Diligence: The Governance Layer · Triodian

Diligence

A governance layer right where the AI acts.

Where a generic AI approximates and acts without accountability, the Triodian appliance enforces declared constraints in hardware and emits tamper-evident proof at each consequential action, a verifiable check inserted at the exact moment a recommendation becomes a real-world action.

5 hardware-rooted subsystems · 6-stage non-bypassable order
Six-stage non-bypassable order, each action checked, admitted or blocked before it acts.

You rely on software guardrails and human oversight to keep the AI in bounds, and most of the time they hold. They hold until machine speed, and then they don't.

Why hardware

Software guardrails get bypassed at machine speed.

In November 2025, a state-sponsored group was reported to have run an autonomous AI agent through a full intrusion campaign against roughly thirty organisations, with a large share of the operation executed with no human in the loop. We cite it as reported, as an illustration of the class of risk, consequential AI actions moving faster than human oversight. Guardrails enforced in software, by the same layer the model can influence, are bypassable at the speed the machine moves. Enforcement that holds has to sit beneath that layer, in hardware. That is what the appliance is.

Diligence diagram
Drops in between the model and the action

How it works

What governing in hardware means

An untrusted model proposes. A tamper-resistant layer decides whether the action is permitted. Proof of that decision is written where anyone can check it. The order is fixed and cannot be bypassed.

Step 01

The AI layer

An untrusted frontier model, any of them, produces a recommendation. It is treated as capable but unaccountable: nothing it asserts about its own compliance is taken on trust.

Untrusted
Step 02

The Deterministic Governance Architecture

Each proposed action is checked against constraints declared in advance. The appliance physically refuses to actuate outside them, enforcement sits beneath the layer that could be incentivised to bypass it.

Enforced in hardware
Step 03

The proof

Each consequential action emits a cryptographic token, written to a tamper-evident ledger the operator, a regulator and the public can audit, evidence generated by the system, not authored about it afterward.

Verifiable

What it changes

Enforcement that holds, and a record that survives

Without it

Oversight that decays with its people

Enforcement depends on a human whose competence to supervise the machine is itself quietly eroding, with no record of what was machine-generated and no signal that the check has gone nominal. The control reads as intact right up to the moment it fails.

With Triodian

Enforcement that doesn’t decay, and provenance that survives

The constraint is enforced in hardware whether or not the reviewer’s skill stays intact, and each decision is bound to a tamper-evident record of what was checked, restoring the machine/human boundary that under-disclosed reliance otherwise erases.

Interoperability

One substrate, many compliance vocabularies

The appliance speaks an open governance protocol, the UGP, so a single substrate can serve sectors with different compliance vocabularies. It is positioned as an interoperability standard, not a second product: the way a governed action in banking and a governed action in energy can be expressed, enforced and proven through the same layer.

Sector compliance rules declared
UGP · open governance protocol one layer
Enforced & proven action verifiable

The governed-reasoning engine behind the appliance already runs a live product in production, see how pinpole grounds this.

Discuss a deployment →

How this differs from what already ships, EQTY Lab, Fiddler, Cisco/Robust Intelligence, IBM watsonx.governance, told honestly.

How we compare →