Agentic AI, RAG and chat — with the control that lets you say yes
Assistants on the models you choose — including ones you host yourself — retrieval over your own documents, agents that do real work on your systems. All of it runs on your infrastructure, so what leaves is filtered and every decision is on record.
Request a confidential briefing
Your teams already want AI.
IronPact is how you give it to them.
IronPact runs the AI your teams need — chat on your choice of models, search over your own documents, agents that act on your systems, connectors to the tools you already use, and a builder so teams make their own. Because execution passes through the platform, control is built in rather than bolted on: CISOs, compliance leaders and IT teams get discovery, policy at the point of use, and evidence an auditor accepts. Vendor-neutral, inside your own infrastructure.
The window is dated. The EU AI Act's high-risk obligations apply from 2 December 2027, and vendor due diligence in a regulated institution takes 12–24 months — the selection window is open now. Non-compliance is priced into the law itself: up to €15M or 3% of worldwide turnover (AI Act Art. 99), and the fine lands on the institution deploying, not on the AI vendor. The regulator postponed enforcement because the tooling to operationalise compliance did not exist. We are the tooling.
Built for teams operating under DORA, NIS2, GDPR, and the EU AI Act — eight frameworks claimable today of twelve wired in, and frameworks are data, not code, so yours can be added. Where a certification is not in place, the product blocks the claim instead of making it.
What your institution gets
The whole thing
IronPact is governed AI enablement for regulated enterprises: agentic AI, retrieval and chat — the things your people could not have — with the control layer that lets them have it. The four below are one product. None of them is sold, or works, on its own.
Agents
Autonomous agents that do real work on your own systems — each with its own identity and a scope of authority you set and can revoke.
Assistants & retrieval
Chat on the models you choose, including ones you host yourself. Search over your confidential corpus, connectors into the tools your teams already use, and a builder so each team can assemble its own skills.
Security
What leaves for a model is filtered, redacted, tokenised or encrypted. Undeclared AI is discovered across browser, endpoint and network. Prompt injection is blocked, files and links are scanned, and access is granted per tool and per group.
Evidence
Allowed, blocked, or granted by exception: every decision leaves a tamper-evident record you can export for an auditor and map to the frameworks your supervisor uses.
All of it runs inside your own infrastructure, with no US cloud dependency. And the record proves what the organisation did, not what any named person typed — the evidence an auditor needs, without the employee monitoring a works council would refuse.
Stéphane Sara
Founder & Chief Architect
Built by regulated-enterprise operators, not AI enthusiasts
The product is built for teams that have to put AI in their people's hands and answer for it afterwards — the capability and the accountability coming from the same system.
- 31 years in regulated IT, cybersecurity, compliance, audit, and deployment.
- Operator experience across banking, enterprise IT, infrastructure, compliance, and secure deployment environments.
Request a confidential briefing
Request a private discussion about the AI you want to put in your people's hands — and what it takes to authorise it.