
Governance and guardrails
The controls that let you put AI in front of customers, staff and auditors, and stop it when you need to.
- 1Who's asking
- 2Mask and screen
- 3Policy
- 4Model in your cloud
- 5Check the answer
- 6Guard the tools
- 7Record it
AI security and governance is two jobs. On every request and every agent action, controls check who is asking, mask personal data, screen for hidden instructions, apply your policy, check the answer and limit which tools an agent may use, and each decision is recorded. Over time, every AI system is listed in an inventory with an owner, tiered by risk, red-teamed before launch, monitored, and able to be stopped in one move. PI Square builds both, mapped to the OWASP Top 10 for LLM and agentic applications, NIST's AI Risk Management Framework, ISO/IEC 42001 and POPIA.
A request or an agent action
from a person, an app, an agent or a document
- Your cloud
Checked before the model
identity, personal data, hidden instructions, policy
Answered in your cloud
enterprise endpoints, no training on your data
Checked after, and recorded
the answer, every tool call, a tamper-evident log
Released, blocked or sent to a person
and paused by its owner if needed
What it's for
Financial services
Credit and fraud models where the AI recommends and a person decides, with the reason recorded, as POPIA section 71 expects for decisions about people.
Healthcare and wellness
Consumer conversations checked against safety rules before a reply is sent, with personal health information masked.
Retail and procurement
Agents that read supplier and customer documents without following instructions hidden inside them.
Any business already using AI
An inventory of every AI system in use, with its owner and risk tier, and controls added around existing chatbots and agents.
How we keep it safe
- Personal data is masked before it reaches a model, and restored only for the person allowed to see it.
- Documents, emails and tool results are read as data, never as instructions, so a hidden instruction can't steer an agent.
- Each agent gets the fewest tools its job needs; sending outside, paying or deleting waits for a person.
- Every request, decision and tool call goes into an audit record, each entry chained to the last so any change shows.
- Every AI system has an inventory entry, a risk tier, red-team results from before launch, and an owner who can pause it.
Built with
- An AI gateway in your cloud
- Model Armor, Bedrock Guardrails or Azure AI Content Safety
- Cloud KMS, AWS KMS or Azure Key Vault
- Model Context Protocol
- Rust
- TypeScript
Where we've built this
- A regulated consumer AI product: governance middleware that checks every model call before it runs, with a cryptographically chained audit trail and signing keys in a cloud key service.
- A retail group's content studio: five layers of prompt rules, two kinds of output scoring, and hard cost limits for each brand.
How an engagement runs
Understand
We list the AI you run or plan, tier each system by risk, and test it against the OWASP lists, POPIA and your own policies.
Prove
Controls on one system: masking, injection screening, tool limits, output checks and an audit record, with red-team results before it goes live.
Embed
The controls have a named owner, monitoring and an incident response process. Coverage can expand to other systems after reviewing their needs.
Questions about governance and guardrails
- What is AI governance?
- The rules and controls that decide what an AI system may do, and the records that prove what it did. In practice: an inventory of AI systems with owners and risk tiers, controls on every request and agent action, testing before launch, monitoring after it, and a way to stop a system quickly.
- What is prompt injection, and can it be stopped?
- Prompt injection is text that tries to give an AI new instructions, typed by a user or hidden in a document, email or web page the AI reads. It is the first risk on the OWASP Top 10 for LLM applications, and no single control stops it reliably. So we layer them: untrusted content is read as data, agents get only the tools they need, risky actions wait for a person, and every attempt is recorded.
- What does POPIA say about AI decisions?
- Section 71 of POPIA says a decision with legal effect, or a significant effect, on a person may not rest solely on automated processing that profiles them, apart from limited exceptions. Where AI scores credit, screens candidates or rates performance, we design it to recommend and a person to decide, with the reason recorded. The legal judgement stays with your own advisers.
- Can you add guardrails to an AI system we already run?
- Usually, yes. The controls sit between your application and the model, so they can be added without rebuilding the application. We confirm it for your system during Understand.
- Which frameworks do you follow?
- The OWASP Top 10 for LLM applications and for agentic applications, NIST's AI Risk Management Framework and its generative AI profile, ISO/IEC 42001 for the management system, Google's Secure AI Framework, and POPIA. Each control is mapped to them, so your auditors can follow it.
- How do these guardrails support compliance audits?
- We agree which model calls, policy decisions and tool actions need an audit record, with appropriate access controls and retention limits. Mapping those controls to relevant frameworks helps your reviewers trace the evidence. This supports an audit; it does not by itself establish compliance or certification.
The other five
Agentic workflows
Agents that carry a piece of work from request to done, inside the tools your people already use.
How we build itKnowledge assistants
Answers from your own documents, with the source attached, for your staff and your customers.
How we build itDocument intelligence
Documents read as they arrive, checked against your rules, and sent where they need to go.
How we build itGenerative content
On-brand images, video and copy in volume, checked against your brand rules before anyone sees them.
How we build itModernisation and integration
Old systems mapped and documented by AI, rebuilt one slice at a time, and proved against the original before anything switches.
How we build it
Tell us what you're working on
Keep this general; leave out sensitive or confidential information.
Or email nikhil@pisquare.ai