Skip to main content

EU-hosted · GDPR · NIS2 · DORA · AI Act-ready

Govern every automation before it acts.

AI agents and deterministic workflows — one audit and control layer across every platform where your company builds unattended systems. Identity, pre-execution policy, immutable evidence.

policy_decisionLIVE
  • workflow://n8n/stock-replenishALLOW
  • agent://finance/invoice-botREVIEW
  • agent://sales/crm-syncALLOW
  • workflow://make/invoice-replicationALLOW
policy: eu-default-v3signed · ed25519 · ttl 60s

the_scope

If it acts on your systems without a human clicking, it's an automation.

SPECIES A

Deterministic workflows

Rules, triggers and webhooks that move data or transact on a schedule nobody reviews. No AI model involved — and still in scope of the regulation that governs enterprise systems.

  • n8n
  • Make
  • Zapier
  • Power Automate
  • Workato
  • webhooks
  • scripts
  • Salesforce Flow
  • Zoho
  • HubSpot

SPECIES B

AI agents

Model-driven steps that decide, draft and act — the same operations as species A, with one more variable nobody can replay by hand.

  • Anthropic
  • OpenAI
  • Google
  • Mistral
  • self-hosted
  • Einstein
  • in-house agents

Same obligations. Same blind spot.

Low-code and the rise of agentic AI handed every department the power to build or customise its own corporate tooling. That autonomy is a win for the business (real operational agility) — and a governance problem for whoever answers for IT (CTOs and CISOs, personally accountable for work built by others): the automation estate now grows outside the review process, and a large part of it runs unidentified and unsupervised. Infrastructure in the shadows is no longer an exception: it is a widespread — and dangerous — condition in an automated company.

the_gap

Six questions nobody can answer about the automations already running your business.

Your auditor (in a preventive review) or an inspector (on a filed complaint) will ask, about every automation:

Q-01 · IDENTITY
Unique identifier?
Q-02 · SCOPE
What can it do?
Q-03 · POLICY
Under which policy?
Q-04 · ACCOUNTABILITY
Who is accountable for it?
Q-05 · RECORD
Where is it logged?
Q-06 · PROOF
Can it be verified?

anatomy

Anatomy of an ungoverned flow.

Four ordinary examples that could be running in a company like yours.

flow://finance/invoice-replication

  1. 01 · TRIGGER

    An invoice is issued in the automated billing platform: with Stripe, say, right after an online sale.

  2. 02 · AUTOMATION

    A webhook fires with an API key embedded in an n8n flow.

  3. 03 · WRITE

    The record is replicated into the company’s Sage accounting ERP.

  • Built two years ago
  • No assigned owner
  • Credentials never rotated
  • In no register

Built by an employee who no longer works here, with credentials written in plain text inside an external flow, moving invoicing data into accounting without a line in any internal manual and without a single review in two years. The exposure is immediate: a processing activity missing from the Art. 30 record, a permanent write credential that does not survive Art. 32, an unassessed link in the invoicing chain ahead of VeriFactu, and an uninventoried asset with no owner if NIS2 or DORA reach you.

WITH KIMETAI

With Kimetai the flow is inventoried and classified from day one, its API key becomes a governed identity with an accountable owner, and every write into accounting carries a signed, sealed decision — the evidence VeriFactu, NIS2 and an Art. 30 audit ask for.

value_proposition

01 · DISCOVER · 02 · CLASSIFY · 03 · ENFORCE · 04 · PROVE

  1. 01 · DISCOVER

    We inventory every automation

    With AI or without it, built by IT or by a business team. You connect your tools once and we show you every agent and workflow — including whatever nobody declared.

  2. 02 · CLASSIFY

    We classify risk, owner and applicable framework

    We help you identify each automation, the systems it reads from or writes into, its criticality and the regulation that reaches it — versioned, and reviewed again whenever the flow changes.

  3. 03 · ENFORCE

    We give you pre-execution control

    We give you one configuration environment where you decide whether to allow, block or require human review for every action your agents and workflows execute — all in a single place.

  4. 04 · PROVE

    We document it in a signed audit trail

    We give you the infrastructure to store and immutably seal every action your workflows and agents take, so you hold real evidence in front of a regulator or an auditor.

and_moreover

Enforcement, not observation.

OBSERVABILITY TOOLS

They record what already happened.

  • Logs arrive after execution
  • Alerts fire once the damage is done
  • Forensics for the incident review, not prevention

KIMETAI

Kimetai decides before it happens.

  • Every action requests authorization first
  • Policy evaluated in-line, in milliseconds
  • Signed verdict token, 60-second TTL, sealed in the audit ledger

See how enforcement works →

the_console

One overview. Every automation, every decision.

Workflows and AI agents in the same inventory, the same policy model and the same audit trail — in a console everyone can read the same way.

illustrative view · synthetic data

Overview

tenant: acme-retail-eu · eu-central-1
Automations governed
128
Decisions today
4,102
Blocked pre-execution
17

recent_decisions

  • workflow://make/invoice-replicationALLOW
  • agent://finance/invoice-botREVIEW
  • workflow://n8n/nightly-crm-exportBLOCK
  • agent://sales/crm-syncALLOW

simulated on last 30 days: 4 would-block · 0 breaking changes

architecture

One single tool for your whole automation inventory.

Wherever your automations were built, governance converges in one place.

ORCHESTRATION PLATFORMS

  • n8n
  • Make
  • Zapier
  • Power Automate
  • Workato

MODELS AND AGENTS

  • Anthropic
  • OpenAI
  • Google
  • Mistral
  • self-hosted
  • in-house

EMBEDDED IN BUSINESS APPS

  • Salesforce
  • Zoho
  • HubSpot
  • SAP
  • Microsoft 365
  • ServiceNow

KIMETAI CONTROL PLANE

One inventory · one permission model · one audit trail

Third-party names are integration targets or technologies already integrated in Kimetai.

regulation_timeline

Your automation is already regulated — by five frameworks at once.

Pick your country to see what applies, ordered by date of applicability.

  1. Applies across the EU

    GDPR · Reg. (EU) 2016/679

    in force

    Record of processing activities (Art. 30) and the right to human intervention in automated decisions (Art. 22.3).

    In force since 2018

  2. Applies across the EU

    NIS2 · Dir. (EU) 2022/2555

    in force

    Asset management as a mandatory measure, with direct accountability for management bodies.

    Since Oct 2024

  3. Applies across the EU

    DORA · Reg. (EU) 2022/2554

    in force

    Complete inventory of ICT assets and dependencies, plus a register of third-party providers.

    Since Jan 2025

  4. Applies across the EU

    AI Act · transparency (Art. 50)

    in force

    Systems that interact with people or generate synthetic content must disclose it.

    02-08-2026

  5. Applies across the EU

    AI Act · high risk (Annex III)

    future

    Human oversight, event logging and technical dossier.

    02-12-2027

  6. Applies across the EU

    ViDA · intra-EU digital reporting

    future

    Converges the national invoicing regimes into intra-EU digital reporting.

    From 2030

Six different national invoicing regimes, converging into ViDA from 2030. Select a country to see the one that applies to you.

NIS2 national transposition and thresholds vary by country — verify your own case.
Informational. Not legal advice. · Last reviewed: August 2026

See it running on your own automations.

We map your inventory with you: what runs, who owns it, which frameworks reach it.