Verify · Assess · Enforce · Attest

The independent authority for enterprise AI.

You set the rules. Lokorium enforces what the AI is allowed to do, on every action, and holds the proof of what it did.

Lokorium does not build AI. It sits above whatever AI you use and controls what it is allowed to do, enforcing your rules wherever the action lands and keeping the proof.

Identity and tokens control what the AI can reach. Lokorium controls what it does with it.

The problem
01 / 10

The AI can act. Letting it is the hard part.

Enterprise AI is ready to do real work. Move money, change records, act on customers, touch the systems that matter. The capability is here.

What’s missing is control. Not whether the AI is clever enough, but whether the business can prove what it’s allowed to do, stop the things it isn’t, and show a regulator exactly what happened. Without that, the safe answer is no. So the industries with the most to gain, the regulated ones, keep the most powerful tool of the decade switched off.

Every regulated AI project lands in one of three places

Most

Blocked

Risk and compliance said no. The project is dead.

Some

Too scared

No one will put their name to a yes. So it stalls.

A few

Risking it

Live on real data, exposed. One wrong action is a breach, a fine, a headline.

That’s the gap Lokorium closes. Not a smarter model. The authority that lets you finally say yes.

Verify · Element 01
02 / 10

The command is the command.

The instruction is captured and reduced to one exact description of what it will do. What executes must match it. Anything altered on the way, or arriving by another route, fails here.

The artifact is the execution permit. One signed, bounded, expiring permit describes one consequence, in eight parts. Change the target, amount, recipient, data or expiry and the permit no longer matches.

Execution permit · illustrativevalid

01 · Who

agent id · signed session

02 · Why

stated business intent

03 · What

exact action, one consequence

04 · Where

named target system

05 · Limits

amount · scope · rate

06 · When

valid from · valid until

07 · Freshness

issued at · nonce

08 · Proof

signature · rule hash

permit 0xB204…7A · sig 3F9C…D1Bound
Assess · Element 02
03 / 10

Inside your rules, or not at all.

The command is weighed against the boundary the business set. That is the go or no go, and it can come back either way. This is the check a risk officer is buying: their rules, applied, before anything happens.

Others can assess. What makes Lokorium an authority rather than an opinion is what happens next, at the point of action, before the point of consequence.

01 · Weighed against

Its data

what may be read, and what may never leave

02 · Weighed against

Its policy

limits, thresholds and who may authorise them

03 · Weighed against

Its regulatory limits

the rules the business already answers to

The go or no go · illustrativeit comes back either way
  • Refund £180 to customer 8842Within refund limitGo
  • Refund £4,000 to customer 8842Over refund limitNo go
  • Email the full customer table to an outside addressBreaks data policyNo go

Illustrative · the same command at two amounts, then a different boundary entirely

Enforce · Element 03
04 / 10

No permit, no action.

A decision that cannot be enforced is advice. The decision is applied where the consequence happens, across every vendor, not just at one cloud's gateway. The target will not act without valid signed authority bound to that exact command. A refusal is not a warning. It does not run.

Honest note on altitude: enforcement is strongest at target native deployment. Where the target is instrumented to check the permit, the refusal holds. Where it is not, we’ll tell you plainly what the enforcement rests on, per workflow.

Without LokoriumBypass reaches target
AGENTintentCLOUD GATEWAYsays noANOTHER ROUTEdifferent credentialblocked at gatewayno check at consequenceTARGETaccepts

Illustrative · scroll to follow the full path

With LokoriumBypass refused at target
AGENTintentCLOUD GATEWAYsays noANOTHER ROUTEdifferent credentialblocked at gatewayLOKORIUMcheck permit at targetno permitTARGETrefuses

Illustrative · scroll to follow the full path

Attest · Element 04
05 / 10

Proof you hold, not proof you borrow.

Attest seals a cryptographic receipt of exactly what was decided and done. When a regulator or a board asks how you know, the answer is a record the business holds, spanning every vendor. Not the cloud’s logs. Not the model vendor’s logs. Both are interested parties.

Two artifacts. A chain of five linked records per request. And a ladder that grades the evidence honestly, because a log is not proof.

Evidence chain · illustrativefive linked records
  1. 01

    Proposal

    the intended action

  2. 02

    Policy decision

    rule matched

  3. 03

    Signed authority

    the permit

  4. 04

    Execution gate

    target check result

  5. 05

    Outcome receipt

    what actually happened

Illustrative · records signed and chained

Evidence ladder

A log is not proof. Not all evidence is equal.

The chain is graded. A decision log is the floor. A corroborated outcome, matched against the customer’s own system of record, is the ceiling. We do not pretend a log is proof. We aim, per workflow, for the highest rung the target and the estate allow.

  1. L4
    Corroborated outcome
    the outcome receipt matched to the customer’s own system of record or telemetry.
  2. L3
    Signed outcome receipt
    the target’s confirmation, signed and held by the business.
  3. L2
    Execution gate result
    the target either accepted the permit or refused, with reason.
  4. L1
    Policy decision
    the rule that matched, or the reason none did.
  5. L0
    Decision log
    a proposal was received. Not proof of anything on its own.

