Sovereign · Model-agnostic · ASEAN-ready

The control plane for governed AI agents in government.

TruGovern registers, certifies, secures and audits every AI agent operating across ministries, GLCs and statutory bodies — so autonomous AI acts safely, transparently and accountably, regardless of the model behind it.

// Built for MyDigital ID · MyGovUC · MyGDX · HRMIS · ePerolehan · PDPA · Cyber Security Act 2024
8
Governance layers, one control plane
100K+
Agents per national tenant
<15min
Mean time to detect a threat
Zero
Control regression on model swap
Aligned to PDPA Malaysia Cyber Security Act 2024 ISO/IEC 42001 ISO/IEC 27001 NIST AI RMF ASEAN AI Governance Guide
The risk landscape

Agentic AI is being adopted faster than it can be governed.

Agents now access systems, make decisions and execute transactions at machine speed. Without a governance framework equivalent to human governance, organisations face five compounding classes of risk.

🪪

Identity

Unknown and rogue agents, impersonation, orphaned credentials with no owner.

🛡️

Security

Prompt injection, jailbreaks, data exfiltration and privilege escalation.

⚖️

Governance

No ownership tracking, no approval workflow, no accountability chain.

📋

Compliance

PDPA breaches, sovereignty breaches, undocumented automated decisions.

👁️

Operational

Shadow AI, duplicate agents and runaway token cost across agencies.

Eight functional layers

One sovereign control plane over every agent.

From registration through to decommissioning, TruGovern supervises the full agent lifecycle — a single source of truth that governs agents whether powered by Llama, Mistral, GPT, Claude, Gemini, DeepSeek or future sovereign models.

L1🗂️

Agent Registry

Authoritative inventory and classification of every agent — owner, purpose, model, connected systems, permissions and risk class.

L2🔐

Identity Authority

Cryptographic Agent IDs, PKI certificates and verifiable credentials, making every action attributable to a human.

L3🚦

Governance Gateway

Inline inspection of prompts, tool calls and outputs; enforces policy regardless of the underlying model.

L4🎯

Security Shield · AISOC

Continuous automated red-teaming, penetration testing and behavioural threat detection — 24/7, not once a year.

L5

Compliance Engine

Maps live controls to PDPA, the Cyber Security Act, ISO 42001/27001 and NIST AI RMF with one-click evidence packs.

L6🏅

Approval & Certification

Staged human approval workflow and Bronze→Platinum certification gating before any agent reaches production.

L7🛍️

Agent Marketplace

A catalogue of certified, reusable agents and templates — cutting duplicate builds across agencies.

L8📊

Command Center

Real-time dashboards for adoption, risk, compliance score and token/cost consumption across the estate.

Inline governance

Every action resolves to an accountable human.

Human User Agency Agent Owner AI Agent Tool / System Action
01 · AUTH

Identify

Signed agent identity checked against the registry, certification level and permissions.

02 · INPUT

Inspect

Prompt-injection, jailbreak and sensitive-data detection plus offensive-language hygiene.

03 · POLICY

Enforce

Allow, deny or step-up — block destructive actions, restrict external recipients, cap counts.

04 · OUTPUT

Audit

PII, toxicity and classification checks, then an immutable, tamper-evident audit record.

Ten functional modules

Everything a governance team needs, in one platform.

A

Agent Registry

Register, classify and discover agents; shadow-agent detection across tenants.

B

Identity Management

Issue, rotate and instantly revoke cryptographic agent credentials.

C

Lifecycle Management

Draft → review → certified → production → retired, with re-certification triggers.

D

Governance & Policy Engine

No-code, versioned policies — deny, step-up or transform — enforced model-agnostically.

E

Security Operations (AISOC)

Continuous testing, anomaly detection and auto-containment of compromised agents.

F

Compliance Management

Live compliance scores, gap analysis and on-demand regulatory evidence packs.

G

Audit & Forensics

Immutable, hash-chained, blockchain-anchored records with legal-hold export.

H

AI Marketplace

Publish and reuse only certified, compliant agents and templates.

I

Citizen Service Portal

Transparency notices, human-escalation paths and explainability for public-facing agents.

J

Executive Command Center

Real-time visibility of agents, risk, cost and adoption — with federated national roll-up.

Trust, by design

No agent reaches production uncertified.

Agents are classified by autonomy and risk, then gated through a staged approval workflow — Business Owner → Governance Officer → Security → Compliance → Approval Board → Production — earning one of four certification tiers.

🥉

Bronze

Low-risk · informational

Self-assessment plus automated checks. Suited to read-only informational agents.

🥈

Silver

Internal · copilot

Reviewed by the agency AI Governance Officer for internal copilot agents.

🥇

Gold

Decision-support

Full security and compliance review for agents that recommend decisions.

💎

Platinum

Autonomous · transaction

Approval-board sign-off and continuous monitoring for autonomous transaction agents.

Compliance & sovereignty

Demonstrable compliance, on demand.

Controls map continuously to every framework your regulators care about. Data, keys, registry and logs stay in-country — no mandatory egress to foreign clouds.

PDPA Cyber Security Act 2024 ISO/IEC 42001 ISO/IEC 27001 NIST AI RMF ASEAN AI Guide
audit-trail · immutable
timestamp  : 06/06/2026 10:30:14 MYT
agency     : Ministry of Finance (MoF)
officer    : officer123 · MyDigital ID
agent     : ProcurementCopilot · AG-MOF-00472
cert      : Gold
task      : Generate tender evaluation
model     : Sovereign Llama-class
policy    : ALLOW · PII redacted · no ext recipients
result    : completed
risk      : low
integrity : hash-chained → ledger ✓
Delivery roadmap

A phased path from pilot to ASEAN federation.

Phase 0
2026

Foundation

Registry, Identity and core policy engine live with a single pilot agency — at least one certified agent in production.

Phase 1
2027

Governance & Security

Full governance gateway, AISOC, compliance engine and command centre — inline enforcement across five or more agencies.

Phase 2
2027–28

Scale & Marketplace

Certification portal, agent marketplace and citizen-service portal — a whole-of-government registry with reusable templates.

Phase 3
2028

National Federation

National registry federation and cross-agency oversight roll-up operational.

Phase 4
2029

ASEAN Network

Cross-border agent governance with at least one federated foreign tenant interoperating.

Sovereign federation

Local-first. Federation-ready.

Each country runs its own instance — national registry, keys and law mappings stay sovereign — while sharing a common framework and opt-in interoperability for cross-border verification.

🇲🇾
Malaysia
anchor tenant
🇧🇳
Brunei
phase 4
🇮🇩
Indonesia
phase 4
🇹🇭
Thailand
phase 4
🇻🇳
Vietnam
phase 4
🇵🇭
Philippines
phase 4
🇸🇬
Singapore
interoperate
🌏
ASEAN+
network

Govern AI on your own sovereign terms.

TruGovern doesn't compete with model providers — it governs and secures every agent regardless of the model behind it. Book an executive briefing to scope a pilot for your ministry, GLC or statutory body.