Hyderabad · Bengaluru · Bhubaneswar · Singapore Trust CenterCareersClient support
Rhinexa Niyantran · Governed AI Adoption Platform

Govern what your AI agents see, and what they do.

One governed front door for enterprise AI. Identity, policy, data protection and action control are applied before a request reaches an approved model, and every decision leaves signed evidence behind. Deployed in your environment.

Deployment
On-premises, private cloud or air-gapped, in your environment
Rollout
Monitor first: observe, then enforce, then contain
Evidence
Signed, hash-linked, tamper-evident, verifiable offline
Grown from
From governing AI adoption for regulated clients
Niyantran Shadow-AI Exposure Assessment: AI sessions, users, services, shadow share and key findings (sample data)Sample data
Discovery first. The Shadow-AI exposure assessment that opens every Niyantran engagement: which services are in use, by whom, and what is already leaving the country. Sample data.
The problem

Ungoverned AI creates gaps conventional controls miss.

Adopting AI without a control point leaves security, privacy and compliance teams reacting after the fact.

01

Shadow AI

Teams adopt assistants and agents outside approved channels. Prompts, context and actions leave the visibility of security and GRC.

02

Data leaving jurisdiction

Sensitive payloads can reach models and regions that conflict with the DPDP Act, sectoral rules and contractual residency obligations.

03

Agents that act without governance

Coding agents and desktop tools execute tool calls and endpoint actions with no identity, policy or evidence of what was allowed.

What you get

Four controls. One operating model.

Niyantran binds identity, policy, data protection and endpoint action into a single decision path.

01

One door, every agent

Approved coding agents and AI tools are routed through one governed entry point, so policy is consistent whatever the channel or IDE. Per-action enforcement is live for Claude Code and Codex; other tools are governed for prompts and data.

02

Identity-aware policy

Decisions follow who is acting: analyst or developer, restricted or elevated estate, with persona rules that travel with the session and a policy floor no user can override.

03

Inline data protection

Sensitive data is detected and masked before it leaves: Indian identifiers such as Aadhaar, PAN, GSTIN, UPI, IFSC and ABHA, and secrets. The workflow continues under policy.

04

Endpoint Action Guard

Govern what an agent may do at the endpoint, not only what it may say: each action allowed, masked or denied by policy. Live today for Claude Code and Codex.

How it works

From identity to evidence.

Six steps on every request, in one path, without handing you off to another tool.

  1. Identify

    Who is acting: user, role, department and risk tier, resolved from your identity provider.

  2. Decide

    Policy evaluates the request against identity, data class and destination: allow, mask or deny.

  3. Protect

    Sensitive data is masked or redacted before egress; prompt injection and secrets are detected.

  4. Route

    Approved work goes to the right model: local for regulated data, cloud for approved tasks, by policy.

  5. Guard

    Agent actions at the endpoint are checked per action on managed surfaces, with egress control on managed Windows endpoints.

  6. Record

    Every decision becomes a signed, hash-linked record in the audit console, exportable as evidence.

Niyantran audit console, executive view: platform status, control posture, sensitive-data detections, evidence integrity and prioritised findings (sample data)Sample data
The executive view once governance is on: control posture, sensitive-data detections, evidence integrity and the findings that need attention. Sample data.
Capabilities

Governed AI you can operate and prove.

Every capability below is part of one path: protection, routing, defence and evidence connected.

01
AI use discoverySee which AI services and agents are in use, by whom and with what classes of data, before you decide policy.
02
Identity and persona policyRules keyed to who is acting, with a non-overridable floor set by security and GRC.
03
Inline data protectionAadhaar, PAN, GSTIN, UPI, IFSC, ABHA and secrets detected and masked before a model sees them.
04
Prompt defencePrompt injection and secret leakage detected in prompts and responses, with policy deciding the outcome.
05
Policy-driven routingRegulated workloads stay on local models inside your estate; approved tasks route to cloud providers, by policy.
06
Endpoint Action GuardPer-action control of what a managed coding agent may run, read, write or call. Live for Claude Code and Codex today.
07
Egress controlNo AI egress from managed Windows endpoints to catalogued destinations, so unmanaged tools cannot bypass policy.
08
Signed evidenceEvery decision recorded as a signed, hash-linked, tamper-evident record that can be verified offline.
09
Audit consoleSearch, inspect and export decisions by user, policy, data class and outcome; evidence packs for reviews.
10
SIEM exportPolicy violations and blocked prompts exported to your SIEM.
11
Obligation mappingEvidence mapped to the controls in ISO/IEC 27001, SOC 2, NIST AI RMF and the OWASP Top 10 for LLM applications. Mapping supports your assurance; it is not certification.
12
Observe modeRun the whole path without blocking: see prompts, data classes, destinations and would-be decisions before you enforce.

