ZeroTrace™ · Sovereign AI Gateway · Coming soon

Use any AI. Keep your IP and your Data, your privacy.

ZeroTrace™ is an AI gateway that lives inside your own perimeter. It reads every request before it can leave the building: open questions go out to the frontier models your teams already love — customer records, contracts and case files stay home, answered by MeaningMemory™, your own in-house AI. Every decision is written to a tamper-evident audit ledger — evidence you can hand an auditor.

AI adoption is not your risk. Uncontrolled AI adoption is.

The EU AI Act puts a price on getting this wrong — up to €35M or 7% of global turnover at the top of the scale, with GDPR already on the clock. The controlled path is by far the cheaper one.

Observing traffic...

Your teams already use AI

Claims files, contracts, source code and board papers are being pasted into public chatbots right now — helpful for the employee, invisible to you. Every paste is an uncontrolled export of your intellectual property to someone else’s server, under someone else’s law.

Tracing egress...

A prompt is a data transfer

The moment a customer record enters a prompt, GDPR applies: special-category rules for health and legal data, cross-border transfer restrictions, and the duty to know exactly where it went. There is no recall button on a prompt.

Reading the register...

The clock was paused — not stopped

Europe deferred the AI Act’s high-risk duties to December 2027 — deferred, not cancelled. Transparency duties already apply, GDPR was never paused, and penalties under the Act reach 7% of global turnover for the most serious violations. The companies that treat the extra time as build time will meet the deadline calmly.

Evaluating options...

Prohibition is not a policy

Banning AI hands productivity to your competitors and pushes usage into the shadows where you cannot see it. The winning move is a controlled path: one gate everyone uses — because it is also the easiest way to use AI.

How it works · Fig. 1

The gate.

One appliance between your people and every AI. Four things happen to every request — inside your building, in milliseconds.

YOUR PERIMETER (100) USERS & APPS (102) ZEROTRACE™ GATE (104) CLASSIFY · REDACT POLICY RESOLVER (110) FAIL-CLOSED EGRESS VALVE (116) OPEN · REDACTED FRONTIER & EU CLOUDS (122) OPEN DATA ONLY MEANINGMEMORY™ (118) SENSITIVE DATA STAYS HERE PERSONAL · SPECIAL · PRIVILEGED · SECRET AUDIT LEDGER (120) — HASH-CHAINED · CONTENT-FREE #a1 #f4 #0e #7c
FIG. 1 — Every request is classified and routed inside your perimeter. Only permitted, redacted traffic passes the egress valve (116); sensitive classes terminate on MeaningMemory™ (118). Every decision — never any content — is appended to the hash-chained ledger (120).

01 — CLASSIFY

Every request is read at home

Deterministic detectors inspect each request inside your perimeter: national identifiers across Germany, the UK, Spain and Greece (check-digit verified), health and legal context in four languages, payment data, keys and secrets. No cloud pre-scan — the classifier never leaves your building.

02 — ROUTE

Policy decides where data may go

Open questions may use frontier or EU clouds. Anything personal, medical, privileged or secret is only ever admissible to sovereign lanes. Errors fail closed — a fault can narrow where data goes, never widen it.

03 — REDACT

What leaves is scrubbed first

Where policy allows cloud egress, detected values are redacted from the message before a single byte departs. The cloud sees the question — not the identity, the diagnosis or the account number behind it.

04 — PROVE

Every decision leaves evidence

Class, lane, model and content digests are appended to a hash-chained, tamper-evident audit ledger. Never the content itself — evidence for your auditors without building a honeypot for your attackers.

Regulation · EU AI Act · GDPR

The EU AI Act, in business terms.

The AI Act regulates AI the way Europe regulates products: by risk. Most obligations fall on “deployers” — companies that use AI, not just those who build it. In July 2026 the Digital Omnibus on AI deferred the high-risk deadlines. Deferred — not cancelled. And the quiet part: GDPR was never deferred. It applies to every prompt your staff sent this morning.

1 Aug 2024

The AI Act enters into force

Regulation (EU) 2024/1689 — the world’s first comprehensive AI law.

