Zero-knowledge BYOC architecture. Every prompt, completion, and token stays inside your GCP project. DAX never sees your data.
The gateway runs entirely in your GCP project. Prompts never cross your cloud boundary — that’s an architectural guarantee, not a policy.
┌───────────────────────────────────────────────────────────────┐ │ Your GCP Project │ │ │ │ ┌─────────────────────────┐ ┌─────────────────────────┐ │ │ │ Control Plane │◄──►│ Data Plane │ │ │ │ Portal & Gov API │ │ OpenAI-compatible │ │ │ │ PostgreSQL + Redis │ │ JWT offline validate │ │ │ │ Audit · Guardrails │ │ PII + injection scan │ │ │ └─────────────────────────┘ └─────────────┬───────────┘ │ │ ✓ Prompts never leave this boundary │ │ └─────────────────────────────────────────────────┬─────────────┘ ↓ ┌─────────────────────┐ │ LLM Providers │ │ Vertex · OpenAI │ │ Anthropic · Ollama │ └─────────────────────┘
DAX maps to the standards your procurement team, legal team, and auditors actually ask for — out of the box, not as an add-on.
| Standard | Requirement | How DAX Covers It |
|---|---|---|
| NIST AI RMF | GOVERN — AI policies | Named guardrail policies, RBAC with 5 built-in roles, audit log evidence trail |
| NIST AI RMF | MAP — Risk identification | Model catalog with risk_tier, autonomy_tier, use-case context on every access request |
| NIST AI RMF | MEASURE — Analytics | Usage events across org/model/user/team/project + incident metrics |
| NIST AI RMF | MANAGE — Response | Guardrail engine, budget hard blocks, incident lifecycle (open → resolved) |
| EU AI Act | Art. 6 — Risk classification | risk_tier + eu_ai_act_category field, compliance dashboard coverage check |
| EU AI Act | Art. 14 — Human oversight | autonomy_tier enforcement — autonomous models require assigned guardrail policy |
| EU AI Act | Art. 13 — Transparency | explainability_doc_url + bias_assessment_url fields, coverage metrics |
| EU AI Act | Art. 73 — Incident reporting | Incident log with severity lifecycle, auto-creation from guardrail violations |
| ISO/IEC 42001 | AI system inventory | Model catalog with lifecycle status, provider, version, and governance metadata |
| ISO/IEC 42001 | Shared responsibility | Built-in printable shared responsibility matrix, documented BYOC boundary |
| SOC 2 Type II | Access control | RBAC, model approval workflow, token scoping — least-privilege by default |
| SOC 2 Type II | Audit logging | Append-only audit log, 25+ event types, CSV export for external auditors |
| GDPR / HIPAA | Data sovereignty | BYOC: prompts never leave customer cloud — architectural, not contractual |
GCP Marketplace purchases count toward your committed spend. No new vendor approval, no new AP setup.
The full platform is running. Sign up with your work email — you’ll be inside the portal in under 60 seconds.
Open Live Pilot →Free pilot · No credit card · GCP Marketplace billing when you upgrade