MeshLogic®
Home Scenarios Platform
Why attestation stopped working The seven questions Endpoint Tool Governance A policy that runs How it deploys Sovereign by deployment
Evidence Control effectiveness
Designed, operating, effective Insufficient as a result Frameworks and your own controls
How we fit
Start a discussion

Prove what your AI agents actually did.

MeshLogic governs what AI agents do at the operating system level, evaluates every action against your policy on the device, and seals the outcome into evidence that re-derives independently of the system that produced it.

Start a discussion How the proof works
Full capability detail and worked verification available under NDA
From board paper to running control
  • The board approves a policyA signed document, agreed in committee
  • The policy is ingestedRead, structured, and mapped to the controls it claims to satisfy
  • It becomes executable codeDeterministic rules, not prose open to interpretation
  • It deploys to every endpointSigned distribution, no rewrite, no per-device configuration
  • Effectiveness is measured where work happensEvery action evaluated, every decision recorded and sealed
  • The evidence flows back through the systemWhat is holding, what is not yet evidenced, and what to change
The next revision starts from what the evidence showed
SealedAttributed, sealed at the moment made, and independently re-derivable.
AWS Qualified Software AWS Qualified Software
Available in AWS Marketplace
AICPA SOC 2 for Service Organizations AICPA SOC 2 for Service Organizations SOC 2® Type 2 examination
All five trust services criteria
Sealed at the moment made
Attributed, and independently re-derivable
Continuous

Every action, everywhere, all of the time.

Thousands of people. Millions of agent actions. Each one evaluated against the policy that was approved, most of them unremarkable, and none of them waiting for a quarterly review to be looked at.

0actions observed in this window An estate of this size produces millions in a day
An action observed Within appetite, mapped to a control Outside it
The problem

Your organisation is running agents that take real actions.

They read files, run commands, call tools and move data, under a person's name and authority.

Security tools look for attackers. Compliance tools collect documents. Neither watches an authorised agent doing authorised-looking work.

A developer asks an assistant to clear a failing deployment. It reads a credentials file, opens a connection to a model provider, writes a copy of the config into a synced folder, and closes the ticket.

Every one of those actions was permitted. None of them was approved. Nothing recorded that any of it happened.

Three questions follow, and nothing you own answers them.

What did it actually do?
no record of the action itself
Who was it acting for?
a service account, and no further
Can you prove that to someone with no reason to trust you?
only our own word for it
Three answers MeshLogic changes
See how it answers them

This is not a prediction. It is the current position.

92%

of organisations that suffered an AI-related breach lacked proper AI access controls.

IBM and Ponemon Institute, Cost of a Data Breach Report 2026
68%

of breached organisations had no AI governance policy to manage AI or detect its unsanctioned use, up from 63% the year before.

IBM and Ponemon Institute, Cost of a Data Breach Report 2026
109:1

Machine identities, including AI agents, now outnumber human identities. Your identity governance covers the one.

Palo Alto Networks, 2026 Identity Security Landscape, 2,900+ security decision-makers

Agent use went up. Governance didn't keep up. Shadow AI went from one breach in five to nearly one in two.

Why MeshLogic

Three things that make this different

Starting with the one your board will test first.

A control you cannot demonstrate is a control you do not have.

A dashboard that reports green on absent evidence is reporting the absence of a finding, not the presence of a control. When the evidence is not there, MeshLogic reports insufficient evidence, per control, and no setting turns that into a pass.

Why we publish the failures
An audit log asks you to trust the vendor holding it. We designed ourselves out of that question.

Every governed action produces a receipt sealed into a public ledger operated independently of MeshLogic. A regulator, an auditor or an acquirer can verify it without taking our word for anything, and could still verify it if MeshLogic ceased to exist tomorrow.

How the anchoring works
No standard requires this yet. That is exactly why you want it before one does.

An agent works across several surfaces at once: a browser tab, a credentials file, a spawned process, a local tool server, a synced folder. Watching any one of them tells you part of the story. MeshLogic sits at the deepest level each platform allows, which is where all of those paths converge, and records whether a person or an agent acting on their behalf did it. No major regime yet names non-human identity as an accountable actor, and every one of them is under review.

How it works

Every capability, on one page.

Know the estate, detect what moves, identify who is acting, protect, comply, prove and remember. Each row is the enterprise position for that scope, and each one says plainly whether it is live, arming, or not yet measured.

Walk through the platform
MeshLogic console, enterprise posture overview
MeshLogic console. Rows that are not yet evidenced say so.

We put ourselves through the examination first.

MeshLogic has completed a SOC 2® Type 2 examination across all five trust services criteria, over a seven month observation period, by running its own operations on the accountability model it sells.

We did not write a policy claiming we govern AI agents. We governed them, in production, and had an auditor examine it for seven months.

What the evidence has to be

Four properties. Miss any one and the rest stops meaning anything.

01

Complete

Every action, not a sample pulled for review.

02

Attributed

Tied to the actor that took it, human or machine.

03

Sealed

Immutable once written, including to us.

04

Verifiable

Checkable by someone with no reason to trust us.

Mapped to the frameworks you answer to

International standards first, regional frameworks wherever you are regulated. Named control identifiers, not a logo wall, and where a control is not yet evidenced it is reported as insufficient.

