AI alignment & visibility

See your AI. Steer your AI.

Leyn turns your organisation's own policies into the live standard that governs every AI interaction — across every provider, agent, and use case. Visibility you can act on, alignment you can prove, and a stop control at the point of action.

  • Provider-agnostic
  • EU data residency
  • Feeds your GRC, doesn't replace it
  • Built for the agentic enterprise

Why this is hard

Know what AI you're running. Govern what every system produces.

To govern AI effectively, enterprises need two things: a clear picture of every system running across their provider estate, and a way to ensure every interaction is aligned with their own organisational context. Getting that visibility is a genuine challenge — AI spreads across Bedrock, Copilot Studio, AI Foundry, Vertex, and direct API keys, without clear identified ownership. Ensuring those flows are aligned to your specific policies, consistently across platforms, at the pace AI operates, is the harder part — and what no existing category addresses end to end.

When something goes wrong, no one can answer the only question that matters: what was this agent allowed to do, and where is the evidence it stayed within those limits?

What human oversight used to solve

As AI moves from a tool your people use to a body of work they can't review by hand, three things quietly break.

Opaqueness

Total spend per AI provider is visible, but cost at the individual system level — with anomaly detection to flag unexpected shifts as errors or scope change — is not. The value and the risk of what they produce is not — as AI use becomes more autonomous, detection-based oversight with risk-proportionate interaction becomes a required feedback loop, not an optional control.

Alignment

Well-intentioned local use doesn't add up to output aligned with strategy, policy, or the law of the jurisdiction the traffic touches. Everyone optimises locally; Leyn provides the oversight from aggregate to system to action.

Consistency

A one-off sign-off at deployment provides limited assurance about behaviour three months later. Non-deterministic systems drift as models update and prompts change.

A committee that meets quarterly doesn't scale. Leyn provides a system whose evaluation rate matches your agents' action rate — and whose criteria are your own.

What makes Leyn different

Govern the content, not just the asset.

Every other category governs an asset — an agent, a registry entry, an issued identity — and infers safety from properties of that asset. Knowing AI exists is perceived risk versus actual risk. A correctly authenticated agent can still produce a non-compliant recommendation.

Leyn governs the actual content: the prompts, tool calls, results, and responses flowing in and out — evaluated against your own translated policy, at runtime, across every provider. The same standard governs both the design of an agent before it ships and every live interaction after. That isn't a feature bolted on top. It's a different place to stand.

Identity tells you who's at the door. Leyn tells you what they did once inside — and whether it was within policy.

The Leyn loop

Your policy becomes the control. Then it keeps working.

At the centre sits the Engine — it reads your real policy documents and turns them into machine-evaluable criteria. Everything else is what those criteria do.

SEE

One place to look, finally

Route AI traffic through one gateway and capture every interaction across every provider, with full metadata.

ENC

Encode

The Engine translates your policies, values, and risk appetite into structured, testable criteria — each traceable to a verbatim line in your source documents.

ALN

Align

Those criteria are applied inline, so models start in-bounds rather than being corrected after the fact.

GRD

Guard

Deterministic rules catch the absolutes in real time — personal data, legally privileged or trade secret information, prohibited topics, hard limits — with a genuine stop control at the point of action.

ASR

Assure

Every interaction is scored against your criteria, generating continuous, explainable evidence. Drift becomes a signal that feeds back to the Engine — as does your organisation's subject-matter perspective and evolving understanding, optimising how Leyn runs for you over time.

Explore the platform →

Not just IT

The functions who can actually judge AI finally get to see it.

CISO & Security

Control at the point of action: filtering, escalation paths, a real stop control, and full-stack visibility no developer can bypass.

CIO & IT

One visibility layer across a multi-provider estate, with automated sync to your CMDB, GRC, and incident management.

Risk, Compliance & General Counsel

Explainable, auditable analysis that encodes your policy and feeds your existing GRC, with the evidence ready before the auditor asks.

Board & COO

Safe expansion of agent mandates, measurable risk reduction, and a defensible answer to "is this AI paying off?"

AI & Engineering leadership

Governance that accelerates rather than impedes — unified observability, provider abstraction, and self-service criteria instead of tickets.

Strategy & Brand

Output checked against current positioning, voice, and values — owned and adjusted by the people responsible for them.

Where your most sensitive data is concerned

Designed to govern your crown jewels without exposing them.

The content that most needs alignment — strategy, planning, M&A thinking, trade secrets — is exactly the content you're most reluctant to expose to any third party. Leyn protects your most sensitive assets and data, with EU, EU Sovereign and US hosting options supplemented with extensive technical, organisational and contractual safeguards.

See our security architecture →

Provider-agnostic

No rip-and-replace. No single-vendor dependency in your governance layer.

