Runtime 01
Agent
Wraps the model provider and the tool layer. Each call is checked against the live pack, allowed or denied, and sealed with its verdict.
- Multi-provider LLM shim
- Pack-derived admissibility
- LangChain adapter
- Per-agent Trust Score
When AI in your business tries to do something it shouldn't — share a patient record, move money, touch a privileged file — we stop it first, route it to the right person to review, and keep a record your auditor can read. That applies to your autonomous agents, to the people using AI to write code, and to the machines they use to reach an LLM.
We didn't bring FICO to AI; we built the trust layer AI was missing. Every agent and business computer earns a TAC Score from 0 to 1000 that rises when it follows the rules and falls when it doesn't.
my-cc.io enforces at the tool-call boundary and seals what happened to a SHA-256 hash-linked chain. Same enforcement engine at every scale, so the record reconciles across all four.
Runtime 01
Wraps the model provider and the tool layer. Each call is checked against the live pack, allowed or denied, and sealed with its verdict.
Runtime 02
Scopes packs, data classes, and consent to a body of work. Every IDE tool inherits the boundary, and the boundary is versioned.
Runtime 03
Runs on the employee's machine. Inspects what a person is about to send to any LLM, holds identifiers locally, and seals the exchange to the same chain.
Runtime 04 · Beta
TaCortex runs the safety floor on the device itself — a humanoid or a child's toy. It screens what the device is about to say or do on-device, from Raspberry Pi to Jetson, and seals each exchange to the same chain.
A full executive narrative covering six business functions, three C-suite conversations (CEO / CFO / CIO-CISO), transparent pricing vs. Collibra, Credo AI, and IBM watsonx, and three illustrative deployment scenarios.
Two short screen recordings: register an organization and bring your first agents under governance, then watch a high-risk action get paused for human escalation.
Registration & onboarding, start to finish — from sign-up to a live TAC Score.
A paused compliance decision — a high-risk agent action held for human escalation and approval.
Collibra observes after the fact through their AI Command Center — catalog, score, and audit AI systems retroactively across AWS, Azure, Google, Databricks, SAP, and MLflow. My-CC.io enforces before execution: PreToolUse and PostToolUse hooks fire at the tool-call boundary, with 100% fire rate, not after a log is written. We cover 151 compliance packs versus approximately 5 in Collibra's AI module — vertical-specific (Healthcare, Financial Services, Mental Health) with categorical pricing floors, not generalist policy templates. Collibra is the Forrester Wave Strong Performer if you need a Fortune-500 data-governance suite that adds AI as a module — starting at $170,000/year with a six-month implementation cycle. My-CC.io is the runtime gate that sits between your data-governance layer and the agent actually executing the action. Self-hosted deployment is available on day one. Pricing published on this page from $4,000–$7,000/yr for the full vertical group — no six-month enterprise procurement cycle required.
Credo AI assesses your AI portfolio and runs governance workflows around it — discovery, policy library, risk-scoring before deployment. My-CC.io does both. We assess: every agent gets a 0 – 1000 TAC Score, the audit chain surfaces risk patterns in real time, and the Insurance & Compliance Report feeds back actionable advice on hardening agent builds, tuning runtime configurations, and improving human-agent interaction. We also enforce: PreToolUse and PostToolUse hooks fire at the tool-call boundary, with 100% fire rate, not just at policy-review time. Their TAC Score is internal to your organization; ours is a portable cross-org credential any partner or relying party can verify. Credo AI is the Forrester Wave Leader if you need policy-library breadth and multi-stakeholder approval workflows. My-CC.io is the assessment loop plus the runtime gate: the trust layer that scores your agents and the bouncer that controls what they are allowed to do. Pricing published on this page — no six-month enterprise sales cycle, no opaque per-developer quote.
IBM watsonx.governance is model-level AI lifecycle governance — bias detection, factsheet automation, OpenPages GRC integration, traditional ML model risk management deeply bound to IBM Cloud. My-CC.io is agent-level enforcement: PreToolUse and PostToolUse hooks fire at the tool-call boundary, with 100% fire rate, across any cloud and any LLM provider. They govern the model; we govern every action the agent takes. IBM is the right choice if you are an IBM Cloud / OpenPages shop with mature ML model-risk programs already in flight and brand trust in regulated industries like banking and insurance. My-CC.io is the runtime gate for teams running modern Claude Code, OpenAI, Bedrock, or Vertex AI agents that are not on IBM's stack. Pricing published on this page from $4,000 – $7,000/yr — no IBM enterprise license required, no bundled-platform minimums, partner channel available for MSPs and consultancies.
Building this in-house typically runs 6 – 9 engineer-months before it is production-ready. The audit chain alone — Ed25519-signed, tamper-evident, retention-aware — is hard to get right under real regulatory scrutiny. Our 151-pack catalog represents years of regulatory research across HIPAA, SOX, GDPR, EU AI Act, NIST AI RMF, ISO 42001, DORA, and every major sector-specific framework. Your engineers ship features; we carry the compliance burden.
