Security & governance
AI proposes, people approve, systems execute, and every action remains on record
These statements are architecture, not a slogan. Explore what Patty controls, how enforcement works, and why each outcome can be verified.
Foundation: the DARI protocol
An open protocol sits beneath every control domain. Authority begins with signed delegation, and each action ends with a verifiable receipt.
Explore DARI →- Propose
AI proposes the next action within the work context and policy boundary.
Intent · target · expected impact - Approve
An authorized person reviews scope and risk, then signs the authority.
Approver · scope · validity - Execute
The control kernel applies only approved authority through isolated tools and infrastructure.
Policy decision · outcome - Record
The chain from proposal to outcome is sealed into a verifiable receipt.
Provenance · signature · audit
Control domains
DARI ProtocolReceipts, not trust, for AI actions — the open delegated-authorization and receipt infrastructure.Security ModelDefense-in-depth authorization across every AI action.Audit & ProvenanceDARI receipts, line-level human/AI provenance linked to Git, encrypted trace vaults.LLM Gateway & Policy EngineServer-side model authority; per-request policy decisions before infra contact.DLP & PrivacyInput masking before retrieval/LLM contact; privacy-law-aligned handling.Responsible AIAI proposes, humans approve, systems execute, everything records.AI Action MonitoringAgent identities as first-class citizens; anomaly detection; pause/resume/terminate controls.Threat DefensePrompt-injection resistance, tool isolation, engine-level boundaries, output moderation.Model SecuritySigned deployments, weight protection, adapter/catalog supply-chain integrity.Data Residency & SovereigntyKorean data residency; closed-network profiles; residency-honoring region failover.Identity & AccessHuman/AI dual identity model; COSE-signed credentials; scoped agent privileges.Regulatory ReadinessEU AI Act awareness; Korean AI legislation readiness; regulator-facing evidence export.Compliance & CertificationsHonest separation between certifications held and roadmap items.