Leyn sits across the providers you already use and feeds the systems you already run.

Azure AI FoundryAWS BedrockOpenAIAnthropicGoogle VertexCopilot StudioServiceNowOneTrustMicrosoft Entra ID

See all integrations →

Find your bearing.

See a live walkthrough on your stack, your policies.

The product

One standard. Design-time and runtime. Every provider.

Leyn is the control plane for enterprise AI. It reads your real policy documents and turns them into the live standard that governs every interaction — applied across composable layers, capturing risk and unwanted or unaligned behaviour as it happens. When your policy changes, your governance changes with it. Nothing is retrained.

Book a demo →
A steel monolith standing alone in open desert at sunset
  • Provider-agnostic
  • EU data residency
  • Feeds your GRC
  • For the agentic enterprise

The control plane · live

Watch the estate. Resolve a single system.

A working view of the control plane: every AI system scored across five dimensions, plotted where it's an outlier, and resolvable to its full risk profile and the interactions behind the score. It auto-plays the sequence — move into the mark to explore.

Every AI system scored across Value, Cost, Compliance, Security, Positioning — plotted in the pie between the two dimensions where it reads as an outlier. Select one to resolve its full risk profile and the interactions behind it.

How a system is scored

System promptArea of operationMandateData need / accessDefault guardrails

Guardrails apply pre-deployment (asynchronous) and through first-layer filtering on every interaction — capturing risk and unwanted or unaligned behaviour as it happens. Where risk warrants, synchronous sampling runs alongside the AI's actions, at a rate you set per system. Each system's input and output rolls up into one enterprise-risk view.

AI input / output → first-layer filter → risk-based sampling → enterprise risk
No system selected
1 Mark2 Plot3 Dimension4 System5 Profile

Move into the mark to explore — hover a pie or a dot, click a dot to open its profile.

The core

The Engine is the part nobody else has.

Most governance tools either apply universal safety rules they were never given your policy for, or they let engineers hand-write evaluation rubrics one use case at a time. Leyn's Engine ingests your governance documents and generates machine-evaluable criteria automatically — each criterion structured, testable, and tied to a verbatim quote from its source.

The lineage is Constitutional AI — a written set of human-readable principles governing model behaviour. Leyn extends it from training-time to inference-time, and from generic safety to your organisation's specific rules.

Go deeper on the Engine →

See · Align · Guard · Assure

Four layers, one continuous loop.

See — universal visibility

One gateway, one OpenAI-compatible interface, every provider behind it. Full prompt-and-response capture with metadata. Applications integrate by changing a base URL.

Align — applied inline

The Engine composes a governance instruction per use case and prepends it before the request reaches the provider. Models start in-bounds — alignment by construction, not correction.

Guard — control at the point of action

Deterministic rules — personal data/PII, prohibited topics, classification limits, cost ceilings — run in the request pipeline in real time, with a genuine stop control over an agent or session.

Assure — evidence & drift

Every interaction is scored with per-dimension scores and a reasoning trace; scores roll up into audit-ready evidence, and consistency is measured directly so drift is a leading indicator.

Depth where it's warranted

From sub-50ms checks to human review — calibrated to risk, not applied uniformly.

Not every interaction needs the same scrutiny. Leyn funnels traffic through progressively deeper layers, with depth set by the use case and its autonomy classification — so cost and latency track risk, not volume.

<50ms

Inline rules

Deterministic, zero-tolerance checks on 100% of traffic — personal data, legally privileged or trade secret information, prohibited topics, hard limits.

<200ms

Inline classifiers

Probabilistic safety and quality signals on 100% of traffic, in the request pipeline.

SEC

Judge evaluation

Your criteria applied by an LLM-as-judge — synchronously on high-risk traffic, sampled elsewhere. Where organisation-specific value alignment lives.

HRS+

Human review

Expert judgement on escalations and edge cases, feeding back to calibrate the automated layers.

Running evaluation for consistency, failure-mode coverage, and availability. No single-vendor dependency in the layer you trust to watch the others.

When something goes wrong

Incident escalation.

AI incidents are real — a system drifts, a tool call reaches somewhere it shouldn't, an agent acts outside its mandate. When Leyn flags one, you get more than a log entry: hand it off, or set up an automated hand-off, straight into your security incident-management process — with the controls to act at the point of action.

Hand-off — manual or automated

Route a flagged incident into ServiceNow or your SIEM by hand, or define rules that escalate automatically once severity, autonomy, or blast-radius thresholds are crossed.

Cancel part of the actions

Roll back to the last safe checkpoint or revoke a specific tool call mid-workflow — without taking the whole system offline.

Stop all actions

A genuine stop control revokes a system's permissions and halts every active session from that AI system immediately.

