REYour AI runs your rules. Not its training data.
FILED2026-05-14 · ctrlai.com
BY⌃ Ctrl AI · est. 2026
REFDOC-001

Your AI runs your rules.
Not its training data.

Upload your policies. Your AI invokes them as typed Ctrls — answers, calculations, data lookups, signed actions. Every call leaves an Ed25519 Receipt of Record your auditor can verify.

BYOK at every tier·Ed25519-signed receipts·EU AI Act · SOC 2 · DORA
Receipt of Record
# 1,847

CTRL
compute-travel-expense-pre-approval
VERSION
v3
ISSUED
2026-05-12 14:32:07 UTC
SEALED BY
Sarah Chen · Finance
RECEIPT
rcpt_3f7a92b8e4c1
ROOT
0x4e2a...b71c

in.amount $2,400.00
in.tier "engineering"
out.approved true
out.gate "none"
post.0 outputs.approved is boolean ✓
post.1 outputs.gate matches enum ✓

SEALED · VERIFIED
ed25519:7a4f9c8e2d1b5036

Verify offline → curl ctrlai.com/api/receipts/rcpt_3f7a92b8e4c1

§1 · The frame

Your AI is creative about how to help. It is not creative about your rules.

Most AI products either over-promise (“the AI runs your company”) or under-deliver (“the AI drafts an email”). Ctrl AI does the procedural work — the 60–80% of white-collar work that is routing, reconciling, checking, drafting. Your team verifies. The verify loop replaces the processing loop. Your team got their week back.

§1·1 · The AI is creative in

How to help

Reading the question. Picking the right Ctrl. Composing multi-step plans. Asking clarifying questions. Spotting gaps in your coverage.

§1·2 · The AI is forbidden from

What your rules mean

Inventing logic. Judging policy questions. Generating numbers or facts from training data. Acting destructively without a signed gate.

§1·3 · Your team owns

Judgment, not processing

The 20–40% of work that needs judgment: sign-offs, exceptions, hard people calls, strategy. The procedural 60–80% — the part that ate the week — is handled.

§2 · The thesis

Three primitives. One signed unit.

LLMs guess. RAG paraphrases. Ctrl AI answers from typed Ctrls your humans signed — every reply, every action, every time. Hallucination is not mitigated; it is structurally impossible.

§2·1 · How

Ctrls

Typed callable functions signed by humans. Input schema. Output schema. Post-conditions. The LLM picks a Ctrl and calls it — it does not invent behaviour from prose.

§2·2 · Why

Missions

Standing directives with success criteria. Auto-evaluated as Ctrls run. The agent has commitments, not just answers.

§2·3 · What

Cases

Durable working memory with an append-only event log. A multi-week decision is a single Case with every signed action attached.

Live trace · /askscripted demo
$ /ask
The LLM does not invent behaviour. It picks a Ctrl + calls it.
§3 · The moment

Upload a folder. Ninety seconds to your first cited answer.

The visceral demo. No abstract pitch, no decks. You see your own company reflected back, and you watch the AI answer your question from your rules — with receipts. This is the whole product.

  1. §3·1

    Ingest

    Drop a folder of your policies — PDF, DOCX, MD, HTML.

    Cloud connectors for Drive / SharePoint / Notion ship next. Until then, drag-drop is your friend. 50 files, 25 MB extracted text.

  2. §3·2

    Posture

    In 60 seconds, your company reflected back: departments, roles, gaps.

    “Your company has 6 departments. Legal has 47 docs and 0 Ctrls. Finance has 12 docs and 0 Ctrls. You appear to be missing documentation for Security/IT.”

  3. §3·3

    Ask

    Type a question. Every sentence cites a signed Ctrl. Every chip opens the Receipt.

    Pick from suggested questions derived from your own docs, or type your own. The answer is a sequence of typed Ctrl invocations, each producing a verifiable receipt.

Magic moment · 90 seconds, compressedscripted demo
  1. §3·1Ingestrunning
  2. §3·2Posture
    queued
  3. §3·3Ask
    queued
Drop folder · 60s posture · cited answer · loops automatically

Already onboarded? See every workspace surface →

§4 · The work

Every reply, a signed Ctrl. Every action, a Receipt.

The work your team does every day — approvals, reviews, decisions — becomes typed Ctrls a human signs. The LLM has one job: pick the right Ctrl and call it. It cannot reply any other way.

DepartmentExample Ctrls
FinanceExpense approvals · Vendor onboarding · Quarterly close · Budget transfers
LegalDPA review · DSAR responses · Ctrl redlining · NDA triage
CompliancePolicy Q&A · Audit evidence · Control attestations · Risk register updates
RevOpsPricing approvals · Renewal cadence · Quota changes · Commission audits
Customer SuccessGDPR requests · Refund decisions · Incident comms · Account reviews
People OpsHiring screens · Policy lookups · Onboarding flows · PTO exceptions

Your workflow isn’t here? Ctrls are typed callable functions — anything a human team handles on a checklist becomes one. Tell us about yours.

