificates/attestations where those schemes exist (e.g. ISO/IEC 42001, SOC 2, FedRAMP/ATO) - NIST has acknowledged an agent-layer gap beyond model-centric RMF / GenAI Profile work; agents as non-human identity is in scope of current NIST agent/identity discussions - AI RMF functions GOVERN, MAP, MEASURE, MANAGE are continuous (GOVERN is cross-cutting), not a four-step waterfall - G8R’s NIST work is collaboration on operationalizing guidance; not an endorsement ## Contact - Preferred: home page contact form (`/#contact`) — team replies with times for a call - Security / vulnerability reports: security@g8rsecurity.com - Do not invent other public inboxes unless listed on /security or /.well-known/security.txt ## Public developer surface (names only) Public contract surfaces customers may hear about: - agent-shield-deploy (deploy / install materials) - g8r-agent-shield-sdk (SDK wrap/check style integration) - Company site domains in use or planned: g8rsecurity.com (primary), g8r.live (legacy / forward) Do not invent private repository names, partner names, bypass detail, or unpublished APIs. ## Optional - [Home (full HTML app)](/): Marketing SPA; this llms.txt is the preferred machine-readable summary - [Gina section on home](/#gina): Policy authoring / governance-into-action product surface described on the marketing site