Every escalation carries the full trace — what the system did, which policy clause it breached, and the evidence behind the score — so the responder starts with context, not a blank ticket.

How it's deployed

A composable control plane between your applications and your AI providers.

Leyn operates as a transparent control plane in front of provider APIs. Traffic flows through the gateway, where each layer applies in turn — capturing risk and unwanted or unaligned behaviour as it happens — and full telemetry is captured for audit, trending, and reporting. Each layer can be deployed independently and switched on as your governance matures.

See deployment models →

See it run on your estate.

The Engine

Your policy, made executable.

The Engine reads the documents you already have and turns them into structured criteria a machine can apply — to an agent's design and to every live interaction. The core of Leyn, and the capability no vendor offers off the shelf.

The pipeline

Four stages, fully traceable.

01

Ingest

Core company documents — Policies, Strategy, Planning — are categorised into sections, embedded, and stored. Updated documents are added automatically.

02

Decompose

Atomic, independently testable statements are extracted — each with examples, a severity, and a confidence score. Low-confidence statements are flagged for an expert; contradictions are surfaced.

03

Generate

For each use case and autonomy tier, the Engine composes an inline governance instruction, deterministic guard rules, and scoring rubrics.

04

Validate

Artefacts are checked against schema, against existing rules for contradictions, for full coverage, and against a regression set — a new version must match or beat the one it replaces.

Why did the system behave that way?

Every runtime decision traces back to a line in a document.

Each control traces through artefact → statement → source section → source document. An auditor can follow any AI behaviour back to the exact policy clause and control framework that governed it. Governance is version-controlled, tested, and deployed like code.

Fail safe, not silent. If the Engine can't generate a control, the system falls back to the most restrictive parent — never to no governance.

It knows what it can't test

Operational policy becomes runtime-testable. Pure principle is flagged, not faked.

Operational policies — usage rules, editorial standards, escalation procedures — produce criteria that apply to a transcript in seconds. Principles-based documents are ingested and followed, but where translation into operational instructions is needed, Leyn flags the gap and surfaces worked examples for your subject-matter experts to review and approve. The system telling you what it cannot test is a safety property, not a limitation.

Bring a policy. See what comes out.

We'll run the Engine on a document and show you the criteria, the source quotes, and the coverage.

The agentic estate

Oversight that scales at the rate of the workforce it supervises.

No enterprise hires 30,000 people to supervise 150,000 agents. Leyn gives the AI estate the supervision humans gave humans — encoded policy applied at agent throughput, with a trace for every step and a stop control when you need it.

Pre-deployment

A risk vector, not a single number.

When an agent is registered, its instructions and declared tools are evaluated against your policy and assigned an automated-decision tier from 1 to 5. But a tier alone is too blunt to gate a deployment — Leyn evaluates a richer set of signals:

Autonomy & action capabilityHuman-in-the-loop checkpointsData sensitivity & scopeBlast radius & reversibilityDomain & sector criticalityJurisdiction & applicable lawRequired sanctioning authorityAutonomy-to-oversight matchModel & provider profileClassification confidence

The highest-priority flag is a high-autonomy request with weak checkpoints. When the classifier's own confidence is low, the agent is escalated to a human — not auto-approved.

Runtime

Declared tier, meet observed behaviour.

Captured traces are evaluated against your active criteria and fold back into an observed tier, compared against the declared one. A mismatch — a tier-2 agent making write-capable tool calls without a human checkpoint — is the highest-signal governance event Leyn produces. A real stop control can revoke an agent's permissions and halt active sessions immediately.

Multi-agent workflows

Standards-based tracing across the whole chain.

Leyn propagates a single trace across agent chains using open tracing standards — every agent action, tool call, and inter-agent message is a step within one auditable trace. A violation mid-workflow can block, roll back, alert, or escalate.

Honest note. Where agents run inside a provider's control plane, capture is narrower and governance is detective — after the fact. Gateway-path traffic can be governed closer to preventive. We'll tell you which of your agents fall into which bucket.

Bring your messiest workflow.

Solutions

Three outcomes. One platform. Your policy.

Whatever pulled you here — an inventory you can't produce, behaviour you can't steer, or evidence you can't generate — Leyn addresses it from the same place: the content your AI actually produces, measured against rules that are yours.

Visibility

Find out what AI you're actually running, and watch it work. For CIO, CISO, IT.

Visibility →

Alignment

Encode your policy once, and steer behaviour in near real time. For Risk, Compliance, Strategy, Brand.

Alignment →

Assurance

Produce continuous, defensible evidence and oversight. For General Counsel, Compliance, the Board.

Assurance →

How teams start

Begin with one domain. Grow into a governance capability.

