Agentic governance substrate for regulated enterprises.
AI agents operating in regulated environments have a problem that session-based memory does not solve: decisions made by an agent need to be persistent, tamper-evident, portable across institutional boundaries, and auditable by a regulator who may inspect them years later.
truc addresses this with two components that are inseparable by design:
The artifact is a single portable file — a property graph sealed with post-quantum cryptography. It carries the agent's decision context, the governance policies under which decisions were made, the system contract registry for connected infrastructure, and an append-only audit chain. The artifact provides tamper-evidence natively: any modification is detectable by anyone holding the verification key. Tamper-proofness — where even the custodian cannot rewrite history without detection — requires a customer-selected external witness. The artifact is the durable governance record. It belongs to the customer. LGT.io never holds it.
The engine speaks openCypher over the Bolt wire protocol, providing a standard query surface over the loaded artifact. Any tooling that works with a Bolt-compatible graph database works with truc unchanged.
truc is designed to run on infrastructure chosen and controlled by the customer. truc transmits no content externally under any operating mode. The only permitted outbound interaction is the optional hash-only Mode P integrity anchor to a customer-nominated witness; all other modes require no outbound network interaction whatsoever. LGT.io operates no runtime dependency in any mode. The artifact is a file the customer holds. The engine runs where the customer chooses.
A compliance layer records what happened. It answers the auditor's question: did this action occur, and was it within permitted parameters?
A purpose governance layer records something fundamentally different: what was supposed to happen, under whose authority, against which business objective, at what cost, and whether the outcome served the intended purpose.
That distinction — between recording activity and capturing purpose — is what makes governed Agentic AI possible.
If every agent action is governed in the context of defined business objectives — with purpose constraints that tie each action to an intended outcome — then the cost and value of every agent interaction becomes attributable in real time. Not as an average across a programme. Not as a batch report at period end. Per action, per agent, per objective, per outcome.
The consequences cascade through every function that currently depends on aggregated, historic reporting
Your CTO group can build things. Your compliance team understands the law as written. The gap between them — translating DUAA purpose compatibility requirements and EU AI Act obligations into actual agent workflow architecture decisions — is where most organisations are currently exposed.
We published the five-layer governance architecture specification and understand the architecture required not because we consulted on it, but because we built the open specification that defines it.
We have already done the structural thinking, and we work with you to apply it to your specific deployment.
Email: hello@lgt.io