Quox for enterprise · self-hosted
Run AI your auditors can check.
Quox is the self-hosted evidence layer for AI agents: every action signed, policy-gated and sealed into a tamper-evident chain on infrastructure you control.

In plain words
What it is, where it lives, when to reach for it
- What is it
- The QuoxCORE platform plus the enterprise plugins, deployed for a whole organisation on servers you own.
- Where do I use it
- On your own infrastructure, including disconnected estates; every team’s agents run through the same instance.
- When would I use it
- When more than one team runs agents and an auditor will eventually ask for the record.
- How do I use it
- Run
curl -fsSL https://get.quox.ai | shto stand up the platform, then talk to us about the enterprise plugins.
QuoxCORE is the free, self-hosted platform underneath this. What is QuoxCORE
Why Quox
Most platforms ask for trust. Quox hands you the receipts.
Break one record and the whole chain says so. When the review comes, you hand over proof, not promises. The core is source-available.
Four open protocols, specified and implemented, turn every agent action into verifiable evidence. Your auditor checks the chain on their own machine, offline, with no Quox account and no call home. You do not trust the agent, you check it.
All 4 are live IETF Internet-Drafts. No standards body has reviewed or endorsed them.
The VOLT and WARD protocols and the evidence API are core. The dedicated ledger and receipt views, and the per-turn decision record, are the Decision Evidence enterprise add-on at $599/yr. See Decision Evidence →
Live demonstration
Try to break the audit trail.
This is the chain of custody behind every governed action: envelopes signed, gates decided, entries hashed and sealed. Watch the evidence arrive, then tamper with a block yourself and see the verifier catch the break at the exact position.
illustrative demo · sample data · denials are evidence too: a refused request appends a block just like a grant does
Live proof
We run our own diligence on it.
When investors review Quox, the dataroom they use runs on the same protocols the platform ships. Every login, document view and export becomes an AEE envelope, a VOLT ledger entry and a WARD-witnessed receipt, and the session’s trail is theirs to inspect and verify from inside the room itself.
The same pattern is live on this site: quox.ai/facts.json carries a WARD receipt you can verify offline, with no Quox account. Read how it works →
Data sovereignty
Your infrastructure. Your keys. Your evidence.
Quox is self-hosted. The control plane, policies, memory, secrets and evidence chain run on your infrastructure, in your VPC, your data centre, or fully air-gapped. Inference runs where you choose: locally for full isolation, or through a model provider you explicitly configure. Nothing calls home, and licence activation supports offline mode.
Multi-tenant from the ground up: organisations are isolated, and credentials in QuoxVault sit behind per-org KEK isolation, so one tenant’s keys never mix with another’s.
External publication is optional and one-way. Every 100 WARD entries, a signed Ed25519 checkpoint can be published to an RFC 3161 timestamp authority, GitHub, GitLab, S3, Gitea or your own webhook. Nothing else crosses the boundary.
How the evidence layer works → Self-hosted AI agent governance, in depth →air-gapped supported · offline licence activation · evidence verifiable with no Quox account
Security controls
Controls your security team will recognise.
Governance that holds in production: every gate decision is logged, and a step that crosses a line you drew waits for a human.
At scale
Govern AI agents at scale, not one agent at a time.
As the number of agents you run grows from one to an estate, the question stops being “is this agent safe” and becomes “is every agent in this organisation held to the same standard”.
AOCL’s policy gate is the same layer for every agent, so a policy written once, blocking a dangerous command or requiring approval above a threshold, applies to the whole estate: a new agent added to the organisation inherits that policy set from day one, rather than starting ungoverned until someone remembers to wire it up.
Fleet products from the big clouds watch fleets that live in their clouds. Quox governs from your side of the boundary: one self-hosted control plane, tied to no model vendor, with evidence you can hand to an auditor.
Baselines are tracked per agent, so drift in one agent’s behaviour shows up against its own history, not a fleet average.
And when containment is what the moment calls for, E-STOP halts an individual agent and DEFCON RED steps the whole instance down: enforced server-side at every dispatch chokepoint, human-only to set or release, failing closed, with the trigger itself landing in the same audit trail as everything else. Alongside them: the approval hold, the policy deny, the budget gate and the loop-stuck kill.
What an agentic control plane is →The layer above
The questions a runtime cannot answer.
Runtime guardrails answer one question: was this tool call permitted. Quox models the organisation, not just the agent: objectives that give agents a reason to run, teams and approvals that give them authority, budgets that bound them, and an evidence chain that outlives them. Self-hosted, tied to no model vendor, on infrastructure you control.
- Why was this agent running at all?
- Who authorised it, and under which objective?
- What did it cost, and against whose budget?
- Can you prove the whole chain to someone who was not there?
Compliance
Mapped to the frameworks your auditors ask for.
One evidence chain, exported against seven frameworks. WARD-signed, generated from live trace data, not screenshots and spreadsheets. Each export fills the sections your telemetry can evidence and marks the rest action-required.
The big products
Six products, one evidence chain.
Each ships as its own thing. Together, they are how the claims on this page actually run.
Compliance Suite
Turns opaque AI decisions into auditor-ready reports across seven frameworks, with a SoA and DPIA builder in the product.
Decision Evidence
Structured, tamper-evident records of what an agent considered, invoked and decided, cryptographically linked to the VOLT ledger.
AOCL Developer Kit
Write your own AOCL layers, sentiment filters, PII detectors and cost trackers, and test each one in the Layer Playground.
Qluster
One console over every QuoxCORE box you run: a box for research, a box for security, a box per client, and none of them gives up its autonomy to be there.
QuoxBastion
One guarded gateway in front of every host in your registry, with parallel SSH across the fleet and a full audit trail on every command.
QuoxBox
Turns an always-on Mac into a governed worker: every action passes default-deny governance before it touches the machine.
Deployment
Deploy on your terms.
The protocols are open and the core platform is free. Commercial tooling, the Compliance Suite and the Developer Kit, is licensed on top, and priority support, onboarding and quarterly compliance reviews are available on commercial plans.
Deploy self-hosted
On your own infrastructure, air-gapped if you need it. The control plane stays yours, with offline licence activation.
Connect your agents
Every decision is captured across the 11 AOCL layers as agents run, with zero code changes required.
Hand over the evidence
Your auditor verifies the chain independently, offline, without a Quox account. One trust anchor across envelopes, runs and reports.
Governance you can prove, not promise.
Bring the receipts to your next audit. Start with the governance stack, or talk to us about a deployment for your organisation.