All Posts
2 Min ReadJohn Mackenzie

LLM Vault Is Live: Governing AI Beyond The Prompt

  • Announcements
  • AI Governance

Today LLM Vault has a public home: llmv.tech. This first post explains, briefly and honestly, why it exists.

The Problem Has Changed Shape

For the last few years, the risk conversation around AI was about output — hallucinations, wrong answers, awkward screenshots. That era is ending. AI systems now call tools, write code, query databases and act across systems, and the controls in most organisations have not kept pace.

The numbers say it plainly. McKinsey finds 88% of organisations already use AI in at least one business function — yet only around 30% reach adequate governance maturity for agentic-AI controls. CSA's 2026 research carries a title that says everything: Autonomous but Not Controlled — 82% of enterprises discovered previously unknown AI agents operating in the past year. And IBM's breach research puts a price on looking away: breaches involving heavy Shadow AI cost an average of $670,000 more.

What LLM Vault Does About It

LLM Vault is the governed layer between your organisation and every model, agent, router and coding tool it uses. Every request passes five gates before a model ever runs:

  1. Classify — what is this? Task, data class, purpose, risk, jurisdiction, user role.
  2. Gate — is it allowed? Model and provider approval, DPIA triggers, residency, budget.
  3. Route — where does it go? The lowest-cost model that still meets the requirement.
  4. Review — can it be trusted? Prompt quality, model fit, security, cost efficiency.
  5. Evidence — can we prove it? A tamper-evident record of the decision, every time.

No token markup, on your own provider keys. Nothing trusted on the sender's say-so — every payload is verified server-side, every time. And every call leaves evidence behind: the model, the route, the data class, the policy result, the exact billed cost, the hashes.

Honest By Design

Two things we will keep saying plainly. LLM Vault is tooling and evidence to help you manage AI risk — it does not certify compliance. And our roadmap is a roadmap: the Control Plane is live today, while the Experiment and Community planes are coming — we will never sell you something that has not shipped.

What Happens Next

The beta is open, and this blog is where we will write about what we are learning: governing autonomous agents, finding and fixing Shadow AI, the real cost of ungoverned usage, evidence and provenance, and the maturity path organisations actually climb.

Explore the platform, read how we handle data, or just get in touch — we reply personally.

Govern every AI interaction. Prove every decision.

Beta Now