A control plane for AI agents · Built in Canada

Governed AI, on sovereign ground.

Cloister runs on your machines, answers to your policies, and keeps a record that holds up. It does not make agents smarter. It makes them governable.

Talk to us Read the source
The cloister of Santa Juliana, Santillana del Mar.

A cloister is a covered walk — a simple, constrained path. That is the whole idea. Agents are useful. Ungoverned agents are a liability. Cloister keeps the work on the path.


The market deployed agents before it governed them.

Most organizations now have agents in production they cannot audit, cannot halt safely, and cannot prove were authorized to act. Cloister is the governance layer they skipped.

Every action is checked against your policy before it runs. Every decision is written to a durable audit log. And the stop actually stops.

81%
of deployed AI agents lack full security approval
40%
of agentic AI projects may be cancelled by 2027 (Gartner)
AI for All
Canada's 2026 national AI strategy leads with trust and sovereignty; the EU AI Act's transparency duties are already in force

The governed flow

Nothing runs until it has been evaluated. Everything that runs is on the record.

01
Task arrives
A request is created and evaluated against the rubric.
02
Laws
Forbidden actions halt immediately. Non-negotiable.
03
Policy gates
May pass, deny, or wait on a human or LLM sensor.
04
Rules
Quantitative bounds checked against declared scope.
05
Dispatch
Only then does the agent run, on the backend you chose.
06
Record
Audit log, health telemetry, provenance-tracked memory.

Fail-closed. A law violation halts immediately. A policy gate can wait for a named human. The audit trail survives failure.


Three tiers of authority

Deterministic evaluation before any agent is invoked. Not a filter on outputs — a boundary on execution.

Law
What may never happen

Forbidden actions — force-push to main, drop a database, commit credentials — halt the task outright. No sensor, no appeal.

Policy
Where judgment is required

Governance gates that can require a named human approval or an LLM evaluation before work proceeds, triggered by the kind of boundary being crossed.

Rule
How far work may reach

Quantitative bounds on declared scope — files touched, lines changed — checked deterministically before dispatch.


Runs where your data lives

Two deployment modes. Both on your infrastructure. Neither phones home.

Cloistered
Fully air-gapped

On-premise, disconnected, with local model backends. No external calls, no exceptions. For Protected workloads and networks that never touch the internet.

·Local models via Ollama and OpenAI-compatible endpoints
·Durable state on your hardware, encrypted at rest
·Complete audit and replay without leaving the room
Connected
Sovereign, with chosen providers

Your infrastructure and your keys, with the frontier providers you approve. Every call governed, every response on the record.

·Anthropic, OpenAI-compatible, and CLI backends with fallback chains
·Policy decides which provider a task class may reach
·Governance state never leaves your deployment

Made on Vancouver Island

Canadian ground. Canadian rules.

Cloister is built in British Columbia and designed for organizations that cannot send their decisions south. The governance engine — everything one team needs to run governed agents — is open source under MIT. The fleet control plane is source-available (BUSL-1.1), with every version converting to MIT within four years: vendor-death insurance for sovereign buyers, in the license itself. Your policies, your audit trail, and your agents' memory stay on infrastructure you control — in Canada, if that is where you put it.

Aligned with AI for All
Canada's AI for All strategy leads with trust and sovereignty, not a binding act. Content-hashed policy gives a cryptographic answer to "what rules were in force when this decision was made?" — provable trust, on infrastructure you control.
Data residency, by construction
No SaaS control plane, no US cloud dependency. Governance state lives where you deploy it.
Built for public-sector patience
Named human approvals, separation of duties, and durable process evidence — the things procurement asks about on page one.

Dashboards assess. Monitors watch. Cloister enforces.

Governance dashboards
Assess models and register agents for audit. They answer "is this compliant?" — at the assessment layer, after the fact.
Agent security monitors
Discover and watch agent activity across the enterprise. They can tell you an agent acted. They cannot stop it from acting.
Cloister
Enforces policy at the moment of execution. Who authorized the action, what policy was in force, whether it can be replayed and recovered — answered by construction.
The Canadian Shield — some of the oldest exposed rock on Earth.

Govern what you have already deployed.

We are working with early partners in government, finance, and health. If that is you, we should talk.

Talk to us Read the source