Illustrative · graded evidence, per workflow

A go or no go, illustrated
06 / 10

An action is attempted. A permit is checked at the target. It is allowed or refused. A receipt is written.

The panel below is a concept, not a live product demo. Two example sessions: a legitimate request, then a bypass that tries another route and dies at the target because it has no valid permit.

Session0xB204·idleillustrative

A legitimate request

  • 01ingestsupport conversation, signed session
  • 02readrefund request, £148.00, account 4471
  • 03intentissue refund via billing system
  • 04checkconsent on file · daily cap not reached
Allowed with permitLokorium decision. Rule set by the business: refunds under £500 are allowed on accounts with a signed customer consent on file, subject to a daily cap.

A permit is issued, bound to this action. The target accepts it and executes.

receipt 2D91…E5 · held by the businesssealed
The distinction that matters
07 / 10

Permission asks who. Lokorium asks whether.

Most tools in this space answer one question: can this agent act as this user. That is access. It is necessary, and it is not enough.

Access asks

Who is acting?

Can this agent act as this user. Necessary, and not enough.

Lokorium asks

Is this allowed?

Is this action, at this value, for this purpose, allowed by the rules of the business.

The gap, in one example · illustrative

A support agent may be authorised to issue refunds. Authorised, and still able to issue a refund of four thousand pounds when the rule says two hundred.

Permission says yes.The business should say no.

Lokorium asks the question permission cannot: is this action, right now, allowed by the rules of the business. That is the difference between an AI that has access and an AI you can actually trust with the work.

Success is not everything blocked. It is the right things through, the wrong things caught, and proof of every call.

Why independent
08 / 10
Point 01 · Independence

Position, not guarantee

The referee can’t also be a player.

Three parties have a stake in what your AI does: the company that built the model, the cloud it runs on, and the AI itself. None of them can be the impartial record of whether it behaved.

Lokorium has no model to sell and no platform to defend. It is the one part of the stack whose only job is to hold the line and hold the proof. When your regulator asks what your AI did and why, the answer shouldn’t come from the same company that sold you the AI.

That independence isn’t a feature. It’s the whole point. It is the structural position we design toward. Structural, and intended. Not a stamped guarantee.

Point 02 · Boundary

Enforcement at the consequence, not at one cloud’s gateway.

Every system in the business is reached by paths that never pass through one vendor’s edge. So the thing that must refuse an action is the system it would affect. Lokorium is designed to sit at that point, across every vendor the business uses.

Point 03 · Evidence

A graded evidence chain you hold, not each vendor’s word.

When a regulator asks how you know, the answer is a chain the business holds, spanning every vendor. Not the cloud’s logs. Not the model vendor’s logs. Both are interested parties. The chain is graded, from a decision log up to an outcome corroborated against the customer’s own system of record.

Who it is for
09 / 10

Built for the businesses that can’t afford to guess.

Lokorium starts where control is not optional: regulated enterprise. Financial services, insurance, healthcare, legal, the public sector. The places where the upside of AI is largest and the cost of a wrong action is a headline, a fine, or a licence. For each sector, the one action that would be career ending if the AI got it wrong.

Financial services
FCA scope. Client facing workflows.

Career ending

Moving customer funds or data outside a named, current authority.

Legal
Regulated advice and matter management.

Career ending

Filing or disclosing without a partner sign off, or breaching legal privilege.

Healthcare
Patient data, clinical decision support.

Career ending

Reading, writing to or acting on the wrong patient record.

Insurance
Underwriting, claims, complaints handling.

Career ending

Paying, or refusing, a claim outside underwriting authority.

Public sector
Casework, benefits, citizen services.

Career ending

Issuing a case decision without the delegated authority to make it.

The sequence
10 / 10

Prove it on data. Then it moves into the physical world.

We’re establishing the authority where the rules already exist, so that when AI moves into the world, the authority is already trusted.

Today

Data

Govern what confidential enterprise data is allowed to reach AI, and what AI is allowed to do with your systems and records. This is where control is needed first, and where Lokorium earns its authority.

Next

Agents

As agents take on real tool use, the same authority governs every action they take across your business.

The horizon

Embodied

The same independent authority, deciding what a machine is allowed to do before it acts in the physical world. A far larger opening, earned only once the ground is proven.

A plain exampleIllustrative
Allowed

Bring an adult a glass of water.

Permit matches. Target accepts.

Refused

Bring a child a glass of alcohol.

No matching permit. Target refuses.

Software today, or a robot arm tomorrow. The question is the same in every era: is this allowed to happen, before it happens.

A horizon, not today’s product. Today Lokorium works on the first of the three.

Design partner
— / partner

Being built with the businesses that need it most.

Lokorium is being shaped alongside regulated enterprises who are moving on AI now and want the guardrails in place as they go, not bolted on after something breaks.

Early partners help define the rules the market will run on, and get to accelerate into the things their competitors cannot safely touch yet.

Get in touch
— / close

Unlock enterprise AI, safely.

The capability is here. The control is what’s been missing. Lokorium is the independent authority that lets regulated business move, on every action, with proof of every one.

Tell us where you are stuck, or where you have gone live and cannot yet prove what the AI is allowed to do. We will come back with what a briefing would cover for your workflow.

Direct email: info@lokorium.com