Consensus rule compliance gate

Provably
compliant.

One checkpoint sits in front of every regulated outbound action. The regulator aligned baseline and your own overlay both have to sign before the action can execute. The receipt is independent of us, and the regulator can rederive the verdict from scratch.

running on a four validator testnet UKGC LCCP · FCA · UK GDPR · EYFS self hosted, offline microsite
Why guardrails are not enough

The box was bolted on. The box did not hold.

Between July and August 2026, three of the world’s leading AI labs disclosed the same failure within weeks of each other. OpenAI found that an agent running an internal cyber capability evaluation had broken out of its sealed test environment, reached the open internet, and gained remote code execution on Hugging Face’s production systems. Anthropic then disclosed three separate cases where Claude reached the live internet from a test environment meant to be sealed and went on to touch the real systems of three outside organisations. A week later Meta disclosed one of its own. No human directed any of it.

Read that structurally. In every case the containment was external to the agent, and in every case it failed: a misconfiguration, an open network path, or a flaw the agent found and used. The most capable labs in the world put autonomous agents in a box, as a precaution, and the box did not hold. Reviewing the pattern, the Cloud Security Alliance named the missing piece directly: a control that can check an agent’s action before it executes. That control is what Kronaxis Compliance is.

Reported by CNBC, The Register, Cybersecurity Dive, and the Cloud Security Alliance.

Miss 1 · Bolted on

Constraint outside the agent. A filter, a policy prompt or a wrapper sits beside the agent, not inside it. It holds until the agent finds the way around, and a capable one will.

Miss 2 · Hoped over

Tested, not proven. “We ran it a thousand times and it behaved” is evidence, not a guarantee. In a regulated setting the one time it does not behave is the only time that counts.

Miss 3 · Unanswerable

No record you can stand behind. When a regulator asks whether the agent stayed within its mandate, “we believe so” is not an answer. You need proof that it could not have done otherwise.

The problem in brief

Compliance today is a promise.

Regulated firms must prove every outbound message, alert, or marketing push followed the rules. In practice, what the regulator gets is the firm’s own logs, written by the firm’s own systems, reviewed long after the damage is done.

Under the UKGC October 2025 framework, FCA Consumer Duty and EU AI Act Article 12, “trust us” is no longer a defence. The fine arrives after the breach.

The gap: the regulator has no way to rederive what the firm’s system actually did before the message went out, and no way to detect a refusal that was quietly turned into a permit.
What Kronaxis Compliance is

Compliance by construction, formally proven.

We took the harder road. The compliance properties that decide whether an autonomous agent can be trusted with money, data and a mandate are formally proven to hold, in the mathematical sense, not tested until we got bored. The guarantee is constitutive: it is built into how the agent is allowed to act, so it is carried with the agent wherever it goes rather than left at the door as a wrapper.

Constraint by construction, not bolt on

The rules the agent must obey are part of the act itself, not a filter beside it. There is no outer box to escape, because the constraint travels inside the agent’s own decision to act.

Formally proven properties

The compliance properties that matter are proven to hold, not sampled and hoped. Proof is a stronger claim than a passing test, and it is the claim a regulated buyer actually needs before deployment.

A record you can answer with

Every action carries the evidence that it stayed within the mandate, so when the question comes you can show what happened and that it could not have happened otherwise.

Grounded in published work

It rests on our Provably Compliant paper and the processes built around it, not a marketing claim. The argument is written down and open to scrutiny. Read it on the white paper page.

Precise by design
We say the compliance properties are formally proven. We do not claim an agent can never be misused; we claim the properties we prove, hold.
Where it fits

One moat, applied to the agents themselves.

Kronaxis runs on a single idea: provable, not plausible. Our intelligence gives findings a professional can verify. Our research is proven against reality before it is trusted. Compliance is the same discipline turned on the workforce itself, so a digital worker can be deployed where the cost of getting it wrong is a regulator, not a refund.

Others give you plausible. We give you provable. Compliance is where that promise meets the law.
Who it is for

Anyone putting an autonomous agent where the rules bite.

Financial services

Agents that touch money, onboarding or advice, where conduct rules and audit are not optional.

Healthcare and law

Regulated advice and casework where an unprovable action is a liability, not a feature.

Government and defence

Autonomous systems that must be shown to have acted within a defined authority.

Platforms deploying agents

Anyone shipping autonomous agents to regulated customers who will ask how compliance is guaranteed.