ISO/IEC 42001InternationalDORAEuropean UnionISO/IEC 27001:2022InternationalAPRA CPS 234AustraliaSOC 2InternationalPrivacy Act APPsAustraliaAML/CTFMulti-jurisdictionAPRA CPS 230AustraliaACSC Essential EightAustralia ISO/IEC 42001InternationalDORAEuropean UnionISO/IEC 27001:2022InternationalAPRA CPS 234AustraliaSOC 2InternationalPrivacy Act APPsAustraliaAML/CTFMulti-jurisdictionAPRA CPS 230AustraliaACSC Essential EightAustralia
How the mapping works

Built to fit the stack you already have

MeshLogic is designed to sit alongside the tools you have invested in, not to displace them. Where those tools reach, we take their signal. Where they do not, we cover the ground ourselves.

Alongside your EDR

An EDR tells you whether the machine is compromised. We tell you what the AI agent did on it, for whom, and prove it. Two questions, one endpoint, both worth answering.

Alongside your DLP

Content inspection at scale across email, SaaS and data at rest belongs to a dedicated platform. We classify sensitive and credential material on the device, as part of governing what agents do with it.

Alongside your GRC platform

Your GRC platform can stay as the system of record for policy and attestation. We supply the endpoint evidence it was never able to collect, already mapped to control identifiers.

On overlapSome of what we do will overlap with what you already run. Treat it as optional coverage rather than duplication: turn our version off where an incumbent does the job well, on where there is a gap. The evidence chain is the same either way.
How we fit with each
Why now

Evidence cannot be backdated.

Everything before the day you start collecting it is a story you tell about yourself. Everything after is something you can prove. That line moves forward one day at a time, and it never moves back.

Agents already operating
No record you can prove
Today
Every action sealed and verifiable
Provable to anyone, years later

The agents are already there

Not a future scenario. Your people are already running tools that read files, execute commands and move data under their own credentials.

The rules are being written now

No major regime yet names non-human identity as an accountable actor, and every one of them is under review. The organisations that answer first will be the ones already holding the evidence.

You cannot start retroactively

A record can only be sealed at the moment it is created. Nothing collected before you began can be made verifiable afterwards, however good the intent.

The evidence you will be asked for in three years starts today.

Bring your control assertions and what is already deployed. We will show you which of them this evidence can carry, verify a record with your assurance team, and be straight about where your existing tools should stay in place.

Start a discussion Read the argument first
Scenarios

Five questions you will be asked. Answered with proof.

Each one is a question a regulator, a board or a court will eventually ask about an AI agent. Each is answered from the device, at the moment it happened, in a form anyone can re-derive.

See the scenariosHow they connect

Evidence covers every endpoint that carries the sensor. A device without it is a gap, and the record says so rather than hiding it.

Pick the question you are being asked
  1. Did anything read that file?A production export left in a shared folder for two hours
    01
  2. How did this happen, and when?An agent quietly changed an approved process
    02
  3. Is this an attack or a runaway?700 agents hit one internal API in 90 seconds
    03
  4. What is running that we never approved?A well-meaning employee's own local model
    04
  5. Did the policy actually work?The board wants effectiveness, not attestation
    05
SealedAttributed at the moment made, and independently re-derivable.
The five questions

What happens instead when the record already exists.

01 / 05
01 · Data breach or not
Illustrative scenario

"Did anything read that file?" answered in an afternoon, not a quarter.

A listed retailer. While debugging a checkout fault, an engineer exports a production customer table, 60,000 rows with names, addresses and partial card numbers, into a shared team folder. It sits there for two hours before anyone notices.

The question

Who opened it, and did any of the coding assistants, copilots or indexing agents on staff machines read it in? The notification clock is running.

What usually happens

The folder's access log knows about people with accounts. It was built before software started acting as people. So the honest answer is weeks of log requests, an assumption that nothing automated read it, and a notification made out of caution because nobody can say otherwise.

What happens instead with MeshLogic

One query across the fleet's sealed record: every process, human or non-human, that touched that file, on every endpoint, for the two hours it existed. Two reads, both by engineers on the fault. One coding agent tried to load the file to infer a schema and was prompted before it could; the engineer declined.

External counsel re-derives the same answer from the published hash. No threshold met. No notification.

Every file action captured on the deviceHuman and non-human identities attributedAgents prompted before ingestingRe-derivable by an outside party
Every endpoint answers2 h window
customers_prod.csv 2,310 endpoints answered 2 reads · 1 prompted and declined · 0 insufficient
Every dot reported. The answer is not "we found nothing". It is that each endpoint said what it did, including the one that tried.
See the record
14:02  file placed      r.tan · wks-0417
14:03  human read       r.tan · author
14:40  human read       s.iyer · on-call
15:12  agent prompted   nhi-7c21 → l.brooks
       load file for schema → declined
16:07  file removed     0 other endpoints reached
09-14  re-derived       external counsel · same answer
Sealedsha256:9f1c…e04a · chain intact
02 · Process drift
Illustrative scenario

The agent found a faster way. Eighteen months later, someone asked how this happened.

A finance team runs a reconciliation agent nightly. It works well. One night it stops calling the validation step because a cached result "looked the same". Nobody changed any code.

The question

Auditors find a class of unmatched transactions that started at some point in the past. When exactly did the process change, was it a person or the agent, and was the change approved?

What usually happens

Nothing was committed, so version control has nothing to show. The model provider's logs belong to the provider. Every tool in the stack was built to track changes people make, and this change was made by no one. "Sometime in Q1, we think" is the best anyone can do.

