TruGovern registers, certifies, secures and audits every AI agent operating across ministries, GLCs, statutory bodies and regulated enterprises â one control plane that inspects every prompt, tool call and output, regardless of the model behind it.
Agents now read sensitive data and take real-world actions â send email, move money, delete records â at machine speed. Without governance equivalent to human governance, organisations face five compounding classes of risk.
Unknown and rogue agents, impersonation, orphaned credentials with no accountable owner.
Prompt injection, jailbreaks, data exfiltration and privilege escalation via tools.
No ownership tracking, no approval workflow, no accountability chain for actions.
PDPA breaches, sovereignty breaches and undocumented automated decisions.
Shadow AI, duplicate agents and runaway token cost across agencies.
From registration through certification, enforcement, monitoring and decommissioning â a single source of truth that governs agents whether powered by Llama, Mistral, GPT, Claude, Gemini, DeepSeek or sovereign Malaysian models.
The authoritative inventory of every agent â owner, agency, class, model, connected systems, permissions and risk.
Every agent receives a unique ID, X.509 certificate and verifiable credentials from a sovereign, in-country CA.
An inline, OpenAI-compatible reverse proxy that inspects, redacts, blocks or escalates every request in the path.
No-code, versioned policies â deny, step-up or transform â written once and enforced across every provider.
Staged human approval gates every agent before production, earning one of four certification tiers.
Continuous automated red-teaming, penetration testing and behavioural threat detection with auto-containment.
Controls map continuously to every framework your regulators require, with one-click evidence packs.
Every governed action produces a tamper-evident, hash-chained record â auditor-grade evidence of control.
Certified template agents cut duplicate builds across agencies, while the public portal delivers AI transparency.
Governance is enforced in the request path â it can block and transform, not merely report after the fact. Point an application's base URL at the gateway; no SDK rewrite, provider keys held server-side.
App routes through the OpenAI-compatible proxy carrying its signed identity token. Streaming supported end-to-end.
Normalise to a common schema; run injection, PII/secret and classification detectors on every input and tool result.
Evaluate policy â allow, deny, step-up or transform (redact) â on the prompt and on every requested tool call.
Inspect and redact the output, return it, and write the full decision to the immutable hash-chained ledger.
Fast heuristics plus a classifier flag manipulation on inbound prompts and on tool results re-entering the model. Configurable threshold: block, flag-and-allow, or step-up â with updatable signature packs, no redeploy.
Detects personal data and credentials on inputs and outputs â including local classes such as NRIC â and redacts, reversibly tokenises, or blocks per policy, with authorised detokenisation.
Every requested tool call is inspected before it runs. Destructive or external actions â delete, send_email, payment.transfer â are held for human approval or blocked outright. Dry-run mode tests before enforcing.
Every decision is recorded â who, what, when, why â in an append-only, hash-chained ledger with configurable retention, residency modes and one-click export accepted by auditors.
Agents are classified by autonomy and risk, then gated through staged human approval, earning one of four certification tiers before going live.
Self-assessment plus automated checks. Suited to read-only informational agents; may auto-approve on passing checks.
Reviewed by the agency AI Governance Officer for internal copilot agents assisting staff workflows.
Full security and compliance review for agents that recommend or shape decisions affecting people or funds.
Approval-board sign-off plus continuous monitoring for autonomous agents that execute transactions.
Controls map continuously to every framework your regulators care about â translated into enforceable gateway rules and audit evidence, not checklists.
The enforcement core is identical across on-prem, sovereign cloud and SaaS â so a Malaysian agency can adopt AI governance without any sensitive content leaving its jurisdiction or its perimeter.
Every provider is reached through an adapter that normalises to a common schema; policy runs against the schema. Swap models with zero control regression and zero policy changes.
On-prem, sovereign or private cloud and managed SaaS share one enforcement core â Kubernetes-native, Helm-packaged, with an air-gap-capable installer.
Full stack inside the agency perimeter with pack updates via a controlled channel â for the highest classification levels.
Deployed in a Malaysia-resident cloud region or government cloud, managed by the customer or by TruGovern under a sovereignty agreement.
TruGovern-operated, Malaysia-resident, multi-tenant with a metadata-only audit option â for regulated enterprises that prefer managed delivery.
Registry, Identity Authority and core policy engine live with a single lighthouse agency pilot.
Full gateway, AISOC, compliance engine and command centre across five or more agencies.
Certification portal, certified agent marketplace and the public citizen-service portal.
National registry federation with cross-agency oversight roll-up and whole-of-government posture.
Cross-border governance with federated foreign tenants interoperating on a common framework.
TruGovern doesn't compete with model providers â it governs and secures every agent regardless of the model behind it. Book an executive briefing to scope a pilot for your ministry, GLC, statutory body or regulated enterprise.