The new way to build

Build AI applications with no code. Governance comes out of the box.

Business logic can be a prompt now. EKKA is the runtime where governance is the execution path: every action authorized before it happens, signed after.

Your prompts, your rows and your credentials never reach us. We can prove what happened because we signed it, not because we saw it. See how, with the commands that check it.

Private beta. Runs in your environment; only signed proof leaves.

One action, governed the Monday report
WITH A GRANT GRANT PLAN STEP Pull the numbers GATE · OPEN DATABASE Sales data SIGNED receipt, on the chain WITHOUT A GRANT NO GRANT PLAN STEP Read salaries GATE · SHUT DATABASE Salaries nothing crossed denial recorded ✓

The shift

Application development changed.
The requirement did not.

Business logic can be written in prompts now. A smart model connected to files, databases, and APIs does what teams of developers used to build.

And the requirement stands: a model holding the keys to everything, unchecked and unrecorded, does not ship.

The new stack ✕ unchecked
MODEL FILES
MODEL DATABASE
MODEL APIS

Every connection open. Nothing checked, nothing recorded.

The same stack, on EKKA ✓ governed
MODEL GATE FILES
MODEL GATE DATABASE
MODEL GATE APIS

A gate on every connection. Opens only for what was granted; every decision signed.

EKKA is how the demo becomes production. Everything the model touches sits behind a gate, a gate opens only for what was granted, and every decision lands on a signed record.

How it works

Build the workflow. Every box runs governed.

An EKKA plan is a workflow anyone can read. This one is the Monday report: the automation a manager builds alone, and security signs off on, because every step passes a gate before it runs and every decision lands on a signed record.

The numbers last week, nothing more The prompt written once, filled with the data The summary the model writes it To the team every Monday, 8 am RECEIPT SIGNED ✓ GATE GATE GATE THE MONDAY REPORT · ONE PLAN, DRAWN

The plan is the drawing: four steps, a gate before each one, a signed receipt after all of them.

Nothing happens without a permit. Nothing happens without a receipt.

The hero diagram above is the rule, not a picture: a step with a grant crosses its gate and signs a receipt; a step without one stops at the gate, and even the stop is recorded.

The Enclave

Yours stays yours.

EKKA runs in your environment. Your files, your database, and your keys never leave. The only thing that travels is proof: a signed record of what ran and who allowed it.

Most platforms ask you to send your data to them so their agents can act on it. EKKA inverts that. The Enclave is a piece of EKKA that lives inside your environment, holds its own identity, and answers to your policy.

It runs on your infrastructure

Your laptop, your server, your VPC. Agents do their work next to the data they need, so the data never has to travel to us. EKKA holds no copy and no keys.

It has its own identity

Each Enclave generates its own signing key at enrollment. The private key never leaves the machine - not at setup, not ever. It proves who it is by signing a challenge, not by presenting a shared secret someone could copy.

It is enrolled, like a member

An Enclave belongs to an organization the way a person does. It can be granted permissions, suspended, or revoked centrally - and it can act on a colleague's behalf when a plan requires human authority.

Only proof leaves it

What crosses the boundary is a signed, hash-chained receipt of what was allowed and what happened. Verifiable offline against published keys. Never the underlying data.

The boundary
YOUR ENVIRONMENT Agent Model Data RECEIPT SIGNED ✓ the only thing that leaves DATA, MODELS AND AGENTS STAY · PROOF TRAVELS

Precisely: an EKKA Enclave is a customer-hosted, cryptographically enrolled execution boundary where agents perform governed work and raw customer data stays local. On the word "enclave". EKKA Enclaves are policy and process isolation boundaries. They do not imply hardware-backed confidential computing unless explicitly configured with such infrastructure. We use the word for what it plainly means - your territory, inside which your rules hold - and we would rather say that up front than let the term do work it has not earned.

Governed by construction

Where AI agents become software you can trust.

Every component sits behind a gate, including the model itself. A gate opens only for a grant you approved: written in plain words, signed, revocable, and expiring on a date you chose. Not allowed means it does not run, and the refusal itself lands on the record.

Grant of Authority

Allow agent Balance Reporter to read the customers table behind the demoV1 Postgres gate. Nothing else.

GRANTED BYYou, the owner SCOPERead only VALID30 days, or until you revoke it
The grant is the key
EKKA GRANT · SIGNED THE GATE CUSTOMERS read only One table. Read only. Expires in 30 days. Revocable anytime. NO KEY, NO TURN · DENY IS THE DEFAULT

Deny is the default. A grant exists only for a power the agent declared and an owner approved, and every decision lands on a signed record.