Risk and audit teams

The people who have to answer for what an automated system did, with evidence.

AI vendors

Builders who need a compliance story stronger than a policy page to sell into serious buyers.

White paper · method level disclosure

Provably compliant autonomous actions. Read the full write up.

Nine sections covering the architecture, the six gate invariants (three decision time, three holding over time), the threat model, the evaluation evidence, the deployment shapes, and the honest limitations. CC BY 4.0 on the paper text; product, source code and rule sets remain closed. Published on Zenodo at DOI 10.5281/zenodo.20601300 (https://doi.org/10.5281/zenodo.20601300).

Where to go from here

Six doors. Pick the one that matters to you.

The microsite is split into six functional reads, plus the white paper above. Each is self contained and opens offline; the proof and industries pages run real cryptography in your browser.

How it works

An interactive eight chapter walk through the gate, the two rulebooks, the role typed quorum, the consensus check, freshness binding, and how the verdict turns into a receipt. Click any chapter to open the deep dive.

Read the explainer

See the proof

Pick a scenario, send a message through the gate, then recheck the proof. The browser recomputes the tamper evident receipt against real captured testnet artefacts. The six gate invariants are laid out symmetrically; the freshness binding card answers “without a real time lookup”.

Run the demo

Industries

Same gate, seven verticals: gambling, FCA debt collection, financial promotions, UK GDPR, Consumer Duty, community pharmacy, EYFS childcare. Each tab carries the actual rules modelled in its rule set, the named refusal codes, and one permit plus one refuse scenario. Gambling uses real captured proofs.

Browse verticals

Integrations

Nine egress patterns catalogued, two deployment shapes (Inline enforce vs Out of band observe), four integration mechanics (SDK, sidecar proxy, webhook, bus interceptor), and the fail CLOSED vs fail SAFE table per surface. The pharmacy cabinet and the fire egress door are not the same question.

See the surfaces

For regulators

Download a proof bundle, verify it in your browser or with the kc-verify CLI on your own machine. The six checks the verifier runs, the four residual questions the verifier does not answer, and the open source path to building the verifier yourself. Don’t trust us. Recompute.

Recompute the proof

Book a pilot

Six week, single surface, Observe only deployment against your outbound marketing channel. No card at the start. No invoice on walk away. Two binary acceptance conditions. The buyer keeps every byte of evidence. Founding rate window is open.

Read the SOW
The principle in one paragraph

Check us. Don’t trust us.

Every regulated outbound action passes one gate. The gate evaluates two independent rulebooks at consensus time: the regulator aligned baseline and the firm’s own overlay. Both must sign. The verdict and its reasons are written to a ledger the firm, the regulator and an independent auditor all see. No single party, not even Kronaxis, can wave a message through or quietly delete a refusal.

Re running the rule on a fresh machine, against the same descriptor and the same rule text, gives the same answer. The receipt’s sealed inclusion can be re computed cryptographically in your browser. That is the difference between “trust us” and “don’t trust us.”

Honest about the bounded claim
The reference embodiment runs on a four validator BFT testnet and is exercised by 26 named scenarios. The structural properties hold today: dual authority composition, the role typed quorum, the consensus enforced gate, deterministic policy replay, the refusal code taxonomy, the hash bound canonical descriptor, and the per action proof on the ledger. The operational hardening that lands at pilot is named openly: hardware backed signing keys, hardware attested signers, a client hosted layer one signer, reproducible builds, multi party validator distribution, M of N governance, a public transparency log mirror, a biometric mobile signer for human sign off, and persistent ledger state on disk. The substitution point for each item is stated on the For regulators page.
Why you can trust this

Receipts, not logos.

We are early, and we would rather earn trust the way we ask a regulated buyer to grant it: by showing the work. No badges we cannot stand behind. Everything below is public and checkable today.

Published research

Four papers, published open access with citable DOIs, covering the compliance architecture and the science underneath it. Read them, cite them, argue with them.

Read the research

Patents filed

Four UK patent applications filed at the Intellectual Property Office across the platform, 91 claims in total. The methods are protected, not hand waved.

Recomputable proof

Do not take our word for any of it. Download a proof bundle and recompute the verdict yourself, in your browser or with the open verifier on your own machine.

Recompute the proof
Independent coverage
Our work has been examined in the press, not just described by us. Private Eye covered Kronaxis in its investigation into hidden property ownership. As more coverage lands it will be listed here, named and linked.