Also included

  • Residency-aware routing
  • Persona rules that travel with the session
  • Evidence packs for audits and reviews
  • Monitor, enforce and contain as separate switches
  • MCP tool governance
  • IDE integrations beyond Claude Code and Codex

Rhinexa Niyantran is

  • A platform you run in your own environment
  • Policy decided by identity, data and action
  • Evidence you can verify without trusting us
  • A path from monitoring to enforcement, at your pace

Rhinexa Niyantran is not

  • A certification or a substitute for your auditor
  • A claim of control over agents it is not installed in
  • A managed security operations service
  • A replacement for your identity provider or SIEM
Coverage

What is live today.

We publish exactly what each capability covers now and what is on the roadmap, so you can plan a pilot on facts.

SurfacePrompt and data governancePer-action enforcement
Claude CodeLiveLive
CodexLiveLive
Other supported AI tools such as Cursor and ClineLiveRoadmap
Managed Windows endpointsEgress control: no AI egress to catalogued destinations Live
Unmanaged agentsDiscovered and contained at the network. No per-action control is claimed.

Managed agents are enforced per action. Unmanaged agents are discovered and contained at the network. We do not claim per-action control of an agent we are not installed in.

Where it fits

Built for the environments teams actually run.

The same platform covers a single segment or a distributed estate.

01

Coding agents and IDEs

Govern Claude Code and Codex today, and other approved tools for prompts and data, through one door with one policy.

02

Regulated enterprises

Keep sensitive prompts and payloads under the DPDP Act and sectoral obligations with masking, residency-aware routing and exportable evidence.

03

Shadow AI containment

See unapproved assistants and agent paths before they become blind spots, and contain them on managed endpoints.

04

Security and GRC together

One operating view for both teams: decisions, policy outcomes and signed records in one rhythm.

05

Private cloud and air-gapped estates

Deploy on-premises or air-gapped so governed AI stays inside your control boundary without rewriting client tools.

06

Controlled rollout

Start in observe mode, prove the evidence, then enforce: from visibility to containment without lock-in.

Deployment and security

Your estate. Your boundary. Your evidence.

One control point you host: identity, policy, protection and signed records inside your boundary, ready for the obligations your teams already report against.

01

Auditable decision records

Policy outcomes are logged, timestamped, attributed and exportable for security and compliance.

02

Deployed where you decide

On-premises, private cloud or air-gapped. Nothing in the decision path needs a public service.

03

Built for Indian obligations

Evidence collection supports the DPDP Act and the CERT-In, RBI and SEBI reporting contexts your teams already use.

04

Framework mapping

Aligned to the evidence needs of ISO/IEC 27001, SOC 2, NIST AI RMF and the OWASP Top 10 for LLM applications. Mapping is not certification.

05

Monitor-first rollout

Observe safely, then enforce; fail closed only on the segments you agree.

06

Mapping is not certification

Niyantran helps you collect evidence against obligations. It does not claim certifications you have not earned.

Pilot

Eight weeks, decided on evidence.

Two weeks to mobilise, six weeks to run. Acceptance criteria are agreed in writing before anything is installed: observe first, enforce when ready, contain where the residual risk demands it.

  1. Weeks 1 to 2: Mobilise

    Scope, success criteria, users and data classes agreed; platform deployed in your environment.

  2. Weeks 3 to 4: Observe

    Monitor mode establishes a baseline of real AI use: prompts, data classes, destinations and would-be decisions.

  3. Weeks 5 to 7: Enforce

    Policies switched on for agreed groups and surfaces; egress control and action guard where agreed.

  4. Week 8: Decide

    Results measured against the acceptance criteria, with the signed evidence to show it. No lock-in.

Questions

Frequently asked.

Is Rhinexa Niyantran self-hosted in our estate?
Yes. It deploys on-premises, in a private cloud or air-gapped, so governed AI traffic and evidence stay inside your control boundary. No decision depends on a public service.
Do we need to rewrite our agents or IDE tools?
No. Niyantran sits as a governed front door for the agents you already use. Approved paths are routed through it; client tools are not rebuilt.
Can we start in observe mode before enforcing?
Yes. The recommended path is monitor, then enforce, then contain. Begin by observing prompts, data classes and would-be decisions; enforce when the acceptance criteria are met.
Which tools does it enforce actions on today?
Per-action enforcement is live for Claude Code and Codex. Other supported tools are governed for prompts and data, with action enforcement on the roadmap. The coverage table above is kept current.
How is evidence different from ordinary logs?
Each policy outcome becomes a signed, hash-linked, tamper-evident record, attributed and exportable, so security, audit and regulators can verify what was allowed, masked or denied without trusting us.
How long does a pilot take?
Eight weeks: two to mobilise, six to run, with acceptance criteria agreed up front and no lock-in at the end.
Rhinexa Niyantran

See Rhinexa Niyantran in your environment.

A guided demo, then an eight-week pilot with acceptance criteria agreed up front.

Request a Rhinexa Niyantran pilot
AI Security services

Need help beyond the platform?

Our AI Security practice advises on governance, architecture and assurance for AI adoption.

Talk to a specialist