§5 · Universal Provenance

Every action leaves a Receipt of Record.

On every invocation we sign the inputs, outputs, signers, and trust level with an Ed25519 key, then append the digest to a chained-hash transparency log. Any counterparty — your auditor, your customer, your regulator — can verify the receipt offline with one curl and one signature check.

Ed25519 signatures over canonical JSON
Append-only transparency log, root hash published
Public verifier endpoints at /.well-known
Maps to EU AI Act Art. 12 · SOC 2 · ISO 42001
# Verify any Ctrl AI receipt offline
curl -s https://ctrlai.com/api/receipts/rcpt_3f7a92b8e4c1 \
  | jq '.receipt' > receipt.json

# Fetch the public signing key
curl -s https://ctrlai.com/.well-known/ctrlai/receipt-keys \
  > keys.json

# Verify the Ed25519 signature
node verify.js receipt.json keys.json
# → SEALED · entry #1,847 · root 0x4e2a...b71c ✓

No SDK required · No vendor lock · Cryptographic, not theatrical

Provenance loop · seal → append → verifyscripted demo
01Receipt
CTRL compute-travel-expense-pre-approval
02Transparency log
03Verifier · offline
Cryptographic, not theatrical. Anyone can verify any receipt.
§6 · Compliance Packs

You don’t author governance. You install it.

Expert co-signed bundles of typed Ctrls — 30–60 templates each, pre-mapped to the regulation’s clauses. Install in five minutes. Map your SOC 2 controls to Ctrls. Map every HIPAA Audit Control to a Ctrl. The auditor reads your receipts.

Pack IDTitle · CoverageJurisdictionStatus
PACK-B2BSAAS-01
B2B SaaS Rev-Ops
Pricing · Approval thresholds · Renewal cadence · Customer health
GlobalAvailable
PACK-EU-AIACT-01
EU AI Act Starter
Articles 12 · 13 · 14 · log retention · oversight gates
EUAvailable
PACK-DORA-01
DORA AI Risk
ICT risk · operational resilience · third-party register
EU · FinServAvailable
PACK-SOC2-01
SOC 2 Type II Operating
Access reviews · change mgmt · incident response · vendor risk
GlobalQ3 2026
PACK-GDPR-01
GDPR Data Processing
DPIA · DSAR · cross-border transfers · breach notification
EUQ3 2026
PACK-HIPAA-01
HIPAA US Healthcare
PHI handling · access controls · audit logs · BAAs
USQ4 2026
Browse the pack catalog All Packs included on Starter and above · Expert co-signing available on Business · Custom Packs: hello@ctrlai.com
§7 · Pricing

Four tiers. BYOK at every tier.

You pay Anthropic, OpenAI, or Google directly for inference. We charge for Ctrls, Receipts, and Packs — never per seat. Free is permanent, Starter and Business are self-serve. Talk to us only if you’re Enterprise.

Tier · 01

Free

$0
forever · + BYOK

For individuals and tiny teams. Permanently free — not a trial.

  • Up to 10 people
  • 5 Packs installed
  • 25 signed Ctrls
  • 100 invocations / month
  • Public Trust Portal
Tier · 02

Starter

From $200
per month · + BYOK

For small companies. Self-serve credit card; no sales call.

  • Up to 50 people
  • All Packs included
  • 200 signed Ctrls
  • Unlimited invocations
  • Private Trust Portal
  • Email support
Tier · 03 · Most popular

Business

From $1,500
per month · + BYOK

For mid-market. Unlimited Ctrls, SSO, custom Packs.

  • Up to 250 people
  • Unlimited signed Ctrls
  • SSO + SAML
  • Custom Packs co-signed
  • Advanced delegations
  • Priority support
Tier · 04

Enterprise

From $50k
per year · custom

For 250+ ppl, regulated industries, named signers.

  • Unlimited everything
  • Concierge onboarding
  • SOC 2 report under NDA
  • Dedicated CS + SLAs
  • On-prem option (year 2)
  • BYOK or our keys
BYOK at every tier. Your Anthropic / OpenAI / Google bill stays with you.
No per-seat pricing. Adoption scales without punishment.
Open spec, open verifier. Anyone can verify any receipt without trusting us.

The Ctrl is signed.
The Receipt is the proof.

Upload a folder. Ninety seconds to your first cited answer. The work your team actually does — approvals, reviews, decisions — backed by Ctrls humans signed and Receipts your auditor can verify.