01 / CUSTOMER-HOSTED
Your infrastructure. Your data.
No SaaS layer. No data egress to VoidAi. The control plane runs in your environment. Per-customer residency by architecture — not a feature flag.
Enterprise tier
Three architectural invariants pre-answer most procurement and security questions before they're asked. SOC 2-aligned by architecture, not retrofit. Single-tenant by design.
The three invariants
01 / CUSTOMER-HOSTED
No SaaS layer. No data egress to VoidAi. The control plane runs in your environment. Per-customer residency by architecture — not a feature flag.
02 / AUDIT-LOG FIRST
Append-only JSONL ledger. 12-field canonical schema. Every Claude call, every state mutation, every external tool invocation — logged before it commits. Forensic by default.
03 / CAPABILITY GATES
Each agent declares an explicit allowlist. The Guardian refuses any non-matching action. Red-line list (payment.*, secrets.export, audit.attest) overrides anything an agent profile tries to grant.
The architecture, visualized
Five enterprise-tier-only agents
On top of the core 19-agent platform, five additional agents handle the enterprise procurement + delivery layer. Same audit log, same Guardian, same WriteShield primitives — different capability scope.
compliance-officer
SOC 2 / GDPR / HIPAA evidence-gathering, policy drafts, audit-prep coordination.
customer-success-manager
Post-sale onboarding tracking, QBR drafts, NPS, escalation routing.
security-questionnaire-responder
Drafts answers to vendor security questionnaires from a 50+ canonical answer library.
msa-builder
Per-deal MSA / Order Form / SOW drafts from lawyer-reviewed templates.
enterprise-account-manager
F500 sales motion: discovery, demo prep, deal stage tracking, MSA-ready handoff.
Procurement quick-answers
Data residency
Customer-hosted. Per-customer = per-residency.
Multi-tenant isolation
Single-tenant by architecture. No shared database.
Audit trail of agent actions
Append-only JSONL, 12-field schema, never overwritten.
Access control to capabilities
Allowlist per agent, red-line list immutable.
Change management
spec-before-code + 48h shadow + eval-driven-deployment.
Incident response
Sentry novel-error capture + per-error stub workflow.
BYOK for sensitive workloads
Customer brings own Anthropic key; vendor never sees it.
SOC 2 Type II
Readiness via Vanta in progress; architecturally aligned today.
Full reference architecture and 50-question VDDQ answer library available under NDA. Ask in the contact form below.
Try the Guardian
The capability gate is the architectural answer to "what stops a compromised agent from doing damage?" Click any action to see the decision. Red-line items are immutable across every agent profile, every tier, every customer.
Guardian — capability gate
deny-by-default · red-line list immutable
Try an action
Cyan = within allowlist. Yellow = denied by deny-list. Magenta = red-line — immutable.
Guardian decision
Awaiting input.
Same rules apply across all 24 agents in your install.
What you watch
Your team gets a localhost dashboard refreshing every 10 seconds. Health score, weekly cost, audit-row count, agent status — at a glance.
VOIDAi
Your agents are GREEN.
Health score
94
GREEN
Cost this week
$2.47
of $25.00 cap
Audit rows (24h)
1,206
0 failures
Active agents
5
running on your host
Latest activity
Agent roster
Three packagings, one product
// SOLO
$5–12k
engagement
Audience
Founders + small teams
Agents
Core 19-agent platform
Sales motion
Web inbound + content
// MID
$15–35k
+ MRR
Audience
Mid-market ops teams
Agents
Core 19 + customer tuning
Sales motion
Targeted outbound
// ENTERPRISE
$75–250k
+ MRR
Audience
Fortune 500 / regulated
Agents
Core 19 + 5 enterprise agents
Sales motion
F500 procurement-cycle
Next step
Procurement teams, security reviewers, and architects: tell me your checkboxes. I'll respond with the matching answer-library entries and a per-deployment customization plan. Solo founder; honest timelines.
Contact — Enterprise inquiry