What happens instead with MeshLogic

The policy on the device says: an agent that skips or reorders a step in an approved process must stop and prompt the owner. At 01:17 on the night it drifts, it does. The owner is asleep, so the run is held, not silently allowed. In the morning she reviews the change, declines it, and the agent resumes the approved sequence.

Eighteen months on, the audit answer is one sealed event and every night since.

Approved processes as running controlsHold and prompt, not just allow or denyA named human owner for every agentEvidence that cannot be backdated
The night it driftedProcess integrity
fetch match enrich validate post APPROVED SEQUENCE · PROC-014 skipped 01:17 RUN HELD owner asleep · run waits 08:06 owner declined the change EVERY NIGHT SINCE 541
Caught in the air, not found later. The skip stopped the run at 01:17. The audit answer is one event, one owner, one decision.
See the record
01:17:42  deviation   step "validate_ledger" skipped
01:17:42  run held    owner m.reyes prompted
08:06:10  declined     resumed on approved sequence
since     541 nights   0 deviations · 0 insufficient
identity  nhi-3a90 · srv-fin-02 · TPM-rooted
Sealedsha256:4b77…c1d3 · chain intact
03 · Machine-speed incident
Illustrative scenario

Seven hundred agents hit one system in ninety seconds.

A professional services firm. A new orchestration template ships to staff laptops. A bug makes every instance retry against the same internal API at once, from 700 devices, each looking like an authorised user.

The question

Is this an attack, a runaway, or both? Which agents, whose machines, sharing what? And can it be stopped before the API falls over, without pulling the network for 700 people?

What usually happens

Four good teams, four consoles, four timelines. The API sees load, security sees 700 valid sessions, the network sees nothing wrong. Each tool is right about its own layer. None was built to see one agent template acting through 700 people at once.

What happens instead with MeshLogic

Each device already knows what is running on it: a non-human identity, linked to a human, using a specific tool. The fleet view collapses 700 events into one fact: same template, same tool call, same target. One policy change, simulated against the last 30 days first, moves that tool from observe to enforce. The barrage stops at the source. Every human keeps working.

Every agent enumerated, owned, linked to a personTool-level control per agentSimulate before enforcingSealed events into your SIEM
Stopped at the source90 s window
ledger/v2 ONE POLICY · post_entry observe → enforce · simulated 700 endpoints stopped calling. 0 people stopped working.
The lines stop at the devices, not at the network. Nobody lost a session, and the SIEM received it already attributed.
See the record
11:02:49  pattern    700 endpoints · 1 target · 1 tool
11:03:10  attributed  697 agents → 697 humans · 3 unresolved
11:04:02  simulated   30 d: 0 legitimate calls affected
11:04:19  enforced    697 ack in 12 s · 3 pending, offline
11:04:31  stopped     2,146 sealed events → SIEM
Sealedsha256:c02e…88f1 · chain intact
04 · Shadow AI, well intentioned
Illustrative scenario

He set up his own model to get ahead. Nobody had told him not to.

An insurer with a bring-your-own-device policy. A claims analyst who codes on weekends installs a local model and an agentic coding tool on his enrolled laptop, points it at the claims folder, and builds a script that drafts settlement letters in half the time. It runs offline. He is proud of it.

The question

Nothing crossed the network, so nothing was inspected. Health details from customer files went into a model nobody approved, on a device the company does not own. Is that happening elsewhere, and how do you find out without turning a good employee into a disciplinary case?

What usually happens

Browser, proxy and cloud controls do their job well for traffic that reaches them. This never did. The tool is invisible because it is local, so either nobody finds out, or someone does months later and the answer is a ban that pushes the next clever shortcut further underground.

What happens instead with MeshLogic

The day the tool first runs, it is enumerated as a new non-human identity on the device, linked to him, with no approved owner. When it reads the first claims file, the policy on the device classifies the read as sensitive and prompts him with the reason and a redacted alternative. He takes the redacted copy. The script still works.

Two weeks later it is reviewed, given an owner, and sanctioned for the whole team with the redaction built in.

Every new agent enumerated the day it appearsPolicy evaluated on the device, online or notLocal models covered, not only cloud APIsPrompting that changes behaviour
Offline, and still governedBYOD · enrolled
byod-0873 · enrolled · personal device no network local model no owner yet claims file SENSITIVE · health redacted copy accepted policy evaluated on the device 0 sensitive fields reached the model Two weeks later: owner assigned, sanctioned the shortcut survived · the exposure did not
He kept his tool. The data stayed put. Governance without policing, on a device that never touched the network.
See the record
08-19 21:13  new agent   nhi-91ab → j.park · owner none
      21:14  sensitive   claims/CL-448120.pdf · DATA-007
      21:14  prompted    redacted copy offered · on device
      21:14  proceeded   0 sensitive fields to model
08-20 08:02  joined chain  timestamped to the moment
09-02        owner        c.walsh · corroborated
Sealedsha256:71d0…2b9e · chain intact
05 · From board paper to running control
Illustrative scenario

The board approved an AI policy. Six months later they asked whether it worked.

A regulated entity. The board signs off an AI acceptable-use policy. The CISO is asked to report, twice a year, whether the policy is effective. Not whether it was published. Whether it held.

