The authority layer for agentic AI.
Agents are eager. TapPass makes eager safe — one layer at the boundary that watches every call, decides it against your rulebook, and keeps the record. EU-hosted, on the stack you already run.





The first wave governed the agents you own. The next governs the ones you don’t.
Most enterprise value will come from agents calling other agents, tools and models — across teams, clouds and companies. That only works if every collaboration is governed. TapPass is where that governance lives.
Enforce in the path, or from your own code.
Gateway
A transparent, OpenAI-compatible proxy. Repoint one base URL and every model and tool call is checked before it runs.
Explore →Verdict SDK
Instrument your own app against the governance server. Ask for a decision, enforce it yourself — nothing leaves your walls.
Explore →MCP gateway
Per-tool permissioning and human-in-the-loop on MCP traffic. Give an agent the three tools its job needs, not the thirty-four the server exposes.
Explore →Policy Engine
Rules written in plain words that actually fire. Least privilege by default; authority granted as it is earned.
Explore →Observe. Decide. Record.
Full observability
Every prompt, response and tool call, in real time, per user and per team.
Policy enforcement
Guardrails and redaction on model calls; per-tool permissioning and approvals on tool calls.
Audit & export
Every interaction recorded and exportable. Evidence is a query, not a project.
BYOK & EU-hosted
Your model keys stay yours, in an encrypted vault. Hosted in your European region.
Keep reading
The Governance Gap: Why AI Agent Security Requires a New Category
AI agents deploy faster than governance can follow.
Runtime Is Where Agent Security Gets Real
A valid credential doesn't make a live action valid.
Give Your Agents Less. On Purpose.
Everyone races to give AI agents more power.