Unknown runtime state
Model registries and policy documents rarely prove what is actually running inside customer environments.
NeoVail helps enterprises govern models, agents, MCP servers, and AI infrastructure through regional control planes, customer-local Sentinel enforcement, and audit-supporting evidence.
The new attack surface
Enterprises are deploying models, agents, and MCP-connected tools faster than governance, audit, and runtime enforcement can keep up. Tool calls, credentials, files, workflows, and regulated systems need decisions before execution.
Model registries and policy documents rarely prove what is actually running inside customer environments.
MCP servers can expose powerful tools, but agent-side permission prompts are not a reliable enterprise control boundary.
Regulated teams need evidence that reflects current runtime state, not spreadsheets assembled after an incident or audit request.
Runtime decision
NeoVail evaluates tool, identity, risk, policy, and runtime context in the same hop. The decision is bound to the policy version that made it and to the evidence record it produces.
Action executes immediately with identity and evidence attached.
Action proceeds with a flagged record for review.
Action is blocked before a tool, credential, or model is touched.
Routed to approvers with expiry and escalation.
Dry-run outcome and side effects captured first.
Runtime decision flow
Every action an agent proposes follows the same path. The decision is the audit record, so there is no second reporting pipeline to reconcile.
models · agents · cli
OIDC · SCIM · groups
MCP registry · scopes
allow · warn · deny
expiry · escalation
success · error · drift
asset graph · export
AI Asset Graph
NeoVail maps the assets, identities, policies, and evidence that determine AI risk. The graph makes governance inspectable across model, agent, MCP, and runtime layers.

Verified against trusted registry records and expected digests.
Mapped to users, groups, tools, environments, and policy decisions.
Controlled through gateway allow and deny enforcement.
Sentinel Runtime Enforcement
Sentinel nodes run in the customer environment to verify runtime state, detect drift, and enforce policy without moving sensitive runtime evidence onto the public website.
Validate deployed models against trusted registry records and approved deployment context.
Detect when a runtime artifact no longer matches the expected digest, version, or provenance record.
Apply enterprise policy at runtime with clear outcomes, evidence, and escalation paths.
Roll out controls safely by observing would-block outcomes before moving into enforcement.
MCP Governance
NeoVail treats MCP servers as governed enterprise assets with identity-aware access, gateway-based allow and deny decisions, and a full audit trail.
Track approved MCP servers, ownership, risk, and allowed environments.
Map access to enterprise users and groups instead of relying on local agent configuration.
Enforce allow and deny policy before tools are invoked.
Record who attempted what, through which agent, against which server, and why it was allowed or blocked.
Beyond point tools
NeoVail is not just an MCP proxy, coding-agent hook, local sandbox, policy DSL, or compliance dashboard. It connects those control surfaces into a single system of record.
Inline tool gating
No asset graph
Local prompt audit
No runtime decision
Filesystem isolation
No evidence pack
Rule authoring
No registry
Post-hoc reporting
No enforcement
Integrations
NeoVail meets your environment where it lives: frontier model APIs, local model servers, agent CLIs, MCP gateways, identity providers, and compliance pipelines.
OIDC · SCIM · groups
frontier + local
CLI + IDE agents
servers · gateways
inbox + chatops
evidence + exports
Compliance and Residency
NeoVail is designed to support EU AI Act readiness work, DORA-aligned evidence workflows, regional control planes, customer-local runtime telemetry, and audit evidence exports. These statements describe product intent and should not be read as a legal certification or regulatory conformity assessment.
Security posture
NeoVail’s public website remains separate from control-plane operations. The product architecture is built around regional tenancy, local enforcement, least privilege, and runtime evidence.
Control planes designed around regional deployment and residency requirements.
Runtime checks and enforcement run near customer models, agents, and MCP servers.
Unknown tools and unbound MCP servers can be blocked before execution.
Access decisions can include users, groups, tools, scopes, environments, and policy versions.
Every decision links identity, policy, runtime context, and outcome into an exportable record.
The public site stores no customer evidence, secrets, telemetry, or enforcement state.
Architecture
The public website is separate from the SaaS control plane, regional telemetry intake, and customer-local enforcement layer.
Static marketing pages, legal notices, trust pages, and demo entry points.
Policy administration, AI asset graph, evidence review, and customer workflow management.
Sentinel telemetry intake with customer-selected residency, handling, and retention rules.
Local enforcement boundary where verification, policy checks, and blocking happen before actions proceed.
Demo
The NeoVail demo shows how governance teams move from inventory to runtime evidence without relying on fragile manual checks.
See how NeoVail governs models, agents, MCP servers, and runtime evidence across enterprise AI environments.