The question

Of the fourteen commitments in the policy, which are enforced on the devices staff use, which are only observed, which have never been tested, and can the board rely on a figure rather than trust an attestation?

What usually happens

A survey, a control library, a slide with green ticks. These were the right tools when controls changed quarterly. If a regulator asks for the evidence behind a tick, the honest answer is a signature and a screenshot.

What happens instead with MeshLogic

Each commitment becomes a control running on every endpoint. Before any is set to enforce, its effect is simulated against a month of real activity so the CISO sees who would be prompted and what would be blocked. The board paper reads directly from the sealed record: what was approved, whether it held, and which parts are not yet evidenced. That last column is printed, not hidden.

When the regulator asks, the entity hands over the hash and the regulator re-derives the report themselves.

Policy as a running controlSimulation before enforcementInsufficient reported, not hiddenA report the regulator can re-derive
Approved, and then measured182 days
board paper runs 9 held 3 prompted 2 not yet evidenced The regulator re-derived the same 14 nothing taken on trust · hollow tiles printed
The two hollow tiles are the point. A report that says where it cannot yet speak is the one a board can rely on.
See the record
03-04  approved     AI-AUP v2 · 14 commitments · board
03-11  simulated    each control vs 30 d telemetry
182 d  9 enforced   held on every endpoint, every day
182 d  3 prompted   1,912 prompts · 88% changed behaviour
182 d  2 insufficient  MDM rollout · 61 devices
09-01  re-derived   regulator · 0 controls weakened
Sealedsha256:e5a3…07cc · re-derived
Five of many

These are five of the questions we have been asked. They are not the list. The same record answers any question about what an agent or a person did on an endpoint, which is why none of these needs new capability to answer, only a different query against evidence that already exists.

  • Which agent touched the payroll export
  • Whether a contractor's assistant could reach the deal room
  • What changed the day the model was upgraded
  • Who approved the exception, and when it lapsed
  • Whether the control signed off in March still held in November
  • Which tools an agent can reach on a merged entity's fleet
The through-line

Five different questions. One way of answering them.

CONTROL

Set the guardrails

What agents and people are supposed to do, written as policy that runs on the device, and tried against real activity before it is switched on.

SEE

Know what actually happened

Every action on every endpoint that carries the sensor, attributed to a human or a non-human identity with a named owner. Online, offline, in the browser or on the machine. Where the sensor is absent, the record says so.

INTERVENE

Step in at the moment

Observe, prompt, hold or enforce, per agent and per tool. Change behaviour where you can; stop it where you must. Never after the fact.

PROVE

Hand over the evidence

Sealed when made, chained, and re-derivable by anyone you give the hash to. Including the honest answer "not yet evidenced".

Point-in-time attestation assumed the world stayed still between audits. Agents do not. The line moves forward one day at a time, and the evidence you will be asked for in three years starts today.

Start a discussion

Which of these is closest to the question you are being asked?

Bring the scenario. We will show you what the sealed record looks like for it, on your fleet, in shadow mode, before anything is enforced.

Start a discussionSee the platform

Scenarios are illustrative composites. Names, timestamps and figures are example values, not client data.

Platform

Your policy is a document. It should be a running control.

A board approves a policy. What happens next decides whether it stays a document or becomes a control.

The same policy, two paths

The left is how it works in most organisations today, and there is nothing wrong with any single step in it. The gap is what happens after the acknowledgement.

Today
  1. The board approves a strategic policySigned off in committee, with the intent agreed.
  2. Management translates it downOperational and tactical instructions written from the strategic text.
  3. It is circulated to staffRead and acknowledged. The acknowledgement is the evidence.
  4. Next review at the following board meetingBetween those two points, nothing reports back.
Effectiveness is inferred from the fact that nobody raised anything.
With MeshLogic
  1. The board approves, knowing what it will meanMeshLogic shows what the change implies across the estate before it is signed.
  2. The document is ingested and translatedOperational and tactical controls are generated from the strategic text, for human review and endorsement. A person still decides.
  3. Endorsed controls reach every endpointDistributed automatically, so what was approved is what runs.
  4. People and agents both acknowledge, and both are measuredIntent is acknowledged as before. Then every action is evaluated against the live policy and sealed as signed evidence of what actually happened.
  5. Effectiveness comes back as dataWhich clauses are holding, which are not, and which are not yet evidenced. The next revision starts there.
and the loop runs again
Across applications, tools and AIThe same path applies whether the actor is a person, an application or an autonomous agent. You can prompt first and enforce later, at the operating system level, instead of finding out at the next review that you never knew.
The problem

Attestation was built for human pace

Almost every control framework in use today answers the question "is this control working?" by asking someone. That was a reasonable compromise when controls operated at human pace.

That compromise has run out.

It is sampled

A control that operated thousands of times is tested against a handful of cases pulled for review. Sampling gives you a statistical argument about a population. It does not tell you what happened in the cases nobody looked at, and it was never designed to.

It is self-reported

The person confirming the control held is usually the person accountable for it holding. That is not dishonesty, it is structure. An attestation is an opinion offered by an interested party, and everyone in the chain knows it, which is why so much assurance effort goes into checking the checkers.

It is point in time

A control is examined on one date and assumed to have held for the period either side of it. The gap between the test and the reality is invisible by construction, and it is exactly where incidents are found afterwards.

