🇲🇾 Sovereign  Âˇ  Model-agnostic  Âˇ  ASEAN-ready

Govern every AI agent before it acts.

TruGovern registers, certifies, secures and audits every AI agent operating across ministries, GLCs, statutory bodies and regulated enterprises — one control plane that inspects every prompt, tool call and output, regardless of the model behind it.

PDPA Malaysia Cyber Security Act 2024 ISO/IEC 42001 ISO/IEC 27001 NIST AI RMF ASEAN AI Governance Guide
< 150 msAdded p95 latency on inspected requests
100%Governed decisions logged, tamper-evident
≥ 90%Prompt-injection catch rate at GA
ZeroControl regression on model swap
audit-ledger ¡ live decision feed
timestamp10:30:14 MYT
agencyMinistry of Finance
agentProcurementCopilot ¡ AG-MOF-00472
certification🥇 Gold · decision-support
actionGenerate tender evaluation
verdictALLOW  PII redacted
nextSTEP-UP  db.delete held for approval
blockedDENY  external email recipient
hash 3f9a…c21 chain integrity verified ✓
The risk landscape

Agentic AI is being adopted faster than it can be governed.

Agents now read sensitive data and take real-world actions — send email, move money, delete records — at machine speed. Without governance equivalent to human governance, organisations face five compounding classes of risk.

🪪

Identity

Unknown and rogue agents, impersonation, orphaned credentials with no accountable owner.

🛡️

Security

Prompt injection, jailbreaks, data exfiltration and privilege escalation via tools.

⚖️

Governance

No ownership tracking, no approval workflow, no accountability chain for actions.

📋

Compliance

PDPA breaches, sovereignty breaches and undocumented automated decisions.

👁️

Operational

Shadow AI, duplicate agents and runaway token cost across agencies.

Full platform ¡ nine modules, eight layers

One sovereign control plane over the full agent lifecycle.

From registration through certification, enforcement, monitoring and decommissioning — a single source of truth that governs agents whether powered by Llama, Mistral, GPT, Claude, Gemini, DeepSeek or sovereign Malaysian models.

MODULE A ¡ L1
🗂️

National Agent Registry

The authoritative inventory of every agent — owner, agency, class, model, connected systems, permissions and risk.

  • Searchable, role-scoped registry with review SLAs
  • Shadow-agent discovery from gateway & network telemetry
  • Quarantine of unregistered agents pending attribution
  • Lifecycle states: register → certify → operate → retire
MODULE B ¡ L2
🔐

Cryptographic Identity Authority

Every agent receives a unique ID, X.509 certificate and verifiable credentials from a sovereign, in-country CA.

  • Accountability chain: human → agency → owner → agent → action
  • HSM-backed keys ¡ TLS 1.3 ¡ SHA-384 certificates
  • Instant rotation and revocation (CRL / OCSP) to halt an agent
  • Service-account & agent-identity lifecycle management
MODULE D ¡ L3
🚦

Governance Gateway

An inline, OpenAI-compatible reverse proxy that inspects, redacts, blocks or escalates every request in the path.

  • Prompt-injection & jailbreak detection, direct and indirect
  • PII & secret redaction incl. NRIC and local data classes
  • Tool-call policy: allow / deny / step-up per action
  • Streaming support with incremental inspection
MODULE D ¡ L4
🧭

Policy & Rules Engine

No-code, versioned policies — deny, step-up or transform — written once and enforced across every provider.

  • Author, version, diff, roll back and promote policies
  • Dry-run (shadow) mode: evaluate and log without enforcing
  • Per-route fail-open vs fail-closed configuration
  • Pre-built rule packs: PDPA, CSA 2024, financial services, healthcare
MODULE C ¡ L6
🏅

Certification & Approval Workflow

Staged human approval gates every agent before production, earning one of four certification tiers.

  • Six-stage workflow: Owner → Governance → Security → Compliance → Board → Production
  • Approval inbox with full context of the held request
  • SLA timers, delegation, escalation and notifications
  • Every approve / reject decision written to the ledger
MODULE E ¡ L4
🎯

AI Security Operations Centre

Continuous automated red-teaming, penetration testing and behavioural threat detection with auto-containment.

