AI Governance  ·  Australian Enterprise and Government

Your organisation is using AI.
Most of it is ungoverned.

Governs sits between your organisation and every AI model it uses. Shadow AI is logged and classified. Australian PII never leaves your network. AIAF compliance assessments populate themselves.

Deploys in 30 minutes. Prompts never leave your network.


47employees, typical agency

The average number of staff at an Australian government agency calling ChatGPT, Claude, or Gemini directly from work devices right now — some of them pasting Tax File Numbers, Medicare numbers, and classified documents into foreign AI systems. Nobody knows. Nobody's stopping it. And nobody can prove it didn't happen.


Typical outcomes — week one
12–47
Shadow AI incidents discovered in the first week of deployment
$2–5K
Monthly AI spend savings identified through model routing optimisation
70%
Of AIAF assessment auto-populated from observed behaviour alone
30 min
From zero to fully governed AI traffic — one Docker container

Five capabilities.
One deployment.

Everything works from the moment you point your first application at the gateway.

01

Shadow IT Logging

A DNS sinkhole intercepts direct calls to ChatGPT, Claude, Gemini, and other public AI services. Every attempt is logged with full context: who, what service, timestamp, and PII classification. Shadow AI becomes a managed risk with an audit trail — not an invisible liability.

Instead of blocking and losing the user, Governs surfaces each incident to your CISO dashboard. The conversation that follows — "you're using AI, let's bring it under governance" — is your upsell moment.

Shadow IT alert — real time
User:  j.morrison@agency.gov.au
Dest:  api.openai.com
Time:  today, 14:22 AEST
PII:   TFN detected  Medicare detected

Status
Intercepted — logged — queued for review
02

Auto-PII Detection

Every prompt passing through the Governs gateway is scanned for Australian PII before it reaches the upstream model. Tax File Numbers, Medicare numbers, BSB combinations, ABNs, passport numbers, and state-specific driver's licences — all built to the patterns that the Privacy Act 1988 actually protects.

Three enforcement modes: flag and alert, redact before forwarding, or block and return an error. Per-application, per-team, or organisation-wide policy.

Before Governs
Help me write to John Smith regarding his tax return. His TFN is 123 456 789 and Medicare number is 2123 45678 1.

After Governs — redact mode
Help me write to John Smith regarding his tax return. His TFN is [REDACTED-TFN] and Medicare number is [REDACTED-MEDICARE].

AIAF Auto-Assessment

Router observes every AI system and auto-populates up to 70% of your Australian AI Assessment Framework assessment from trace data. Nine dimensions filled automatically. Your compliance officer reviews the rest and signs off. The report writes itself.

Cost and ROI Tracking

Real-time spend by team and model. Every request scored for complexity — Governs shows exactly which calls are running on expensive models unnecessarily, what you'd save by routing them down, and creates the routing rule in one click.

Live Agent Traces

Every AI agent's reasoning chain visualised in real time. Tool calls, LLM invocations, and decision points as they happen. Built on OpenTelemetry spans. Your governance team sees what an agent actually did — not just that it ran.


Built for the Australian
regulatory environment.

Not a US product with GDPR templates bolted on. Every feature is designed around Australian obligations from the ground up.

Privacy Act 1988
Australian PII patterns built in — TFN, Medicare, BSB, ABN, state-specific driver's licences. Prompts are scanned against what the Privacy Act actually protects, not international templates repurposed for the Australian market.
ASD Essential Eight
Shadow IT blocking maps directly to application control requirements. Unauthorised AI tools are intercepted at the network layer and logged with full evidence. Audit trails are generated automatically with every incident.
AIAF
The Australian AI Assessment Framework is a core feature of Governs, not a report template. Assessment dimensions are auto-populated from observed AI behaviour — your compliance officers review, not create, the assessment.
Data Sovereignty
Prompts and responses never leave your network. The Governs data plane runs on your infrastructure. Only metadata and spans reach our IRAP-attested control plane in AWS Sydney (ap-southeast-2). Firewall teams whitelist one IP.
ISM Alignment
Audit trail, access control, and governance reporting align with Information Security Manual requirements. Every AI interaction is logged with immutable evidence suitable for audit and incident response purposes.
IRAP Attested
Our control plane in AWS ap-southeast-2 is targeting IRAP attestation. One outbound HTTPS connection from your perimeter to ours. That is the entire attack surface for cloud-resident Governs infrastructure.

Up and running
in 30 minutes.

One Docker container. One DNS configuration. One line change per application.

Step 01

Deploy the data plane

Run the Governs container inside your network. It starts an OpenAI-compatible gateway and sets up the DNS intercept for shadow AI detection.

docker run governs/agent --env-file .env
Step 02

Change one line

Point your existing AI applications at the Governs gateway. The OpenAI SDK, LangChain, and LlamaIndex all work without any other modifications.

base_url="http://ai.internal/v1"
Step 03

Govern everything

Every AI call — authorised or shadow — is now visible, PII-scanned, cost-tracked, and AIAF-assessed. The dashboard is live within minutes of first traffic.

governs.com.au/dashboard → live

Five minutes.
Everything they need to see.

This is exactly what we run in every product demonstration — against your own AI traffic, not a scripted environment.

01

"Change one line"

Point an existing OpenAI application at Governs. Nothing breaks. A trace appears in the dashboard immediately. The audience sees their own application, governed, in under a minute.

02

"Here is what you are spending"

Live cost dashboard. AI spend broken down by team and model. Most organisations have never seen this number before and it is almost always larger than expected.

03

"Here is what you are leaving on the table"

The ROI panel. Typically $2,000–$4,000 per month in identified routing savings for a mid-size agency. One click creates the routing rule. The audience creates it themselves.

04

"Someone just called ChatGPT directly"

A shadow IT event triggered live. PII flagged. Employee identity, team, timestamp, and prompt preview — all logged in real time on the CISO dashboard.

05

"Your AIAF assessment is 70% complete"

Auto-populated from observed behaviour. The compliance officer opens a near-complete AIAF assessment based on five minutes of live traffic. They review the remaining fields. The report writes itself.

Per governed AI system.
No per-seat surprises.

Pilot programs available for government agencies. Contact us for volume pricing.

Base

Govern

Per AI system  ·  per month
Contact us for pricing

  • AI Gateway proxy — OpenAI-compatible
  • Australian PII detection (flag / redact / block)
  • Shadow IT logging via DNS sinkhole
  • AIAF auto-assessment (70% auto-populated)
  • Cost tracking and ROI recommendations
  • Live agent trace visualisation
  • Data plane on your infrastructure
  • Control plane in AWS Sydney (IRAP)
Get in touch
Enterprise

Sovereign

For agencies requiring dedicated infrastructure
Custom pricing

  • Everything in Enforce
  • Dedicated sovereign cloud tenancy
  • IRAP assessment support
  • On-site deployment assistance
  • ISM documentation package
  • Dedicated customer success
Talk to us

See it running on
your AI traffic.

We'll run the demonstration against your own AI tools in five minutes. No slide deck. No scripted environment. Your AI, governed — live in the room.