Get started

Quox for enterprise · self-hosted

Run AI your auditors can check.

Quox is the self-hosted evidence layer for AI agents: every action signed, policy-gated and sealed into a tamper-evident chain on infrastructure you control.

AOCL control layers 11Framework exports 7External chain backends 6Ward tip #04213
The live compliance monitor: real-time posture across seven frameworks with a cross-framework gap heatmap

In plain words

What it is, where it lives, when to reach for it

What is it
The QuoxCORE platform plus the enterprise plugins, deployed for a whole organisation on servers you own.
Where do I use it
On your own infrastructure, including disconnected estates; every team’s agents run through the same instance.
When would I use it
When more than one team runs agents and an auditor will eventually ask for the record.
How do I use it
Run curl -fsSL https://get.quox.ai | sh to stand up the platform, then talk to us about the enterprise plugins.

QuoxCORE is the free, self-hosted platform underneath this. What is QuoxCORE

Why Quox

Most platforms ask for trust. Quox hands you the receipts.

Break one record and the whole chain says so. When the review comes, you hand over proof, not promises. The core is source-available.

Four open protocols, specified and implemented, turn every agent action into verifiable evidence. Your auditor checks the chain on their own machine, offline, with no Quox account and no call home. You do not trust the agent, you check it.

All 4 are live IETF Internet-Drafts. No standards body has reviewed or endorsed them.

The VOLT and WARD protocols and the evidence API are core. The dedicated ledger and receipt views, and the per-turn decision record, are the Decision Evidence enterprise add-on at $599/yr. See Decision Evidence →

Live demonstration

Try to break the audit trail.

This is the chain of custody behind every governed action: envelopes signed, gates decided, entries hashed and sealed. Watch the evidence arrive, then tamper with a block yourself and see the verifier catch the break at the exact position.

evidence register · org acme live
ward chain · tip verification

illustrative demo · sample data · denials are evidence too: a refused request appends a block just like a grant does

Live proof

We run our own diligence on it.

When investors review Quox, the dataroom they use runs on the same protocols the platform ships. Every login, document view and export becomes an AEE envelope, a VOLT ledger entry and a WARD-witnessed receipt, and the session’s trail is theirs to inspect and verify from inside the room itself.

The same pattern is live on this site: quox.ai/facts.json carries a WARD receipt you can verify offline, with no Quox account. Read how it works →

Data sovereignty

Your infrastructure. Your keys. Your evidence.

Quox is self-hosted. The control plane, policies, memory, secrets and evidence chain run on your infrastructure, in your VPC, your data centre, or fully air-gapped. Inference runs where you choose: locally for full isolation, or through a model provider you explicitly configure. Nothing calls home, and licence activation supports offline mode.

Multi-tenant from the ground up: organisations are isolated, and credentials in QuoxVault sit behind per-org KEK isolation, so one tenant’s keys never mix with another’s.

External publication is optional and one-way. Every 100 WARD entries, a signed Ed25519 checkpoint can be published to an RFC 3161 timestamp authority, GitHub, GitLab, S3, Gitea or your own webhook. Nothing else crosses the boundary.

How the evidence layer works → Self-hosted AI agent governance, in depth →
YOUR BOUNDARYVPC · DATA CENTRE · AIR-GAPPEDQuoxCOREorchestration · inferenceagentsgoverned toolsQuoxVaultper-org KEK isolationAOCL gatespolicy · identity · HITL#04211#04212tip #04213WARD · append-only · Ed25519-signed tipsCONTROL PLANE STAYS YOURS · NO CALL HOMEoptional · one-waysigned checkpointsevery 100 entries:TSA · GitHub · GitLabS3 · Gitea · webhook

air-gapped supported · offline licence activation · evidence verifiable with no Quox account

Security controls

Controls your security team will recognise.

Governance that holds in production: every gate decision is logged, and a step that crosses a line you drew waits for a human.

HITL-01Human-in-the-loopSensitive operations hold for a human. Every envelope resolves to ALLOW, DENY or HOLD, and nothing passes a gate unchecked.enforced
GATE-02Policy checkpointsPolicy, identity and approval checkpoints across 11 AOCL control layers on every request.enforced
EYES-034-eyes approvalHigh-risk policy changes are staged for a second admin. The approver cannot be the requester.opt-in
HIST-04Policy change historyAppend-only audit trail for every policy mutation: actor, role, timestamp, field-level diff and reason.always on
SIEM-05Incident fan-outRuntime policy denials become triaged incidents, delivered to Splunk HEC, Microsoft Sentinel, Wazuh, generic CEF or any HMAC-signed endpoint.5 formats
BASE-06Behavioural baselinesPer-agent baselines catch drift before it matters. Replay any trace layer by layer, and simulate policy changes with What-If.per agent

At scale

Govern AI agents at scale, not one agent at a time.

As the number of agents you run grows from one to an estate, the question stops being “is this agent safe” and becomes “is every agent in this organisation held to the same standard”.

AOCL’s policy gate is the same layer for every agent, so a policy written once, blocking a dangerous command or requiring approval above a threshold, applies to the whole estate: a new agent added to the organisation inherits that policy set from day one, rather than starting ungoverned until someone remembers to wire it up.

Fleet products from the big clouds watch fleets that live in their clouds. Quox governs from your side of the boundary: one self-hosted control plane, tied to no model vendor, with evidence you can hand to an auditor.

Baselines are tracked per agent, so drift in one agent’s behaviour shows up against its own history, not a fleet average.

And when containment is what the moment calls for, E-STOP halts an individual agent and DEFCON RED steps the whole instance down: enforced server-side at every dispatch chokepoint, human-only to set or release, failing closed, with the trigger itself landing in the same audit trail as everything else. Alongside them: the approval hold, the policy deny, the budget gate and the loop-stuck kill.

What an agentic control plane is →

The layer above

The questions a runtime cannot answer.

Runtime guardrails answer one question: was this tool call permitted. Quox models the organisation, not just the agent: objectives that give agents a reason to run, teams and approvals that give them authority, budgets that bound them, and an evidence chain that outlives them. Self-hosted, tied to no model vendor, on infrastructure you control.

  • Why was this agent running at all?
  • Who authorised it, and under which objective?
  • What did it cost, and against whose budget?
  • Can you prove the whole chain to someone who was not there?

Compliance

Mapped to the frameworks your auditors ask for.

One evidence chain, exported against seven frameworks. WARD-signed, generated from live trace data, not screenshots and spreadsheets. Each export fills the sections your telemetry can evidence and marks the rest action-required.

The big products

Six products, one evidence chain.

Each ships as its own thing. Together, they are how the claims on this page actually run.

Deployment

Deploy on your terms.

The protocols are open and the core platform is free. Commercial tooling, the Compliance Suite and the Developer Kit, is licensed on top, and priority support, onboarding and quarterly compliance reviews are available on commercial plans.

Enterprise pricing is custom: one licence covers the whole organisation, with no per-user charges. Volume licensing and custom frameworks available.
See enterprise plugin pricing →
01

Deploy self-hosted

On your own infrastructure, air-gapped if you need it. The control plane stays yours, with offline licence activation.

02

Connect your agents

Every decision is captured across the 11 AOCL layers as agents run, with zero code changes required.

03

Hand over the evidence

Your auditor verifies the chain independently, offline, without a Quox account. One trust anchor across envelopes, runs and reports.

Governance you can prove, not promise.

Bring the receipts to your next audit. Start with the governance stack, or talk to us about a deployment for your organisation.