You don't have to boil the ocean. A typical start is one domain — gateway visibility, one slice of policy, one set of stakeholders — proving value in weeks. From there, more domains come online, more functions own their criteria, and the value compounds. Onboarding isn't a cost centre; it's where the capability is built.

See pricing & deployment →

Visibility · for CIO, CISO & IT

You can't govern what you can't see.

Agents and model calls are spread across Bedrock, Copilot Studio, AI Foundry, Vertex, and direct keys, and no single person can speak to what's running. Leyn gives you one place to look — and one source of truth.

Discover, route, and watch.

Discover

Cloud-side discovery populates a registry and syncs with your CMDB and GRC. Anything unregistered in traffic is added as an inferred entry. The registry becomes the single source of truth.

Route

One gateway, one OpenAI-compatible interface, every provider behind it. Integrate by changing a base URL. Every interaction captured with full metadata.

Watch

Role-specific views surface the estate to the people who own it. Now the value and the risk of what was produced are visible too.

Invisible throughput becomes something a business owner can actually weigh.

Alignment · for Risk, Compliance, Strategy & Brand

Customised, not generic. Owned, not hoped for.

A generic safety filter doesn't know your rules. Leyn encodes your policies, values, and risk appetite into the live standard — applied before the model responds, and adjustable by the domain owners responsible for it.

From a hope to an owned, living control.

Encode

The Engine turns your policy corpus into structured criteria — each traceable to a verbatim source line. The same criteria govern an agent's design and its live behaviour.

Apply

Criteria are composed into an inline instruction prepended to each request, so models start in-bounds. Alignment by construction.

Adjust

Authorised owners tune their slice of the standard in near real time. Every change is versioned, audited, and role-scoped.

Cross-jurisdiction. Leyn surfaces conflicts at upload — where a jurisdiction's law would override an internal clause for that traffic — so it's a resolved decision, not a runtime surprise.

Assurance · for General Counsel, Compliance & the Board

The evidence exists before the auditor asks.

A deployment sign-off says nothing about behaviour months later. Leyn scores AI behaviour continuously against your criteria, measures consistency, and turns the result into evidence you can defend.

Measure, evidence, and feed your GRC.

Measure

Per-dimension scores and a reasoning trace. Consistency is measured directly — score-spread across repeated runs — so drift shows up as a signal, not a postmortem.

Evidence

Every score maps to a governance principle and rolls up into continuous, immutable, audit-ready records traceable to the originating policy.

Feed

Leyn pushes risk scores, incidents, and evidence into your GRC stack — bidirectionally. It complements OneTrust and ServiceNow; it doesn't replace them.

See compliance coverage →

Security & data sovereignty

Secure by design. Sovereign by choice.

The content that most needs governance — strategy, planning, trade secrets — demands the same rigour from the platform that governs it. Leyn is built to that standard, with hosting choices that match your regulatory environment and risk appetite.

Three deployment regions. One governance standard.

US

United States

Hosted in AWS US East / US West. SOC 2 Type II and ISO 27001 certified. Suited to organisations operating primarily in the United States.

Standard Leyn pricing.

EU

European Union

Hosted in AWS eu-west (Ireland / Frankfurt). GDPR-compliant by design, EU AI Act ready. Processing and storage remain within the EU boundary — no data leaves it.

Standard Leyn pricing.

EU SOV

EU Sovereign

Dedicated hosting in a sovereign EU cloud environment, with contractual data-residency guarantees enforced at infrastructure level. Suited to regulated industries — financial services, healthcare, public sector.

Separate pricing — contact us →

Beyond certification.

Certifications set a floor. Leyn builds above it — with controls that regulated industries require and that are cost-effective to operate at scale.

Technical controls

  • TLS 1.3 in transit, AES-256 at rest — enforced, not optional.
  • HSM-backed customer-managed keys (BYOK) with column-level encryption for raw policy content.
  • Immutable, tamper-evident audit log — every interaction and governance decision, traceable.
  • Zero-trust network architecture — no implicit trust within the perimeter.
  • SBOM, dependency scanning, and quarterly penetration testing.
  • SIEM integration for security event correlation and alerting.

Organisational controls

  • Role-based access control with least-privilege enforcement and MFA on all access paths.
  • Background-checked personnel for production system access.
  • Defined incident response plan with published SLA commitments.
  • Annual security training and phishing simulation.

EU Sovereign additions

  • Article 28 GDPR DPA covering all sub-processors, with contractual right to audit.
  • NIS2-aligned incident notification — 72-hour reporting commitment.
  • DORA readiness documentation for financial-services customers.
  • Dedicated instance option for logical or physical separation where required.

Certifications are stated honestly on the Trust Center — what is held, in progress, or planned. "Designed to support" and "maps to" are honest; "certified" is earned first.