The runtime sees identified data at the tool-call boundary — real customer names, real patient records, real credentials, real account numbers. That is the only way to enforce: the hook fires on the actual values, the validator checks the actual values, the audit chain seals the actual values. Identified data is the substrate of governance. PII Shield then classifies and redacts before anything leaves your environment. Your dashboards, your Insurance & Compliance Report, your audit-chain export, and our platform see de-identified aggregates — names redacted, identifiers tokenized, sensitive values stripped. Only your governed agents see the raw data, and only at the moment of the decision. The runtime sees identified data so it can enforce; every human surface shows de-identified data.
The runtime ships as a self-hosted Docker container or a drop-in wrapper for your existing Node.js infrastructure — nothing runs on our servers unless you want it to. We have a documented SOC 2 path, and security reviews are fast-tracked for enterprise prospects. We can join your IT team's assessment call within one business day of your request.
Anthropic, OpenAI, Amazon Bedrock, Azure OpenAI, Google Gemini, DeepSeek, Replicate, and HuggingFace inference endpoints. Orchestrator wrappers are available for LangChain, CrewAI, and AutoGen. Claude Code customers get hook-based enforcement out of the box — no code changes required.
One vertical group pack — $1,000 / pack for 1–3 packs, $4,000 / yr at 4 packs, $5,000 at 5, $6,000 at 6, $7,000 at 7+ (which unlocks the full 151-pack catalog). Individual add-ons outside your group are $400 / yr each. Hard annual billing cap of $7,000 / yr per customer. ISO 27001 license bundled free; GDPR free with EU / Global / International groups. Sixty percent of our pipeline is regulated SMBs — healthcare practices, boutique law firms, independent mortgage brokers, fintech startups — and they pay the same per-agent rates as enterprise customers.
Three options. First, a three-line Connector SDK wrapper around your existing agent calls. Second, a URL swap to proxy.my-cc.io — no code change at all, just route your LLM calls through our proxy. Third, for Claude Code customers, hook-based enforcement fires automatically with zero changes to your application code. Pick whichever fits your stack.
EU AI Act, GDPR, UK GDPR, DORA, and ISO 27001 packs are included in our library. Data residency in EU-West is available on request — no data leaves European infrastructure if you enable it. UK entities get UK GDPR and FCA AI guidance mapped separately from EU GDPR so obligations do not blur post-Brexit.
The audit chain output is designed to be auditor-ready: every event is Ed25519-signed, hash-linked, and tamper-evident. We provide evidence bundles in the format your auditor expects — you (or your auditor) provide the opinions; we provide the verifiable record. SOC 2 Type II and ISO 27001 certifications are on our roadmap for Q3 2026.
Yes. Children's Toys is a dedicated vertical with its own personas for toy designers and for parents and caregivers. The packs map to COPPA, the EU AI Act Article 5 prohibitions on manipulative and exploitative design aimed at children, FTC guidance, and the UK and Canada children's codes. For embedded toys we also ship the Toy-LOM Guard, an on-device runtime that governs the language model inside the toy itself: it runs offline, fails closed when in doubt, and enforces a deterministic safety floor for affect limits, dark-turn handling, engagement integrity, caregiver authority, and child PII without needing to phone home. A caregiver app to control the environment and review behavior audit reports is coming soon.
Your role determines what we show you — the language, the content, and what's relevant to you.
Plain and simple: here is what the safety guard does every single time your child talks to the toy. It is always on, it lives right inside the toy, and it does not need the internet to work.
You will be able to set the rules for your child's toy and check in any time. For now, the safety above is built in and always on.
$3, one time, for a single toy. That safety keeps working offline for good. The parent app and ongoing updates will be a small subscription when they launch.
The Toy-LOM Guard is set up one time from your toy's own design: what it is for, the topics it should stick to, the age it is built for, and the lines it must never cross. From then on it enforces that design on the device, on every turn, so the toy behaves the way you built it and cannot drift.
A toy that runs the guard earns a TAC Score you can show on the box and in your product listing, so parents can see at a glance that it was built to keep their child safe. The score bands and pricing are below.
Prompt-based safety instructions are advisory; they live in the model's context window and can be talked around. The governance runtime does not.
The substrate separates ingress from verification from egress on purpose. Ingress decides what the agent is allowed to see. Verification decides whether the policy file itself has been tampered with, whether the tool is allowlisted, and whether the agent has budget to proceed. Egress is the last line before any side effect reaches the world.
Safe request. The green pulse walks every gate. The action is released and the chain records it.
Policy hash mismatch. Verification refuses the tool because the policy file on disk no longer matches the sealed hash.
Unauthorised action at egress. The egress guard stack catches a tool call the agent should not make. The block is logged with the gate that fired it.
Every governed agent earns a continuous score reflecting how well it operates inside the policies bound to it. From 0 to 1000, a portable trust score for AI agents.
One vertical group pack covers your core regulators. Group tiers: 4 packs $4,000 · 5 packs $5,000 · 6 packs $6,000 · 7+ packs $7,000 (full 151-pack catalog unlocked). Individual add-ons from packs outside your group $400 / yr. Annual billing cap $7,000.
Your request is on our audit chain. The next steps run automatically — see the panel on the right of the form for the order of operations. We respond inside one business day.
Back to home