Why this stopped being tolerableAn autonomous agent can take more actions before lunch than a team takes in a quarter, and there is no person at the end of it to attest. The control population has moved to machine pace while the method of measuring it has not.
Why MeshLogic

The platform is organised around the questions you get asked

Not around features. Each area exists to answer one question a board, an auditor or a regulator will eventually put to you.

The order is the argumentWhat exists, who and what can reach it, what data is involved, what we do about it, what is happening, whether that met the standard, whether we can prove it, and why we decided that in the first place. Most tooling answers two or three and leaves you reconciling the rest across systems that disagree.

Endpoint Tool Governance

The category we had to name, because nothing existed for it.

Every AI agent your people run reaches for a tool: a file, a command, a model endpoint, a local tool server.

Endpoint Tool Governance is the discipline of deciding which of those reaches are permitted, enforcing that where the reach happens, and keeping proof of the decision.

Eight capability areas make it up. Together they are what a serious buyer means when they ask whether you can govern agentic AI on an endpoint.

01

Discovery and visibility

Which AI assistants, extensions, tool servers and local models are running, and whether each is approved, tolerated or unknown.

02

Access control

Which identity may reach which tool, and which data an agent may reach on its behalf. Per identity, per tool, not per machine.

03

Runtime protection

Policy evaluated on the device and enforced as the action happens, without a round trip to a service that might be unreachable.

04

Audit and behaviour

Tool calls traced, patterns correlated across identity, data and device, and the whole trail written where it cannot be edited afterwards.

05

Policy management

Authored centrally, versioned, staged, scoped hierarchically, with an exception workflow that records an exception as recorded rather than as enforced.

06

Platform integration

Signal out to the systems you already run, and identity in from the ones that hold it. MeshLogic is not asking to be your only console.

07

Compliance and deployment

Immutable retention, evidence export, key management, and staged rollout through the management tooling already on your fleet.

08

Acceptable use

Policy applied to what an agent does with a tool, so an acceptable-use standard becomes something enforced rather than something signed.

Endpoint Tool Governance in the MeshLogic console
One policy surface for applications, tool servers and skills. Verdicts inherit down the hierarchy and a child can only tighten.
Why the whole set mattersDiscovery without control is an inventory. Control without audit is unprovable. Audit without immutability is a log someone can edit. The eight are not a feature list, they are the minimum set that makes the claim survive scrutiny, and MeshLogic was built to hold all of them rather than to score well on some.

Two questions that sit outside the scope

Assessments of agentic AI concentrate on what an agent does with data in motion.

Two questions usually fall outside that boundary. Where does sensitive data already live, and how is it classified before an agent reaches for it?

And why was this decision permitted at all?

Plenty of organisations answer the first, through a data security programme that runs separately from anything agentic. Far fewer have an owner for the second.

MeshLogic was not built to pass an assessment.

It was built to a thesis, and passes assessments as a by-product.

What replaces it: a policy that runs, and reports back

Six stages, and the last one feeds the first. Stage 05 is where the attestation above is replaced by measurement.

StageWhat happensWhat changes
01The board approves a policyA signed document agreed in committee. It is the last artefact everyone is looking at together.
02The policy is ingestedRead, structured, and mapped to the control identifiers it claims to satisfy. The mapping is explicit, so a clause can be traced to the evidence that will test it.
03It becomes executable codeDeterministic rules rather than prose open to interpretation. Two people reading the same clause can disagree. Two endpoints evaluating the same rule cannot.
04It deploys to every endpointSigned distribution, no rewrite per platform, no per-device configuration. The policy that was approved is the policy that runs.
05Effectiveness is measured where the work happensEvery action is evaluated against the live policy version, and every decision is recorded and sealed. Not sampled, not self-attested.
06The evidence flows back through the systemWhich clauses are holding, which are not, and which are not yet evidenced. Where a control is falling short of the intent behind it, MeshLogic proposes the change and a person decides. The next revision starts from that instead of from opinion.
The learning loop is the pointA policy that is never measured cannot improve. A policy that is measured by the people it governs improves slowly and in one direction. Closing the loop with evidence the board can verify independently is what turns a governance document into a control that gets better each cycle.

An executive can only escalate what is recorded, and a board can only rely on what reaches it.

How it deploys

Three operating principles that matter more than any feature.

01

Through your MDM

No new management plane. Signed packages, delivered by the tooling you already run.

02

Observe first

MeshLogic arms when you are ready. Nothing is enforced without you asking for it.

03

Actions, not words

Behaviour is judged by what an identity does: which tools it reaches for, what it touches, and whether that matches the pattern it has established. Prompt text is not inspected and there is no keystroke capture.

Sovereign by deployment, not by configuration

Data residency is usually sold as a constraint you negotiate down. We built it as a property of the architecture instead. The whole platform stands up inside the jurisdiction you nominate: storage, processing, key management and the evidence anchor.

A pooled platform

One system holding everyone, with data tagged by territory. Separation is a claim that has to be tested, and an assessor will ask you to prove a negative.

A MeshLogic instance

The platform deployed once per jurisdiction, self-contained. Data does not leave, because there is nowhere for it to go. A new region is a deployment, not a re-architecture.

The loop closes with the board, not with a log file.

What was approved, whether it held, and which parts of it are not yet evidenced. That is the report we are built to produce.

How the proof works Start a discussion
Evidence

An audit log asks you to trust the vendor.

