Enterprise AI Control Plane

Govern every AI system. Refuse the requests you should. Prove both.

MERIDVAR discovers the AI in use across your organisation, records how each system and vendor was assessed and approved, stops the requests your policy rejects before a model is called, and keeps the evidence. It runs on your infrastructure, and nothing is sent to us.

Deployment
Self-hosted appliance
Tenancy
Single tenant
Telemetry
None
Connectivity
Runs without internet access

The problem

AI use has outrun AI governance

Employees use consumer AI. Developers wire in model APIs. Business units buy AI inside SaaS products. Agents act through MCP servers. Each decision was local, but the exposure is not.

AI in use
There is no single inventory of the systems, agents and vendors in use.
Risk
There is no shared view of the data involved, the autonomy granted or the decisions made about people.
Data flows
A prompt is an authorised request to an authorised service, with the data in the body.
Spend
Consumption is spread across teams, keys and providers.
Accountability
Nobody can show who approved what, on what basis and until when.
13%of organisations reported a breach of AI models or applications.
97%of those organisations lacked proper AI access controls.
USD 670,000was added to the average cost of a breach where shadow AI use was high.

Source: IBM, Cost of a Data Breach Report 2025.

Why now

Three trends are converging on the same gap

AI adoption is decentralised

AI arrives through employees, SaaS features, developer keys and vendor contracts, all at the same time. No single team sees all of it.

AI systems are becoming autonomous

Agents call tools, and MCP servers expose enterprise systems to models. A tool that can delete, pay or send data outside the organisation is a new kind of privileged access.

Accountability now has a schedule

EU AI Act transparency obligations have applied since 2 August 2026. Boards, auditors and regulators are asking the same question: how is AI governed here?

Walkthrough

From an unknown AI system to an auditable decision

Follow one system through the appliance as it is found, given an owner, classified, reviewed, approved, controlled and evidenced.

MERIDVAR consoleIllustrative

AI inventory

Systems that this appliance observed in traffic or that a person declared.

Support reply assistantObserved in gateway trafficCandidate
Contract summariserDeclared by an operatorDeclared
Unsanctioned chat serviceFound in an uploaded proxy logCandidate
Legacy translation botDeclared by an operatorRetired

An observation never becomes a declaration on its own. A person confirms it. An empty inventory means that nothing was recorded, not that no AI is in use.

Illustrative interface with invented example data. It shows behaviour documented for the current release and is not a screenshot of a customer environment.

Who it is for

One control plane for every team that answers for AI

TeamWhat they needWhat MERIDVAR gives them
Security
CISO
Know what AI exists and what it is doing, and control the risk.
  • Shadow AI discovered against your list of sanctioned providers
  • Prompt DLP, threat detection and data residency enforced before the call
  • Agents and MCP servers registered, reviewed and risk-rated
AI Security
IT
CIO and CTO
Enable enterprise AI without losing control.
  • An OpenAI-compatible endpoint that your teams and SDKs already use
  • Approved model lists, with four providers supported for live dispatch
  • A defined route to approval: assess, review and approve, with conditions
Product
Finance
CFO and FinOps
Make AI financially accountable.
  • A ledger of governed requests, with tokens, model and actual cost
  • Spend by team and by model over time
  • Team budgets with hard or soft caps, enforced at admission
AI FinOps
Privacy and compliance
DPO, compliance and legal
Turn AI governance into auditable evidence.
  • Every decision recorded with who made it, when and on what basis
  • Approvals that read “review required” when the facts change
  • An audit package for each AI system and each vendor
AI Governance

Why MERIDVAR

The decision, the gate and the evidence, in one place that you operate

MERIDVAR is focused where a GRC suite or a security platform is broad. What sets it apart is its architecture.