  • Mean time to detect < 15 minutes ¡ automated containment
  • Behavioural anomaly detection on action volume & egress
  • SOAR runbooks; critical agents auto-suspended on detection
  • Replaces once-a-year testing with continuous assurance
MODULE F ¡ L5
✅

Continuous Compliance Engine

Controls map continuously to every framework your regulators require, with one-click evidence packs.

  • Live coverage scoring against PDPA, CSA 2024, ISO 42001 & more
  • Gap analysis with owners, severity and remediation deadlines
  • Scheduled regulatory reports and compliance dashboards
  • Sector packs for Bank Negara RMiT and healthcare data rules
MODULE G ¡ L6
🧾

Immutable Audit & Forensics

Every governed action produces a tamper-evident, hash-chained record — auditor-grade evidence of control.

  • Append-only ledger; each entry links to the previous
  • Metadata-only or full-content modes for residency
  • Filterable real-time decision feed across all models
  • CSV / JSON & legal-hold export; chain-verification report
MODULES H ¡ I ¡ L7
🛍️

Marketplace & Citizen Portal

Certified template agents cut duplicate builds across agencies, while the public portal delivers AI transparency.

  • Deploy certified, compliant template agents — target ≥30% reuse
  • Citizens see which agent handled their case, and why
  • Guaranteed rights: explanation, human review, appeal
  • PDPA & AIGE-aligned transparency notices on every public agent
Inline governance ¡ the enforcement heart

Every request. Every tool call. Every output. Governed inline.

Governance is enforced in the request path — it can block and transform, not merely report after the fact. Point an application's base URL at the gateway; no SDK rewrite, provider keys held server-side.

01 ¡ AUTH

Intercept

App routes through the OpenAI-compatible proxy carrying its signed identity token. Streaming supported end-to-end.

02 ¡ INPUT

Inspect

Normalise to a common schema; run injection, PII/secret and classification detectors on every input and tool result.

03 ¡ POLICY

Enforce

Evaluate policy — allow, deny, step-up or transform (redact) — on the prompt and on every requested tool call.

04 ¡ OUTPUT

Audit

Inspect and redact the output, return it, and write the full decision to the immutable hash-chained ledger.

🧨

Prompt-injection & jailbreak detection

Fast heuristics plus a classifier flag manipulation on inbound prompts and on tool results re-entering the model. Configurable threshold: block, flag-and-allow, or step-up — with updatable signature packs, no redeploy.

🫥

PII & secret redaction

Detects personal data and credentials on inputs and outputs — including local classes such as NRIC — and redacts, reversibly tokenises, or blocks per policy, with authorised detokenisation.

🛑

Tool-call policy & step-up approval

Every requested tool call is inspected before it runs. Destructive or external actions — delete, send_email, payment.transfer — are held for human approval or blocked outright. Dry-run mode tests before enforcing.

⛓️

Tamper-evident audit log

Every decision is recorded — who, what, when, why — in an append-only, hash-chained ledger with configurable retention, residency modes and one-click export accepted by auditors.

Trust, by design

No agent reaches production uncertified.

Agents are classified by autonomy and risk, then gated through staged human approval, earning one of four certification tiers before going live.

🥉

Bronze

Low-risk ¡ informational

Self-assessment plus automated checks. Suited to read-only informational agents; may auto-approve on passing checks.

🥈

Silver

Internal ¡ copilot

Reviewed by the agency AI Governance Officer for internal copilot agents assisting staff workflows.

🥇

Gold

Decision-support

Full security and compliance review for agents that recommend or shape decisions affecting people or funds.

💎

Platinum

Autonomous ¡ transaction

Approval-board sign-off plus continuous monitoring for autonomous agents that execute transactions.

1Business Owner→ 2Governance Officer→ 3Security Team→ 4Compliance Team→ 5Approval Board→ 6Production ✓
Compliance & sovereignty

Demonstrable compliance, on demand.

