Open Source Delivering AI’s X-factor · Apache 2.0

Enterprise AI Governance Without Compromise

Zero-knowledge BYOC architecture. Every prompt, completion, and token stays inside your GCP project. DAX never sees your data.

Architecture

Your cloud. Your data. Always.

The gateway runs entirely in your GCP project. Prompts never cross your cloud boundary — that’s an architectural guarantee, not a policy.

┌───────────────────────────────────────────────────────────────┐
│  Your GCP Project                                               │
│                                                                │
│  ┌─────────────────────────┐    ┌─────────────────────────┐  │
│  │  Control Plane         │◄──►│  Data Plane             │  │
│  │  Portal & Gov API      │    │  OpenAI-compatible      │  │
│  │  PostgreSQL + Redis    │    │  JWT offline validate   │  │
│  │  Audit · Guardrails    │    │  PII + injection scan   │  │
│  └─────────────────────────┘    └─────────────┬───────────┘  │
│  ✓ Prompts never leave this boundary            │             │
└─────────────────────────────────────────────────┬─────────────┘
                                                 ↓
                                    ┌─────────────────────┐
                                    │  LLM Providers       │
                                    │  Vertex · OpenAI    │
                                    │  Anthropic · Ollama │
                                    └─────────────────────┘
🔒
Zero-Knowledge
Control plane receives token counts and cost only. Prompt content is never transmitted.
☁️
True BYOC
Every service — API, portal, gateway, database — lives in your own GCP project.
⚡
No Hot-Path Latency
Gateway validates JWT offline. Zero control-plane round-trips per inference request.
Features

Every governance layer. One platform.

📋
Model Catalog
Governed inventory with risk tier, autonomy tier, EU AI Act category, and approval workflow per model.
🛡️
Guardrail Engine
PII detection, prompt injection, secrets scanning, and bidirectional output filtering — per model.
📝
Audit Log
Append-only log of 25+ governance event types. Immutable, CSV-exportable, actor and IP tracked.
💰
Budget Controls
Org / team / project / user spend limits with configurable soft alerts and hard blocks at the gateway.
📊
Compliance Dashboards
Live pass/fail for SOC 2, GDPR, HIPAA, EU AI Act, and NIST AI RMF — all reading live platform data.
🚨
Incident Response
NIST AI RMF MANAGE-aligned incident log. Auto-created from guardrail blocks, severity lifecycle, webhook alerts.
Compliance Coverage

Built for the frameworks buyers require.

DAX maps to the standards your procurement team, legal team, and auditors actually ask for — out of the box, not as an add-on.

StandardRequirementHow DAX Covers It
NIST AI RMFGOVERN — AI policiesNamed guardrail policies, RBAC with 5 built-in roles, audit log evidence trail
NIST AI RMFMAP — Risk identificationModel catalog with risk_tier, autonomy_tier, use-case context on every access request
NIST AI RMFMEASURE — AnalyticsUsage events across org/model/user/team/project + incident metrics
NIST AI RMFMANAGE — ResponseGuardrail engine, budget hard blocks, incident lifecycle (open → resolved)
EU AI ActArt. 6 — Risk classificationrisk_tier + eu_ai_act_category field, compliance dashboard coverage check
EU AI ActArt. 14 — Human oversightautonomy_tier enforcement — autonomous models require assigned guardrail policy
EU AI ActArt. 13 — Transparencyexplainability_doc_url + bias_assessment_url fields, coverage metrics
EU AI ActArt. 73 — Incident reportingIncident log with severity lifecycle, auto-creation from guardrail violations
ISO/IEC 42001AI system inventoryModel catalog with lifecycle status, provider, version, and governance metadata
ISO/IEC 42001Shared responsibilityBuilt-in printable shared responsibility matrix, documented BYOC boundary
SOC 2 Type IIAccess controlRBAC, model approval workflow, token scoping — least-privilege by default
SOC 2 Type IIAudit loggingAppend-only audit log, 25+ event types, CSV export for external auditors
GDPR / HIPAAData sovereigntyBYOC: prompts never leave customer cloud — architectural, not contractual
Pricing

Open core. Marketplace billing.

GCP Marketplace purchases count toward your committed spend. No new vendor approval, no new AP setup.

Community
Free
Self-hosted, forever
  • Full governance engine
  • OpenAI-compatible gateway
  • All provider adapters
  • Guardrail engine
  • Audit log + compliance dashboards
  • GitHub Issues support
Deploy on GitHub
Popular
Pro
$18/user/mo
GCP Marketplace
  • Everything in Community
  • DAX-hosted control plane
  • White-label portal
  • SSO / SAML (Okta, Azure AD)
  • Priority email support
  • 99.9% SLA
Start Free Pilot
Enterprise
Custom
GCP Marketplace private offer
  • Everything in Pro
  • Full BYOC — your GCP project
  • Slack Connect with engineering
  • SOC 2 Type II documentation
  • Multi-year contract
  • 99.99% SLA + dedicated CSM
Contact Us

Experience DAX Enterprise now

The full platform is running. Sign up with your work email — you’ll be inside the portal in under 60 seconds.

Open Live Pilot →

Free pilot · No credit card · GCP Marketplace billing when you upgrade