No vendor cloud
There is no MERIDVAR control plane in our cloud and no telemetry. Prompt content is inspected, and evidence is kept, on your own infrastructure. No new data processor enters the path.
Governance tied to a gate that can refuse
The record of what was approved and the gateway that admits or refuses requests live in the same appliance and write to the same evidence log.
Decisions that visibly go stale
An approval keeps the basis on which it was granted. When an answer, a vendor decision or a classification changes, the approval reads “review required”, with the reasons.
Customer-controlled by design
Self-hosted, single-tenant and able to run offline, with signed licences and signed updates verified on the appliance. See the deployment model

How MERIDVAR relates to the categories you already know

CategoryWhat it does wellWhere MERIDVAR sits
AI governance platformsProgramme workflow, policy content and model riskGovernance tied to observed traffic and to a gate that can refuse, operated by the customer
AI security platformsBroad AI threat coverage, from models to agentsFocused on admission control, with no vendor in the data path and the governance record included
SSE, CASB and SASEInline access control at network scaleComplementary: AI-specific governance, evaluated on your network
DSPM and data securityFinding and protecting data at restComplementary: governs decisions about AI systems and the prompt itself, before the call
LLM gateways and AI FinOps toolsRouting, caching and developer adoptionSpend by team and by model, recorded beside the security and governance decision
GRC platformsEnterprise-wide risk and control librariesThe AI-specific record that a GRC programme can draw on

Where a buyer is comfortable with cloud processing, an incumbent platform is often the right choice. MERIDVAR is built for the buyer who will not add a vendor’s cloud to the AI data path.

Architecture

The control plane runs where you run it

One appliance sits between your callers and your model providers. It runs five connected stages and keeps one record for every team.

MERIDVAR reference architectureCallers on the customer network reach AI providers through the MERIDVAR appliance, which runs five connected stages: discover, assess, approve, control and prove. Security, privacy, risk, finance and audit teams read one shared record. Nothing leaves the customer network for MERIDVAR.YOUR NETWORKOUTSIDE YOUR NETWORKPeopleA token for each personAI applicationsOpenAI-compatible APIAI agentsSigned identitiesMCP serversDeclared inventoryUnmanaged trafficPAC file and proxy captureMERIDVAR applianceOne organisation, one appliance, and no control plane in our cloud01DISCOVERInventory and shadow AI02ASSESSQuestionnaires and risk rules03APPROVEReviews and approvals04CONTROLAdmission gateway05PROVEEvidence log and audit packageModel providersAnthropic, OpenAI, Azure OpenAI, xAISelf-hosted modelsYour own endpointSaaS AI servicesSeen through uploaded logsADMITTED REQUESTS ONLYNO TELEMETRY TO MERIDVARRUNS WITHOUT INTERNET ACCESSONE SHARED RECORDSecurityPrivacyRisk and complianceFinanceAuditEvery team that answers for AI reads the same appliance: visibility, policy, control, evidence and spend.
Controls apply to traffic routed through the gateway. Visibility of other traffic depends on uploaded logs, endpoint agents and declarations.

Frameworks

Evidence that carries across frameworks

MERIDVAR helps organisations operationalise governance controls and generate evidence relevant to the frameworks they answer to. Whether an organisation is compliant remains its own determination.

See the mapping by territory

FrameworkIn the product today
EU AI ActControl mapping with computed status
NIST AI RMFControl mapping with computed status
ISO/IEC 42001Control mapping with computed status
GDPR, DORA, NIS2 and LGPDRelevant evidence, with no framework mapping

Assurance

Built for the buyer who reads the architecture first

Deployment
A single-tenant appliance on your infrastructure. One appliance serves one organisation.
Data handling
No raw identifier is stored. Findings keep masked samples. Provider keys are never returned to the browser.
Access control
Administrator, operator and viewer roles, checked on the server. The approver is never the requester.
Auditability
An append-only, hash-chained log. A record edited on disk reads as an evidence mismatch.

See the deployment model

For investors

Building the control layer for the AI economy

Every enterprise that adopts AI needs to know what it runs, decide what is allowed, enforce that decision and prove it. That is a new control layer, with several budget owners and a record that grows more valuable over time.

Investor overview

Request a demo

See MERIDVAR refuse a request on your own network

A working session with the founder. We install the appliance with you, route a test request through it and walk through the evidence it leaves behind.