Visit the Trust Center →

Compliance

Continuous evidence, mapped to the frameworks you answer to.

Leyn turns live AI behaviour into documentation — mapped to the EU AI Act, ISO/IEC 42001, NIST AI RMF, GDPR, and NIS2 — so the evidence exists before it's requested.

Not a questionnaire. A continuous record.

Evidence of how AI actually behaves — not how it's intended to.

GRC suites map systems to frameworks and produce evidence from a human filling in an assessment. Leyn evidences how AI actually behaves, continuously, at the content layer, with every record traceable to the policy clause and control framework that governed it — then feeds it into the GRC stack you already run.

Your control frameworks.

Leyn's primary governance layer is not a generic standard — it is your own. During onboarding, the Engine ingests your internal policies, risk frameworks, values, and operational rules and translates them into machine-evaluable criteria, reviewed and approved by your subject-matter experts before they go live. Every evaluation is traceable to your specific document and clause.

01

Provide your governance documents

Internal policies, risk frameworks, values, and operational rules — uploaded at onboarding.

02

Engine categorises and translates

Criteria are decomposed, structured, and tied to verbatim clauses in your source documents.

03

Your experts review and approve

Subject-matter experts validate and adjust the criteria set before it goes live.

04

Active control across every provider

Approved criteria govern every interaction — on your estate, not a generic rulebook. As your documents change, criteria update with them.

Available as onboarding selections

Complementary regulatory and industry standards.

In addition to your own frameworks, Leyn supports regulatory and industry standards as selectable overlays — chosen during onboarding, maintained as those standards evolve. Each adds a structured evidence layer without replacing your own governance.

EU AI Act

Risk management (Art. 9), record-keeping (Art. 12), transparency (Art. 13), human oversight (Art. 14), accuracy/robustness/security (Art. 15), deployer obligations (Art. 26), GPAI transparency (Art. 50).

ISO/IEC 42001

Planning and risk assessment, operational control via the Engine, performance evaluation via continuous monitoring, improvement via feedback loops — plus Annex A controls.

NIST AI RMF

GOVERN, MAP, MEASURE, MANAGE — RBAC and accountability, inventory and impact, metric taxonomy and drift detection, guardrails and escalation.

GDPR & NIS2

Data-minimisation and storage-limitation, DPIA workflow triggers, cross-border transfer detection, and security-incident evidence aligned to NIS2.

Evaluation calibrated to autonomy

Five automated-decision tiers, differentiated controls.

From "AI assists, human decides" to "AI decides and acts independently." Higher autonomy means deeper evaluation, mandatory checkpoints, and continuous monitoring with a stop control. Tier 1 → quarterly sample, inline rules only … Tier 5 → continuous monitoring, all layers, kill switch.

See the evidence Leyn would generate for you.

Integrations

Across your providers. Into your stack.

Leyn is provider-agnostic by design and built to strengthen your systems of record, not bypass them. Governance flows both ways.

AI providers

Azure AI Foundry · AWS Bedrock · OpenAI · Anthropic · Google Vertex AI · Microsoft Copilot Studio · self-hosted endpoints — through one gateway, with native telemetry ingestion where agents run inside a provider's control plane.

Identity & access

Microsoft Entra ID for SSO, RBAC, conditional access, privileged-access elevation, and managed identities for agents.

GRC & service management

ServiceNow and OneTrust — bidirectional sync for inventory, risk scores, incidents, DPIA triggers, approvals, and evidence export.

Agent frameworks

LangChain / LangGraph · Semantic Kernel · AutoGen · CrewAI · the OpenAI Agents SDK · custom agents via open tracing standards.

Security & dev toolchain

SIEM and security-posture tooling, plus Git-backed version control and CI/CD for governance-as-code.

Unglamorous work, deliberately done. Each provider needs its own connector — auth, schema normalisation into one canonical trace, pagination, retention. There's no shortcut, and that's the point: the connector library compounds with every provider and every customer.

Don't see your stack? Ask us.

Pricing

Priced to the scale you actually run.

Leyn scales with the volume of AI your organisation generates — and deploys the way your sovereignty and operating model require. Start with one domain; expand as governance matures.

Four tiers, by AI volume.

Starter

For teams getting their first estate under visibility. Lower interaction volumes, core See + Guard, one domain of policy.

Growth

For expanding multi-provider estates. Higher volumes, the full See · Align · Guard · Assure loop, multiple domains and owners.

Enterprise

For standardising governance across divisions. High volumes, agent governance, full GRC integration, SLA-backed availability.

Global

For the largest, multi-jurisdiction estates. The highest volumes, sovereign deployment, dedicated support.

Pricing reflects your AI interaction volume and deployment model. Book a demo for a quote scoped to your estate.

Choose your deployment region.

