Skip to content
AI Gatewarden emblemAI Gatewarden

Compliance

The log is the legal defense

Gatewarden turns AI usage into a tamper-evident record you can stand behind. Its compliance value is investigation-readiness and evidence of reasonable care — not a substitute for legal advice.

The policy-pack model

A policy-agnostic core, regulatory specifics in packs

The appliance knows risk levels, rules, events, and reports. Each policy pack supplies the regulatory framing — so the same product adapts as requirements evolve.

  • Gatewarden's compliance logic lives in policy packs. The core appliance is policy-agnostic — it knows only about risk levels, rules, events, and reports.
  • A policy pack supplies the specific regulatory rules, the classification reasons, and the compliance-report mapping, so the same appliance can serve different regulatory frameworks over time.
  • The first pack covers AI service governance and is built around Texas's TRAIGA (HB 149).

Active policy pack

AI service governance (Texas TRAIGA / HB 149)

The first pack is built around Texas's TRAIGA. The product's value proposition stays constant; only this regulatory framing is pack-specific.

Investigation-readiness

If a regulator investigates — for example, through a civil investigative demand — Gatewarden's tamper-evident logs serve as evidence of good-faith monitoring and reasonable care.

Visibility into sensitive-data exposure

Content classification flags when prompts send sensitive or regulated data to AI services, and service detection shows where AI is used – the core shadow-AI exfiltration risk made visible. That evidence maps to TRAIGA reasonable care and CID-readiness; it is not a determination that the law was broken.

Documentation, not enforcement

For government-agency deployments, Gatewarden provides an organization-type flag, a standing disclosure reminder, and an operator-acknowledgment record — for documentation only. The disclosure itself is your application's responsibility.

TRAIGA is primarily a prohibitions statute, not a standing governance mandate. So Gatewarden is framed as readiness and defense: its content classification surfaces when sensitive or regulated data is exposed to AI services, and its tamper-evident logs map that evidence to your TRAIGA obligations – reasonable care and readiness for a civil investigative demand. Gatewarden surfaces risk evidence; it does not determine that a TRAIGA prohibition was violated.

We never present a product feature as a legal requirement. Where a capability maps to a statute, we frame it as readiness or defense; otherwise we present it simply as product value.