We designed ourselves out of that question. Every record MeshLogic produces is sealed at the moment it is made, attributed to the actor that caused it, and re-derivable from the receipt we hand you, against a trust store held outside the system that produced it.

Inside MeshLogic Independent of MeshLogic Action Hash period root Timestamp authority Public transparency log Anyone holding a receipt can recompute the chain and check it against the log
01

Hash

Every governed action is hashed into a content hash.

02

Seal

Written to storage under a compliance lock. No administrator, including ours, can delete it or shorten its retention.

03

Anchor

Each period is anchored twice outside MeshLogic: a trusted timestamp authority, and a public transparency log.

Why the anchor sits outsideAn anchor we could edit would not be an anchor, so it sits in a ledger operated independently of MeshLogic. And a failed check is not a dead end: it establishes that a record changed and which period it changed in, which means an attempt to hide something becomes a finding of its own.

Not a blockchain. A hash chain with trusted timestamping, anchored in a public transparency log. That is the accurate description, and for anyone who knows the difference it is the more credible one.

Why MeshLogic

You have years of history. Here is where you actually stand.

Most organisations we talk to have a decade of logs already. It is worth being straight about what that means, because the honest answer is better than it first sounds.

Any log store no change detected
Your existing logs were never provableNo log store, ours or anyone else's, can show that its own history was not edited.
Sealed and anchored verification failed
Everything from the day you start isThe clock begins at the first sealed event, not when a rollout finishes.
And it outlives the contractThe ledger is public and independently operated, so what you collected stays verifiable if you leave us, if we are acquired, or if we cease to exist. Evidence you cannot take with you is not really yours.

Verified, not asserted

Every signed leaf MeshLogic has produced re-derives against a trust store held outside the system that made it, with zero mismatches. That is not a claim we make about ourselves. It is a check we can repeat in front of you, from a receipt we hand you.

If your assurance team wants to do exactly that, we will walk them through recomputing a chain from a receipt in a session. It is the most useful hour you can spend evaluating us.

Why now

The line moves forward one day at a time.

A record can only be sealed at the moment it is made. So the evidence you will be asked for in three years is the evidence that starts being collected today, and every day you wait is a day that can never be added later.

Bring a receipt to your own auditor.

That is the entire proposition. If it does not hold up without us defending it, we have not built what we say we built.

Start a discussion Control effectiveness
Control effectiveness

An audit opinion proves a control ran. It does not prove it worked.

A Type 2 examination samples whether a control operated over a period. It is a good question, and it is not the one your board asked. MeshLogic measures whether the behaviour a control was designed to constrain actually changed, and maps that evidence to the control identifiers you answer to.

Where a control is carried, you see exactly what carries it. Where nothing does, it scores INSUFFICIENT instead of green.

Read this firstNo major information security or operational risk regime textually mandates per-action, who-did-what attribution, and none names AI or non-human identity as an attributable subject. That gap is the reason MeshLogic exists. It also means we say the platform exceeds the baseline rather than satisfies a requirement, because no such requirement exists yet.
The problem

Three questions, and the category answers two

Every control sits at one of three levels. Most of the market stops at the second.

DesignedApproved, written down, and true of nothing yet
OperatingSampled and signed off. This is what an audit opinion covers
EffectiveEvery action evaluated, attributed and sealed.Only MeshLogic does this.
Approved. And true of nothing yet.
200 governed actions over the period
a governed action, unexaminedin the samplenever looked ata personan agent acting for oneinsufficientoutside appetite

Most dashboards cannot return a bad result

A platform that passes a control on absent evidence is reporting the absence of a finding, not the presence of a control. Those are different things, and the difference is where regulatory failures live.

If nothing on the endpoint ever produced a signal for a given control, a scoring engine has two options. It can infer that no signal means no problem, which is how most of them behave. Or it can say that it cannot evidence the control, which is what is actually true.

Why MeshLogic

Insufficient is a first-class result

Not a gap in the product. A property of it.

It is architectural

Insufficient evidence is how the scoring engine behaves when a control has no live evidence source. It is not a setting, a threshold or a reporting preference, and there is no configuration that turns it into a pass.

It is per control

Across every framework we map, each control carries its own position and the evidence sitting behind it. Where a control is not yet evidenced we say so, and what it would take to close it. That line moves as more of your estate is connected. You get the shape of your coverage, not a single number that hides it.

It is uncomfortable on purpose

The platform will tell a board that most of its operational resilience controls are not yet evidenced, whatever the source. That is true, it is useful, and no vendor whose dashboard always goes green will tell them.

What that looks like in practice

The same controls, cut by office and by the regulation each one answers to. Measured per office, blank where an office is not reporting, and never blended into a single number that hides both.

Control effectiveness by office and regulation in the MeshLogic console
Green is effective, amber is degraded, red is ineffective, and a dash means no evidence rather than a pass.

Every framework you answer to, and the controls only you answer for

Effectiveness is only useful when it lands on the identifiers someone else is going to name. MeshLogic maps across the major international standards, the regional regimes, and the sector frameworks that apply where you are regulated. It also does something none of those cover.

International standards

The management-system and information-security standards your assurance programme is already built around, mapped to named control identifiers rather than to a category.

Regional and sector regimes

The prudential, financial-services, privacy and national frameworks that apply where you operate. MeshLogic deploys as a self-contained instance per jurisdiction, so answering to several at once does not mean running several products.