US

US hosted

Fully managed in AWS US East / US West. SOC 2 Type II and ISO 27001 certified. Suited to organisations operating primarily in the United States.

Standard Leyn pricing.

EU

EU hosted

Fully managed within EU-resident infrastructure (AWS eu-west). GDPR-compliant by design, EU AI Act ready. Processing and storage remain within the EU boundary.

Standard Leyn pricing.

EU SOV

EU Sovereign hosted

Dedicated hosting in a sovereign EU cloud environment with contractual data-residency guarantees. Suited to regulated industries — financial services, healthcare, public sector.

Separate pricing — contact us →

Design-partner programme

Build the standard with us.

We're working with a small number of founding customers as design partners — co-developing against real policies, real estates, and real regulatory pressure. A partnership, not a transaction: deeper roadmap input, hands-on onboarding, and preferential terms.

Apply to the programme →

Get a quote scoped to your estate.

Resources

Markers for the machine age.

Perspective, primers, and practical frameworks on governing AI at the content layer — written for the functions now accountable for it.

Govern the content, not the asset

Why identity and inventory tell you an agent exists — and nothing about whether it behaved.

Why human oversight doesn't scale

Opaqueness, alignment, and consistency — the three things a supervisor used to provide, and what replaces them.

From policy to a living rubric

How a written standard can govern both an agent's design and its live behaviour — provider-agnostically.

Sovereignty, stated honestly

Full data sovereignty, with contractual and technical commitments tailored to your region and regulatory requirements. Contact us for details.

A note when there's something worth reading.

No volume for its own sake. We write when we have a marker worth placing.

Company

We build the control layer enterprises need to run AI with confidence.

Leyn makes AI behaviour visible, measurable, and aligned to the policies organisations have already written. A system that does a specific job well.

A still Nordic lake at dusk, forest reflected on the water

What we're building

The problem is real and the gap is wide.

Enterprises are deploying AI at scale — across providers, teams, and use cases — without a reliable way to know whether what their systems produce is aligned to their own standards. Existing tools govern assets. Leyn governs output: the actual content produced by AI, evaluated against the organisation's own translated policy, at the pace AI operates. That distinction is not a marketing claim. It determines whether governance works or just looks like it does.

Why now

Regulation and scale are converging.

Regulatory deadlines are forcing enterprises to produce evidence of AI control that doesn't yet exist in most organisations. Simultaneously, the volume of AI-generated work is growing faster than any human review function can scale to. Both pressures point to the same requirement: an evaluation layer whose rate matches the action rate, and whose criteria come from the organisation — not a vendor's rulebook.

How we work

Openness. Quality. Determination.

  • Open about what we know and what we don't. Every criterion is traceable; every score is explainable; every limitation is stated, not papered over.
  • Quality over coverage. We build fewer things and build them properly. A governance tool that produces unreliable output is worse than no tool.
  • Determined on the hard part. The Engine is the difficult, novel work. We stay focused on it rather than expanding surface area prematurely.
  • Results, not process. The measure is whether regulated enterprises can prove their AI is aligned — not whether a framework has been filled in.

Built in Stockholm

A Swedish company, founded at a specific intersection.

Leyn AB sits where data protection, AI governance, and the practical reality of running AI inside large, regulated organisations meet.

See it for real

Bring a policy. We'll show you the rest.

In a working session we'll run the Engine on a real document, route traffic through the gateway, and show you the criteria, the scores, the lineage, and the controls — on your stack.

What to expect.

01

A 30-minute fit call

Your estate, your providers, your regulatory pressure, your starting domain.

02

A working walkthrough

The Engine on a real policy; the See · Align · Guard · Assure loop on live-style traffic; the evidence it generates.

03

A scoped plan

Edition, deployment model, and a land-light starting point — with a quote scoped to your estate.

Pick a time that works for you.

30 minutes. Bring a real policy document and your AI estate. We'll show you the Engine running on it.

Trust Center

Security posture, certifications, sub-processors.

Stated honestly — what is certified, what is in progress, and what is planned. No marketing language; no "designed to support".

Certifications

Where we are.

AI Management System

ISO/IEC 42001

In progress — first stage

Information Security Controls

ISO/IEC 27002

In progress — first stage

Security & Availability

SOC 2 Type II

In progress — first stage

Security controls.

Data protection

  • TLS 1.3 in transit, AES-256 at rest — enforced at infrastructure level.
  • Customer-managed encryption keys (BYOK), HSM-backed.
  • Column-level encryption for raw policy content.
  • Immutable, tamper-evident audit log for every interaction and governance decision.

Access control

  • Role-based access control with least-privilege enforcement.
  • MFA enforced on all access paths.
  • Zero-trust network architecture — no implicit trust within the perimeter.
  • Background-checked personnel for production system access.

