Control the action
A model's answer is not the boundary worth defending. The boundary is the point where intent becomes an entry in a system of record — so that is where the decision belongs, on a deterministic path with no model in the loop.
Company
GovernorAI governs agents it did not build, running on infrastructure it does not own. That constraint is deliberate: it is what makes the evidence worth anything to the people who have to review it.
PRINCIPLES
A model's answer is not the boundary worth defending. The boundary is the point where intent becomes an entry in a system of record — so that is where the decision belongs, on a deterministic path with no model in the loop.
Every capability page names what it does not do. Outcomes are limited to what an enforcement point genuinely supports, unmeasurable assurance domains report not_assessed rather than a pass, and mapping evidence to controls is never described as certification. A gap that is printed can be planned around; a gap that is hidden is found during diligence.
Evidence is a by-product of governing, not a report assembled afterwards. Governance actions are recorded as they happen, in a hash-chained ledger where a removed or altered entry does not verify.
FOUNDERS
Who is accountable for the claims on the rest of this site.
Mynul is a technology executive with 25 years building cloud, security, data, AI and large-scale software platforms. Most recently he was President of Software & Platform Engineering at Viasat, leading an 850-person global engineering organisation spanning platform engineering, SRE, security, data and ML, observability and enterprise systems. He was also Viasat’s Executive Sponsor for AI Governance, shaping how the enterprise adopted and operated AI systems.
Before that he was Global CTO and EVP Engineering at Mercado Bitcoin / 2TM, a regulated fintech and digital-asset platform operating under stringent security, compliance, privacy and data-governance requirements. Earlier he held senior engineering and architecture leadership at IBM Public Cloud — a regulated public-cloud environment supporting FedRAMP, SOC 2, PCI and HIPAA workloads — and engineering leadership roles at Cisco.
He holds CISSP and CCIE Security certifications and is the author of a cybersecurity handbook on enterprise security architecture and operational resilience.
GovernorAI comes from that experience directly: the gap between an enterprise AI policy and an enforceable runtime control, in environments where the difference is measured in regulators and outages rather than opinions.
Those environments held the certifications named above. SentinelLayer holds none of them; see Trust for what this company does and does not claim.
Rayaadh's work centers on the intersection of agent behavior and real-world constraints—latency, reliability, security, and human oversight. He has contributed to engineering initiatives emphasizing automation, scalable design, and developer velocity, with a focus on translating modern AI capabilities into predictable, enforceable runtime systems.
At SentinelLayer, Rayaadh leads platform engineering and SDK development, shaping how policy logic, runtime enforcement, and developer experience come together. His focus ensures SentinelLayer remains fast, transparent, and simple to integrate—without compromising safety or control.
LinkedIn ↗“SentinelLayer is a father-and-son mission grounded in two generations of systems engineering—enterprise-scale governance paired with modern agentic runtime execution. Together, we’re building the governance platform that makes autonomous systems safe, accountable, and enterprise-ready.”
TRUST & SECURITY
Answered here rather than in a questionnaire round-trip.
Row-level isolation with per-tenant scoping, verified by an isolation inspector rather than asserted.
enforcedRole-based access control, SSO and SCIM provisioning, with separation of duties on policy approval.
rbac · sso · scimThe SDK is a thin client. You keep every credential, all tool code and all control flow. GovernorAI is not a proxy in front of your model provider.
no token pathMulti-region and federated deployments are supported. An air-gapped shape is architecturally available for qualified enterprise engagements; it is not a standard commercial tier and is not something we can demonstrate today.
per deploymentAny transport error, timeout, non-2xx or unparseable response resolves to deny, never to allow. Enforcement does not degrade quietly.
by contractEd25519/Merkle signed evidence bundles are available per deployment, and are not default-on. Configuration and verification are explicit.
configureDESIGN PARTNER PROGRAM
We map its action boundary, define the policy and prove the governed outcome with your teams.