Resources
Plain answers for the people evaluating AI governance.
What buyers ask us most, a checklist you can use with any vendor including us, and a short glossary.
Questions
What buyers ask first.
What is an Enterprise AI Control Plane?
The layer where an organisation discovers its AI, decides what is allowed, enforces that decision on the traffic it can see and proves what it decided. The term describes a function, not a hosted service. MERIDVAR runs where you run it.
How is this different from an AI governance platform?
Most governance platforms record programme workflow from declared inventories. MERIDVAR ties the governance record to observed traffic and to a gateway that can refuse a request, in one appliance the customer operates.
How is this different from an AI security platform or an SSE?
Those products usually inspect content in the vendor cloud and cover a broader threat surface. MERIDVAR is focused on admission control. It inspects on your network, adds no data processor to the path and includes the governance record.
Does MERIDVAR make us compliant with the EU AI Act?
No. No software does. MERIDVAR helps you operationalise controls and produce evidence relevant to the EU AI Act, NIST AI RMF and ISO/IEC 42001. Whether you are compliant is a determination for you and your counsel.
What does MERIDVAR see of our prompts?
Nothing. There is no MERIDVAR cloud and no telemetry. Prompt content is inspected on your appliance, and stored findings keep masked samples only.
Which AI traffic does it control?
Traffic routed through the gateway: by the OpenAI compatible endpoint, the console playground or the proxy path. Other traffic can be made visible through uploaded proxy or DNS logs, endpoint agents and declarations, but is not controlled.
How does it handle AI agents and MCP servers?
Agents are registered with signed identities. MCP servers and their tools are declared and risk rated. Both are assessed with a shipped questionnaire and governed through the AI systems that use them. Approval is recorded at the level of the AI system.
What do we need to run it?
A host on a private network that runs Docker. One appliance serves one organisation. Once installed it runs without internet access, including licensing and signed updates.
How does MERIDVAR approach assurance and identity?
The console uses role based access enforced on the server, and OIDC from your identity provider can be required at the gateway. An internal red team reviews every release. Independent assurance, including a penetration test and SOC 2 readiness, is on the roadmap. Current security documentation is available on request.
Evaluation checklist
Ten questions to ask any AI governance or AI security vendor.
Ask us too.
Data and deployment
- Where is prompt content inspected, and who operates that infrastructure?
- Does the product add a data processor to our AI data path?
- What does the vendor receive by telemetry, by default?
- Does it keep working without internet access?
- Is raw sensitive data ever stored in findings or logs?
Governance and evidence
- Is a risk rating explainable, factor by factor, and repeatable?
- How is "unknown" treated in an assessment?
- Can the person who requests an approval also grant it?
- What happens to an approval when the underlying facts change?
- What exactly does the audit evidence establish, and who can verify it?
Glossary
Terms used on this site.
- Admission gateway
- A control point that decides whether an AI request may proceed before any model provider is contacted.
- Shadow AI
- AI services in use that the organisation has not sanctioned, often unknown to IT and security.
- MCP server
- A Model Context Protocol server. It exposes tools and data from enterprise systems to AI models and agents.
- Prompt DLP
- Data loss prevention applied to the content of an AI request: the prompt, system messages, tool arguments and tool results.
- Pinned basis
- The exact classification, reviews, vendor approval and inventory snapshot an approval was requested on.
- Evidence log
- An append only record in which each entry carries the hash of the one before, so that an edit is detectable.
- Audit package
- A downloadable file with every governance record and evidence entry about one AI system or vendor.
- Live dispatch
- The switch that lets admitted requests actually call the model provider. With it off, policy can be tested at no cost.
See MERIDVAR refuse a request on your own network.
A working session with the founder. We install the appliance with you, route a test request and walk through the evidence it leaves behind.