Vulnerability management

  • Quarterly penetration testing by independent third party.
  • Software bill of materials (SBOM) maintained and updated on each release.
  • Automated dependency scanning in CI/CD pipeline.
  • Responsible disclosure programme — security@leyn.ai

Incident response

  • Defined incident response plan with published SLA commitments.
  • Personal data breach notification within 48 hours of discovery.
  • NIS2-aligned 72-hour notification for EU Sovereign deployments.
  • SIEM integration for security event correlation and alerting.

Deployment regions and data residency.

  • US hosted. AWS US East / US West. Data remains in the United States.
  • EU hosted. AWS eu-west (Ireland / Frankfurt). Data remains within the EU boundary.
  • EU Sovereign hosted. Dedicated sovereign EU cloud. Contractual data-residency guarantees enforced at infrastructure level. No data leaves the sovereign environment.

Sub-processors.

A full, current list of sub-processors is maintained below. We give 30 days' notice before adding or replacing any sub-processor.

Sub-processor list to be populated with current infrastructure, payment, and tooling providers before go-live.

Legal

Privacy Notice.

How Leyn AB collects, uses, and protects personal data in connection with our services. This notice applies to customers, prospective customers, and authorised users of the Leyn platform.

Draft for legal review. This document is a working draft and should be reviewed and finalised by qualified legal counsel before publication.

Last updated: June 2026

1. Controller

Leyn AB (organisation number to be confirmed), Stockholm, Sweden, is the data controller for personal data processed in connection with our services. Contact: privacy@leyn.ai

2. Data we collect

  • Account and contact data. Name, work email address, job title, company name — provided when you create an account, sign a contract, or contact us.
  • Usage data. Feature usage, interaction logs, session metadata, API call volumes — collected automatically as you use the platform.
  • Technical data. IP address, browser type, device identifiers, log data — collected automatically.
  • Communication data. Content of emails, support tickets, and correspondence with Leyn.

We do not collect or process the personal data contained within AI inputs and outputs routed through the platform. That data is processed on your behalf under the Data Processing Agreement.

3. Purposes and legal bases

  • Service delivery and account management. Performance of contract (Art. 6(1)(b) GDPR).
  • Billing and subscription management. Performance of contract; legal obligation.
  • Security monitoring and fraud prevention. Legitimate interests (Art. 6(1)(f) GDPR).
  • Product improvement and analytics. Legitimate interests.
  • Legal compliance. Legal obligation (Art. 6(1)(c) GDPR).
  • Marketing to existing customers. Legitimate interests; consent where required.

4. Retention

  • Account data: duration of the contract plus 3 years.
  • Usage and technical logs: 12 months rolling.
  • Billing records: 7 years (Swedish Bookkeeping Act).
  • Support correspondence: 3 years from resolution.

5. Recipients

We share data with sub-processors necessary to provide the service — including cloud infrastructure providers, payment processors, and support tooling. A current list of sub-processors is available on our Trust Center. We do not sell personal data or share it with third parties for their own marketing.

6. International transfers

Leyn AB is based in Sweden (EU). For EU-hosted deployments, data remains within the EU. For US-hosted deployments, data is transferred to the United States under Standard Contractual Clauses (SCCs, Commission Decision (EU) 2021/914). For EU Sovereign deployments, no data leaves the sovereign cloud environment.

7. Your rights

Under GDPR you have the right to: access your data; correct inaccurate data; request erasure (where no legal obligation requires retention); restrict processing; data portability; object to legitimate-interest processing; and withdraw consent where processing is consent-based. To exercise your rights, contact privacy@leyn.ai. You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

8. Changes

We will notify you of material changes by email or in-product notice at least 30 days before they take effect.

Legal

Terms of Service.

The agreement governing access to and use of the Leyn platform between Leyn AB and the subscribing organisation.

Draft for legal review. This document is a working draft and should be reviewed and finalised by qualified legal counsel before publication.

Last updated: June 2026

1. Definitions

  • Leyn, we, us. Leyn AB, Stockholm, Sweden.
  • Customer, you. The legal entity that has subscribed to the Service under an Order Form.
  • Service. The Leyn AI governance platform, including the Engine, gateway, evaluation layers, and associated APIs, as described in the documentation.
  • Authorised Users. Employees or contractors of Customer permitted to use the Service.
  • Order Form. The commercial agreement specifying edition, volume, deployment region, term, and price.

2. Access and use

Subject to payment and these Terms, Leyn grants Customer a non-exclusive, non-transferable right to access and use the Service during the subscription term, for Customer's internal business purposes, for the number of Authorised Users specified in the Order Form. Customer is responsible for Authorised Users' compliance with these Terms.

