Ginkgo-AI
Book a Demo Request a Briefing
Home / Platform
The architecture

Five governed layers.
One shared evidence trail.

Governed Intelligence powered by METIS™ is a purpose-built five-layer control plane that mediates every interaction — enforcing policy, maintaining lineage, and governing every connection between your systems and your AI.

Governed Intelligence powered by METIS — five-layer control plane
The architecture

Five layers. Every interaction. One evidence trail.

Layer 1 · Interface

Interface

The single entry point for every user, application, and API client. Every request enters here and is immediately subject to governance at Layer 3.

Layer 2 · Tool Factory

Tool Factory

Orchestrates tool composition, agent coordination, and workflow execution. Every tool is registered, versioned, and policy-bound. Every tool call logged before execution.

Control fabricLayer 3 · Governance

Governance & Policy

Policy engine, identity and access management, data classification, and the audit ledger. Every other layer is subject to Layer 3 — there is no path around it.

Layer 4 · Argus

Argus Integration Server

Manages every connection between the control plane and external systems. Kill-switch control per connector. Governed API mediation. All traffic logged.

Layer 5 · Application

Decision Modules

Application-layer modules that convert governed intelligence into documented outcomes. Root Cause Analysis, Forensic Accounting, Predictive Budgeting — each with a defensible output and complete evidence chain.

USERS · APPS · CLIENTS GOVERNED INTELLIGENCE POWERED BY METIS™ L1 · INTERFACEInterface L2 · TOOL FACTORYTool Factory L3 · CONTROL FABRICGovernance & Policy L4 · ARGUS INTEGRATION SERVERIntegration Server L5 · APPLICATIONDecision Modules SYSTEMS · DATA · MODELS · DECISIONS
Layer 4

Argus Integration Server

Every connection between the control plane and an external system runs through Argus. No shadow integrations. No unmediated data access.

Kill-switch control

Revoke any connector instantly

Any connector can be disabled without a code change, without a deployment, without delay. When a data source changes status, the integration stops immediately.

Connector registry

Declared, versioned, permissioned

Every integration is registered in the Argus connector registry. The same governance that applies to users applies to integrations — no exceptions.

Governed mediation

Every payload inspected and logged

Every inbound and outbound API call is inspected, classified, and logged. Data sensitivity labels are applied before content enters the control plane.

Security & compliance

A hardened perimeter with mapped controls

Healthcare

HIPAA & HITECH

PHI classification at ingestion, BAA-ready architecture, access scoped to care role, full audit trail for covered entity compliance.

Federal & state

FedRAMP & CJIS

Deployment options for IL4/IL5 environments. CJIS Security Policy controls mapped to the Governance layer. Air-gap ready.

Privacy

GDPR & CCPA

Data residency controls, right-to-erasure hooks, consent management, and classification-based access enforcement.

AI governance

NIST AI RMF

Govern, Map, Measure, and Manage functions operationalized in the control plane. Audit evidence is continuous, not point-in-time.

Education

FERPA

Student record classification, consent-scoped data access, and disclosure logging built into the governance layer.

Deployment

Cryptographic separation

Classified and unclassified workloads on shared infrastructure with cryptographic boundaries. No cross-contamination.

Audit & lineage

Reconstruct any decision, on demand

Tamper-evident ledger

Append-only audit record. Every event is cryptographically linked to the prior event. No gaps, no edits, no deletions.

Full retrieval lineage

Every retrieved document, every source span, every passage that contributed to a response is recorded with its classification label.

Policy version at decision time

The exact policy version in effect at the time of every decision is recorded. Policy drift cannot retroactively invalidate evidence.

Actor-level attribution

Every event is attributed to a specific human user, service account, or named agent — with the permissions active at that moment.

See the control plane against your environment.

We will map the five layers to your systems, data sources, and compliance obligations in a working session.

Book a Demo Request an Executive Briefing