Your own controls

The ones no framework names. Internal standards, acceptable use, the appetite your board actually set. The same measurement applies, and effectiveness is reported against your policy rather than somebody else's clause.

The part usually left outMost organisations have more internal controls than regulated ones, and none of them are measured. A framework tells you what an assessor will ask. It does not tell you whether the thing your board asked for is happening.

Why we hold ourselves to this too

We are a company whose product claim is that organisations assert controls they cannot demonstrate. A homepage that overstated would refute the product. So the same standard runs through everything here: what we can evidence, we say; what we cannot, we say that too; and the detail sits in a versioned technical brief you can hold us to rather than in marketing copy that moves.

This is not a moral position. It is the only position consistent with what we sell.

Bring your own control list.

Name the assertions your board is asking about. We will show you which ones we can evidence today, which ones score INSUFFICIENT, and which of them an audit opinion was never going to answer.

Start a discussion How the proof works
Australia · APRA-regulated entities

CPS 234 and CPS 230, evidenced rather than attested.

For APRA-regulated entities and their boards. MeshLogic maps evidence to named paragraphs of CPS 234 and to CPS 230 incident management. Where a control is not yet evidenced, this page says so.

The framing we hold toNeither CPS 234 nor CPS 230 textually mandates per-action, who-did-what attribution, and neither names AI or non-human identity as an attributable subject. MeshLogic enables, accelerates and exceeds the baseline. We do not claim the standard requires per-action attribution, because it does not. We cite the standards themselves, not the Prudential Practice Guides, which are non-binding.
Why MeshLogic

CPS 234, Information Security

Our strongest mapping. Built, not planned, and covering paragraphs 15 to 25.

ParagraphsObligationEvidence source
15, 17, 19Information security capability, control implementation, identity and privilegeProcess-execution telemetry, privilege-change and identity-event categories
16Information security policy frameworkPolicy events and policy-violation categories
18Control testing and configuration changeConfiguration-change events, severity-banded DLP findings
20, 21, 23Detection, response and testingThreat-detection and behavioural-alert telemetry
22Audit trailData-plane transfer events. Under-covered: login-based audit evidence comes from a separate identity producer that does not yet reach the same telemetry stream.
24, 25Systematic testing and internal auditAI interaction telemetry

CPS 230, Operational Risk Management

We are deliberately more modest here than the market noise would suggest. CPS 230 is an operational resilience standard, and most of it is not evidenced by endpoint security telemetry.

ControlPosition
CPS230-4, Incident managementEvidenced Threat-detection events, 132,000 live events on the stream
Operational risk frameworkInsufficient
Business continuityInsufficient
Service provider managementInsufficient
IT resilience and recoveryInsufficient
Testing and assuranceInsufficient
Where MeshLogic fits in a CPS 230 programmeIncident management, and third party and AI tool risk on your endpoints. We do not evidence your business continuity arrangements and we will not claim to. If a vendor tells you their endpoint agent evidences CPS 230 broadly, ask them which paragraph.

An Australian instance, not an Australian option

MeshLogic deploys as a self-contained regional instance. For APRA-regulated entities that means the entire platform runs in Australia: storage, processing, key management and the evidence anchor, with disaster recovery in a second Australian region. There is no global pool holding your data with a territory flag against it.

If you are an Australian entity with operations offshore, the same architecture works in the other direction. Each jurisdiction gets its own instance of the same platform, which is a cleaner answer to a cross-border data question than any configuration setting.

Bring the control assertions your board is asking about.

We will show you which ones we can evidence today, and which ones score INSUFFICIENT.

Start a discussion All frameworks
How we fit

MeshLogic is built to integrate with the stack you already run.

You have spent years and budget on endpoint security, data protection and governance tooling. MeshLogic is designed to take signal from those investments and add the layer none of them was built to provide.

What an autonomous agent did, under whose authority, provable to someone outside your organisation.

Why MeshLogic

Alongside your EDR

Different question, same endpoint.

An EDR asks whether this machine is compromised. We ask what the agent on it did, for whom, and whether you can demonstrate it.

AreaHow it works together
Threat preventionMalware, ransomware and intrusion response stay with your EDR. We take its signal where it is useful and do not attempt to duplicate it.
Agent activityAttribution of a file write, a process spawn or a tool call to the specific agent that performed it, and to the identity it acted under. This is the layer MeshLogic brings.
OverlapOptional coverageProcess and file telemetry exists in both. Ours is oriented to governance rather than threat, and can be scoped down where your EDR already covers the ground.

Alongside your data protection platform

Mature content inspection across mail flow, SaaS and data at rest is a category of its own, with taxonomies tuned over years. Where one is deployed we take its signal rather than run the same scan twice.

What we classify is different: sensitive and credential material on the device, at the moment an agent reaches for it, as part of governing that action.

AreaHow it works together
Enterprise content inspectionMail flow and SaaS coverage sit naturally with a dedicated platform, and we read from it where it is there.
Agent-driven data movementWhere an autonomous agent reads or moves material on the device, we govern that action and record the decision against your policy. This is the layer MeshLogic brings.
OverlapOptional coverageOn-device classification exists in both. Ours is tied to the action that triggered it, so it answers what an agent was reaching for rather than what sits in a store. Where endpoint coverage is thin or absent, it can carry the ground on its own.

