I · STAGE II · PATH III · REACH IV · SERVICES V · PROOF VI · STORY
I · The Stage

Every action
passes through stone.

Your AI can suggest anything. Between that suggestion and a real change to your business sit eight layers of control — each one narrowing what is possible, each one leaving a mark that cannot be erased.

Turn the monolith. Choose a layer. See why it exists, when it fires, how it works, and where it sits.

Drag to turn · Click a layer
II · The Path

A request does not arrive.
It ascends.

Nothing in StoneAI is a suggestion box. A request enters at the boundary and must survive every layer above it. Anything that fails a layer stops there — and the stop is recorded as carefully as an approval would be.

Layer 01 · Boundary

Stone Connect

Scoped connections into your real systems, so an agent holds a narrow key instead of the master key.

Why
When
How
Where
III · The Reach

The question is not whether
your AI is wrong.

It is how far a wrong answer can travel. Accuracy decides how often; reach decides how much. Give an agent more autonomy below and watch what it can touch — first without controls, then under StoneAI.

SYSTEMS REACHABLE
IRREVERSIBLE ACTIONS
UNLOGGED DECISIONS
IV · The Services

Eight controls.
One chokepoint.

Each layer answers the same four questions, because a control you cannot explain is a control you cannot defend — to your board, your customers, or a regulator.

V · The Proof

Controls nobody can see
are controls nobody has.

Governance regimes rarely ask whether you bought a tool. They ask you to produce evidence: who decided, on what basis, with what authority, and can you prove it was not edited afterwards. Every layer above is designed to emit exactly that, as a by-product of doing its job.

EU AI Act
Asks for meaningful human oversight of high-risk systems and records that show it. Cedar Gate is the oversight; the Record is the evidence it happened.
NIST AI RMF
Organized around mapping, measuring and managing AI risk. Reach limits and the Council are the management function; the ledger is the measurement.
ISO/IEC 42001
Expects a governed lifecycle with defined roles and accountability. Identity, scopes and signatures assign both, per action.
SOC 2
Turns on change control and access control being demonstrable over time. Append-only history is the demonstration.
GDPR
Data minimization and a lawful basis for processing. Data Shield minimizes at the egress point, before a provider ever sees the field.
HIPAA
Minimum necessary access and an audit trail for disclosures. Scoped connectors enforce the first; the Record supplies the second.
What this is not

StoneAI does not make your organization compliant, and no vendor can. Certification is awarded to you, by an accredited body, after it examines how you actually operate. What StoneAI does is narrower and more useful: it makes the evidence exist by default, so the examination is a retrieval exercise rather than a reconstruction. We state this plainly because a governance product that overstates its own guarantees has already failed its first test.

VI · The Story

Why we build brakes.

Nearly every failure involving AI in a business has the same shape. The model was not evil and usually was not even badly wrong. It was confidently wrong once, at a moment when nothing stood between its output and a system that mattered — and it held credentials broad enough to make that single mistake expensive.

The industry's reflex is to answer this with better models. That helps, and it is not a control. A control is something that holds even when the model is wrong, even when the prompt was poisoned, even when a vendor ships a regression on a Tuesday. You cannot get that from the thing you are trying to constrain.

“Trust the AI” is a posture. A signature bound to a hash is a control.

So StoneAI takes the opposite approach to autonomy. A judgment leaves the Council as a decree that is inert by construction — not a permission, not a queued job, but a sealed statement carrying no capability whatsoever. The only thing that converts it into an action is a human signature cryptographically bound to that decree's exact content. Change one character and the signature no longer matches. The brake is not policy, and it is not a setting someone can quietly disable under deadline pressure. It is arithmetic.

The same logic governs reach. An agent is never handed the master key, because the cheapest way to survive a mistake is to have made it impossible for that mistake to travel. Scope the key, shrink the blast radius, and a bad afternoon stays a bad afternoon instead of becoming an incident report.

Speed is worth very little if you cannot say, afterwards, exactly what happened and who agreed to it.

This is not a brake on ambition. It is what lets you actually use powerful AI on the work that matters — the billing system, the customer record, the production deploy — instead of restricting it to the harmless edges of the business because nobody is willing to sign off on the risk. Limits are what make the interesting use cases approvable.

Open the console Read the plain-language version