Controls map continuously to every framework your regulators care about — translated into enforceable gateway rules and audit evidence, not checklists.

PDPA (Malaysia)Personal data protection ¡ NRIC handling
98%
Cyber Security Act 2024NACSA ¡ CNI security duties & incident evidence
95%
ISO/IEC 42001AI management system
92%
ISO/IEC 27001Information security
97%
NIST AI RMFGovern ¡ Map ¡ Measure ¡ Manage
90%
ASEAN AI Governance GuideRegional alignment ¡ AIGE national guidelines
88%
Bank Negara RMiT & SC rulesFinancial-services & capital-markets sector packs
86%

🇲🇾 The sovereignty stance

The enforcement core is identical across on-prem, sovereign cloud and SaaS — so a Malaysian agency can adopt AI governance without any sensitive content leaving its jurisdiction or its perimeter.

  • Data, keys, registry and logs stay in-country
  • No mandatory egress to foreign clouds
  • Metadata-only audit mode for classified workloads
  • Content residency configurable per tenant
  • Sovereign CA with in-country root of trust
  • Government IdP & MyDigital ID integration
Model-agnostic by construction

One policy. Every model. No rewrites.

Every provider is reached through an adapter that normalises to a common schema; policy runs against the schema. Swap models with zero control regression and zero policy changes.

🧠 Model adapters

LlamaMistralGPT / Azure OpenAIClaudeGemini / VertexDeepSeekSovereign / MIMOS LLM

🏛️ Government systems

MyDigital IDMyGovUCMyGDXHRMISePerolehanGovernment IdP (OIDC / SAML)

🏢 Enterprise & protocol

SAPOracleDynamicsSalesforceMCPOpenAI-compatible API
Deployment topologies

Residency is a configuration, not a fork.

On-prem, sovereign or private cloud and managed SaaS share one enforcement core — Kubernetes-native, Helm-packaged, with an air-gap-capable installer.

🔒

On-prem / air-gapped

Full stack inside the agency perimeter with pack updates via a controlled channel — for the highest classification levels.

Federal ¡ classified workloads
☁️

Sovereign / private cloud

Deployed in a Malaysia-resident cloud region or government cloud, managed by the customer or by TruGovern under a sovereignty agreement.

Ministries ¡ GLCs ¡ statutory bodies
🛠️

Managed SaaS

TruGovern-operated, Malaysia-resident, multi-tenant with a metadata-only audit option — for regulated enterprises that prefer managed delivery.

Banks ¡ insurers ¡ healthcare ¡ telco
99.9%Gateway availability (HA deployment)
100K+Agents supported per national tenant
WCAG 2.1 AAAccessible console ¡ English + Bahasa Malaysia
ISO ¡ SOC 2Target certifications for the managed service
Delivery roadmap

A phased path from pilot to ASEAN federation.

2026 ¡ PHASE 0

Foundation

Registry, Identity Authority and core policy engine live with a single lighthouse agency pilot.

2027 ¡ PHASE 1

Governance & Security

Full gateway, AISOC, compliance engine and command centre across five or more agencies.

2027–28 · PHASE 2

Scale & Marketplace

Certification portal, certified agent marketplace and the public citizen-service portal.

2028 ¡ PHASE 3

National Federation

National registry federation with cross-agency oversight roll-up and whole-of-government posture.

2029 ¡ PHASE 4

ASEAN Network

Cross-border governance with federated foreign tenants interoperating on a common framework.

🇲🇾
MalaysiaAnchor tenant
🇸🇬
SingaporeInteroperate
🇧🇳
BruneiPhase 4
🇮🇩
IndonesiaPhase 4
🇹🇭
ThailandPhase 4
🇻🇳
VietnamPhase 4
🇵🇭
PhilippinesPhase 4
🌏
ASEAN+Network

Govern AI on your own sovereign terms.

TruGovern doesn't compete with model providers — it governs and secures every agent regardless of the model behind it. Book an executive briefing to scope a pilot for your ministry, GLC, statutory body or regulated enterprise.