Compliance
The log is the legal defense
Gatewarden turns AI usage into a tamper-evident record you can stand behind. Its compliance value is investigation-readiness and evidence of reasonable care — not a substitute for legal advice.
The policy-pack model
A policy-agnostic core, regulatory specifics in packs
The appliance knows risk levels, rules, events, and reports. Each policy pack supplies the regulatory framing — so the same product adapts as requirements evolve.
- Gatewarden's compliance logic lives in policy packs. The core appliance is policy-agnostic — it knows only about risk levels, rules, events, and reports.
- A policy pack supplies the specific regulatory rules, the classification reasons, and the compliance-report mapping, so the same appliance can serve different regulatory frameworks over time.
- The first pack covers AI service governance and is built around Texas's TRAIGA (HB 149).
Active policy pack
AI service governance (Texas TRAIGA / HB 149)
The first pack is built around Texas's TRAIGA. The product's value proposition stays constant; only this regulatory framing is pack-specific.
Investigation-readiness
If a regulator investigates — for example, through a civil investigative demand — Gatewarden's tamper-evident logs serve as evidence of good-faith monitoring and reasonable care.
Visibility into sensitive-data exposure
Content classification flags when prompts send sensitive or regulated data to AI services, and service detection shows where AI is used – the core shadow-AI exfiltration risk made visible. That evidence maps to TRAIGA reasonable care and CID-readiness; it is not a determination that the law was broken.
Documentation, not enforcement
For government-agency deployments, Gatewarden provides an organization-type flag, a standing disclosure reminder, and an operator-acknowledgment record — for documentation only. The disclosure itself is your application's responsibility.
TRAIGA is primarily a prohibitions statute, not a standing governance mandate. So Gatewarden is framed as readiness and defense: its content classification surfaces when sensitive or regulated data is exposed to AI services, and its tamper-evident logs map that evidence to your TRAIGA obligations – reasonable care and readiness for a civil investigative demand. Gatewarden surfaces risk evidence; it does not determine that a TRAIGA prohibition was violated.
We never present a product feature as a legal requirement. Where a capability maps to a statute, we frame it as readiness or defense; otherwise we present it simply as product value.