2 Feb 2025

Prohibitions & AI literacy apply

Banned practices (social scoring, manipulative systems) and staff AI-literacy duties take effect.

2 Aug 2025

General-purpose AI rules apply

Obligations for GPAI model providers, governance structures and the penalty framework activate.

27 Jul 2026

Digital Omnibus on AI in force — deadlines deferred

High-risk compliance dates are pushed back to give standards and authorities time to catch up. The core high-risk obligations are preserved — alongside targeted amendments elsewhere in the Act.

2 Aug 2026 — you are here

Transparency obligations apply

People must be told when they interact with AI — law today (Art. 50). Machine-readable marking of AI content applies to newly placed systems now; systems already on the market have until 2 Dec 2026.

2 Dec 2027

High-risk obligations apply (Annex III)

Risk pricing in life & health insurance, credit scoring, employment screening, essential services — logging, oversight, data governance and impact assessments become enforceable.

2 Aug 2028

High-risk rules reach regulated products (Annex I)

AI embedded in machinery, medical devices and other regulated products follows.

What you will have to evidence — and what ZeroTrace™ hands you.

Art. 12 · 19 · 26

Logging & record-keeping

High-risk systems must log automatically; deployers must retain those logs — at least six months.

A hash-chained, content-free audit ledger with external anchoring — records that can prove they haven’t been edited, retained on your own hardware for as long as you choose.

Art. 26

Human oversight & use control

Deployers must use high-risk AI under defined controls, with oversight assigned to competent people.

Policy lanes with stricter-only overrides. Your administrators set who may reach which models with which classes of data — and faults fail closed, never open.

Art. 10 · GDPR Art. 9

Data governance & special categories

Health, legal and other special-category data demand explicit safeguards — under GDPR, today.

Deterministic detection before any byte leaves — national IDs, health context, legal privilege, secrets — with redaction on every cloud-bound lane.

Art. 27

Fundamental-rights impact assessment

Banks and insurers using Annex III systems are among the first required to assess impact on fundamental rights.

Per-request decision records give the assessment its evidence base: which data classes appeared, where they were allowed to go, and what actually happened.

Art. 50 — applies now

Transparency

People must know when AI is in the loop; AI content must be identifiable — marking phases in fully by 2 Dec 2026 for systems already on the market.

Provenance on every response — which model answered, under which policy, in which lane — machine-readable, ready to surface to your users.

35M€ / 7%

of global annual turnover, whichever is higher — the ceiling for prohibited-practice violations.

15M€ / 3%

of global annual turnover — the ceiling for most other violations, including high-risk duties.

ZeroTrace™ is compliance infrastructure, not legal advice. It gives you the technical controls and the evidence trail; your counsel maps them to your obligations under Regulation (EU) 2024/1689 as amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744), the GDPR and sector rules such as DORA.

Built for the industries where a leak is a headline.

Deployment model

The box is yours.

Every deployment is a ZeroTrace™ Node on your infrastructure — your building, your cloud tenancy, or fully air-gapped. We operate only a content-blind control plane for licensing and updates.

Sealing perimeter...

Nothing to hand over

Prompts, files and answers live only on your Node. There is no vendor copy of your data to request, breach or subpoena — because it never existed.

Checking uplink...

Content-blind by construction

The Node’s link to our cloud carries licenses, configuration and health counts — never prompts, never responses, never files. Air-gapped sites run with offline licensing.

Verifying license...

Never-brick licensing

If a license lapses, your gateway degrades gracefully — it never stops serving. Your access to your own AI is not a hostage in a billing conversation.

Opening lanes...

Use any AI — really

OpenAI-compatible in, best-model out: frontier clouds, EU providers and your in-house MeaningMemory™ behind one endpoint. Adopt new models the day they ship — policy, not habit, decides where data goes.

Position

Sovereignty is not where your data is stored. It is where your data is allowed to go.

Coming soon.

We are onboarding a small number of design partners ahead of general availability. If your industry is on this page, we should talk.