Alongside your GRC platform

Your GRC platform can stay as the system of record for policy, attestation and the control register, or you can run that register in MeshLogic. Either way the register was never the hard part.

The hard part is that nothing has been feeding it evidence from where the work actually happens.

AreaHow it works together
Policy and attestationAuthoring, workflow and sign-off stay where they are. We do not ask you to move them.
Evidence supplyEndpoint evidence, mapped to control identifiers and sealed, so a control score is derived from what happened rather than from what someone attested. This is the layer MeshLogic brings.
OverlapOptional coverageMeshLogic maps evidence to control identifiers itself, across international standards, regional regimes and your own internal controls. Where no GRC platform is in place, or one is being replaced, that mapping stands on its own.

Alongside browser-level AI monitoring

Tools that discover AI use and prompt people inside the browser are solving a different problem to ours today, and the two sit well together.

They watch the person

Prompt content at submit time, and the behaviour of someone typing into a chat box. If your primary concern is employees pasting customer data into a web chat, that is the right layer for it.

We watch the agent

A command line agent, a local tool server, a file written to disk, a process spawned by an autonomous coding agent. A browser tool sees what happens in the tab. What it cannot see is the same agent acting outside it, which is where the actions with consequences tend to land.

Why the evidence layer belongs with usBetween the two, the gap narrows considerably. The reason MeshLogic holds the record is the strength of the evidence rather than the breadth of it: a monitoring tool produces a log, and we produce a sealed, attributed record that re-derives independently of the system that made it.

Tell us what is already deployed.

The first conversation is usually about what you have, what it evidences today, and where the gaps sit. We will tell you which ones we can close and which ones your existing tools should.

Start a discussion Control effectiveness
Contact

Tell us what you need evidenced.

The most useful first message names the control assertions your board is asking about, what is already deployed, and roughly how many endpoints. That is enough for a first conversation.

Send us a message

Add a work email, a company and a message, and we will have enough to reply usefully.

This opens your own mail client with the message composed. Nothing is submitted to a third party, and there is no tracking on this form.

Get in touch

We would rather you tested the claims than took them. Bring a control list and we will show you what the evidence carries and what scores insufficient.

Sales and evaluationsales@meshlogic.ai
Existing deploymentssupport@meshlogic.ai
Where we areSydney, Australia. Deployments run in the jurisdiction you nominate.

What happens after you send it

Three steps, and none of them is a discovery call about your budget.

A reply from a person

Not a queue and not a sequence of nurture emails. If we are not the right fit for what you described, we will say so in the first reply.

Your control list, not our feature list

You name the assertions your board is asking about. We show you which ones the evidence carries today and which score insufficient.

The technical brief, under NDA

Versioned, and covering platform support, the interception model, the policy language and worked verification of the evidence chain.

What we do with what you sendWe use it to answer you. It is not added to a marketing list, not sold, and not passed to a third party. If you would rather start under an NDA before describing your estate, say so in the message and we will send one first.
Partnership

Working with MeshLogic.

We work with regulated enterprises deploying MeshLogic across their estate, with advisory and assurance firms who need evidence their clients can rely on, and with technology partners whose platforms consume or supply governance signal.

Why MeshLogic

What you can verify before you commit

We would rather you tested the claims than took them.

  • The platform runs continuously in production against the production cloud backend. We run it on ourselves, every day, before we ask anyone else to.
  • The evidence re-derives independently. Every signed leaf MeshLogic has produced re-derives against a trust store held outside the system that made it, with zero mismatches. Bring a receipt to your own assurance team and we will recompute it in front of them.
  • A five-criteria SOC 2® Type 2 examination has been completed across a seven month observation period, by running our own operations on the accountability model we sell.
  • The full chain runs, end to end, from a user action through to a sealed provenance entry anchored outside MeshLogic. The technical brief walks through every step.
  • Enforcement is armed only when you choose. MeshLogic deploys in observe mode. Nothing is enforced without you asking for it.

How an engagement starts

Your control assertions, not our feature list

You name the assertions your board is asking about. We show you which our evidence can carry, and which will score insufficient against your current estate.

A 30 day deployment in observe mode

Delivered through your existing MDM to a nominated set of endpoints. Success is defined up front, and the output is the evidence itself rather than a slide.

A technical brief under NDA

Versioned, and covering platform support, the interception model, the policy language and worked verification of the evidence chain.

Start a partnership discussion.

Tell us what is already deployed, your endpoint count, and the control assertions your board is asking about. That is enough for a first conversation.

Get in touch Control effectiveness

Cookies and tracking

This site sets no cookies, runs no analytics in your browser, and loads no third-party trackers.

Visit counts are measured from server logs, which never leave our hosting and cannot identify you.

The contact form composes a message in your own mail client. Nothing is submitted to a third party.

Fonts are served by Google Fonts, which receives your IP address as part of that request. Everything else is served from this domain.

MeshLogic®

Govern what AI agents do on your endpoints.Prove it to anyone, without asking them to trust us.

Platform

  • Scenarios
  • Coverage and interception
  • The evidence chain
  • Control effectiveness

Company

  • How we fit
  • Partnership

Legal

  • Privacy Policy
  • Terms of Service
  • Security disclosure
© 2026 MeshLogic®. Mesh Logic Pty Ltd, ABN 27 686 743 046. Sydney, NSW, Australia. SOC 2 is a registered trademark of the American Institute of Certified Public Accountants.