Blocked before I/O

A disallowed action is refused before any data moves - not caught afterward and logged. The refusal itself is a signed record.

Receipts, not logs

Every step emits a signed, hash-chained receipt containing the exact data accessed, model invoked, and prompt used. Receipts can be verified offline against published keys.

Your data never leaves

Your Enclave runs in your environment, on your infrastructure. EKKA holds no data and no keys - only signed proof crosses the line.

The record of one run
#1 PERMIT SIGNED ✓ #2 WORK SIGNED ✓ #3 ATTESTED SIGNED ✓ #2 EDITED CHAIN BREAKS Every decision hangs on one chain, each receipt linked to the one before. Edit one byte of history and the break is visible to anyone who checks. VERIFIABLE OFFLINE · NO TRUST IN US REQUIRED

What you can build

Same shape. Any domain.

Invoice chasing, claims triage, compliance reporting, new-hire onboarding. Every one is the same four pieces: a plan, gates, a model, and an audit trail.

Run a compliance report on schedule

Assemble evidence across systems on a cadence. The receipt chain is the audit trail.

Watch your production

Read APM, logs, and uptime through governed calls and produce reports with the proof attached.

Risk across your data

Join customer, invoice, and subscription data to identify payment risk.

A multi-agent workflow

Route requests, fan out to specialists, verify results, and synthesize responses.

Yours

The smallest plan is two steps. The largest is a full multi-agent workflow. EKKA governs every step the same way.

If you can describe it, you can build it.

The library grows as builders publish more - every one governed by the same rules.

The marketplace

Your agent works for you. It can also earn for you.

That blank tile above? It could be your knowledge, running for other people.

Step 1

Publish your agent

Your knowledge, packaged as an agent others can run. The catalog is curated: EKKA approves what gets published, and you stay the owner.

Step 2

Others run it

Inside their own EKKA, on their own data, behind their own gates. Your agent never sees what it was not granted.

Step 3

Usage pays the creator

Every run is metered at the published price, and metered usage is what pays the creator.

If you have knowledge, you have a product. You do not need to code it, host it, or defend it. The plan carries the logic, the gates carry the safety, and the record carries the proof.

The value

What your organization gains

Teams build with AI at full speed. The organization keeps control, visibility, and proof. Nothing happens without your permission. Everything that happens is on the record. Anyone can check the record, including you.

Ship AI Faster

Teams build and iterate on AI agents without waiting for custom security reviews on every workflow.

Reduce Operational Risk

Prevent unauthorized actions before they happen, across data, infrastructure, models, and connected systems.

Prove Compliance

Every action is authorized, signed, and traceable with immutable execution history ready for audit.

One Model, Any Scale

The same governance model applies whether you're running one task or thousands of AI workflows.

The impact

Before EKKA
  • AI can reach systems without consistent governance
  • Security reviews slow every deployment
  • Audits require reconstructing what happened
  • Scaling agents increases risk and complexity
  • Teams lack visibility into what AI is doing in production
After EKKA
  • Every action is evaluated and permitted before it happens
  • Governance is built into every execution
  • Every action already has signed, immutable proof
  • Scaling agents preserves the same governance model
  • Full visibility into who did what, when, and why

Nothing moves without permission. Nothing is claimed without proof.

Questions

The things people ask first

What is governed execution?
A runtime where every action an agent takes is authorized before it happens and signed after, rather than a policy you hope is followed.
Does EKKA see my data or my credentials?
No. Prompts, rows and keys never reach us. We can prove what happened because we signed it, not because we saw it.
What happens when an agent tries something it should not?
It is refused before anything moves: no socket, no DNS, no credential read. The refusal is recorded with its reason.
Can I revoke access instantly?
Yes. Revoking a grant takes effect on the next attempt, not at the next deploy.
Can I run it all on my own machines?
Yes. The Enclave runs in your environment holding your data and keys, and hosted is a choice, not a requirement.

Request access

This is for you.

If you have knowledge

"I know how this job is done. I can publish an agent that does it for others."

If you need an application

"I know what I want built. I do not need to worry about coding."

Governance and a signed audit trail, by construction - from your very first agent.

Private beta. It runs in your environment, and every request gets a personal reply.

EKKA was built by people who ran automated pipelines that touched real money, where a compliance check inside the execution path was the only reason the system was allowed to exist. EKKA is that principle, generalized: authorize before, sign after.

By requesting access you agree to our Terms and Privacy Policy.