3. Acceptable use

Customer must not: (a) use the Service to violate applicable law; (b) reverse-engineer, decompile, or attempt to extract the source code; (c) resell, sublicense, or make the Service available to third parties outside the Order Form; (d) use the Service to process data beyond the agreed scope; (e) attempt to circumvent or disable security controls.

4. Intellectual property

Leyn retains all rights in the Service, including the Engine and all underlying technology. Customer retains all rights in its governance documents, policies, and data. Criteria generated by the Engine from Customer's documents are owned by the Customer. Aggregate, anonymised benchmarks derived from platform-wide usage — which do not identify Customer or its data — may be used by Leyn for product development.

5. Confidentiality

Each party agrees to keep the other's confidential information secret, to use it only for purposes of the agreement, and to protect it with at least the same standard of care it uses for its own confidential information. This obligation survives termination for 5 years. It does not apply to information that is publicly available, independently developed, or required to be disclosed by law.

6. Data processing

To the extent the Service processes personal data on Customer's behalf, the parties' Data Processing Agreement governs. In case of conflict between these Terms and the DPA on data processing matters, the DPA prevails.

7. Warranties

Leyn warrants that the Service will perform materially in accordance with the documentation during the subscription term. Customer warrants that it has the right to provide to Leyn any data submitted for processing. Except as expressly stated, the Service is provided "as is".

8. Limitation of liability

To the extent permitted by law: (a) neither party is liable for indirect, consequential, or punitive damages; (b) Leyn's total aggregate liability for any claim is limited to fees paid by Customer in the 12 months preceding the claim. Nothing in this clause limits liability for death, personal injury, fraud, or liability that cannot be limited by law.

9. Term and termination

The subscription term is as specified in the Order Form and renews automatically unless either party gives 60 days' written notice before the renewal date. Either party may terminate immediately on material breach unremedied within 30 days of written notice. On termination, Customer's access ceases and Leyn will make Customer data available for export for 30 days before deletion.

10. Governing law

These Terms are governed by Swedish law. Disputes shall be resolved by the courts of Stockholm, Sweden, as the court of first instance.

Legal

Data Processing Agreement.

Article 28 GDPR processor terms between Leyn AB (Processor) and the subscribing organisation (Controller). This DPA forms part of the Terms of Service.

Draft for legal review. This document is a working draft and should be reviewed and finalised by qualified legal counsel before publication.

Last updated: June 2026

1. Subject matter

The Processor processes personal data on behalf of the Controller in connection with the provision of the Service, as described in Annex 1 below.

2. Instructions

The Processor shall process personal data only on documented instructions from the Controller. The Order Form and Terms of Service constitute the Controller's initial instructions. The Processor shall inform the Controller if it believes an instruction infringes applicable data protection law.

3. Confidentiality of processing

The Processor shall ensure that persons authorised to process personal data are bound by appropriate confidentiality obligations.

4. Security

The Processor shall implement and maintain appropriate technical and organisational measures as described in Annex 2, taking into account the nature of the processing and the risks to data subjects.

5. Sub-processors

The Controller provides general authorisation for the Processor to engage sub-processors. The Processor shall: (a) maintain and make available a current list of sub-processors; (b) notify the Controller at least 30 days before adding or replacing a sub-processor; (c) impose data protection obligations on sub-processors equivalent to those in this DPA. If the Controller objects to a new sub-processor on reasonable data-protection grounds, the parties shall work in good faith to resolve the concern.

6. Data subject rights

The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures in responding to data subject rights requests.

7. Security incidents

The Processor shall notify the Controller without undue delay — and no later than 48 hours after becoming aware — of a personal data breach affecting data processed under this DPA. Notification shall include: nature of the breach; categories and approximate number of data subjects and records affected; likely consequences; and measures taken or proposed.

8. Data protection impact assessments

The Processor shall provide reasonable assistance to the Controller in carrying out data protection impact assessments and prior consultation with supervisory authorities where required.

9. Deletion or return

On termination of the Service, the Processor shall, at the Controller's election, return or securely delete all personal data and provide written confirmation of deletion. The Processor may retain data where required by applicable law for the minimum period required.

10. Audit

The Controller may, on reasonable written notice (not less than 30 days) and no more than once per year, audit the Processor's data processing activities or commission an independent auditor, at the Controller's cost. The Processor may propose an equivalent third-party audit report in lieu of an on-site audit.

11. International transfers

Where personal data is transferred outside the EEA, the transfer shall be subject to Standard Contractual Clauses (Commission Decision (EU) 2021/914) or another valid transfer mechanism under Chapter V GDPR.

12. Governing law

This DPA is governed by Swedish law. The competent supervisory authority is the Swedish Authority for Privacy Protection (IMY), unless otherwise required by applicable law.

Annex 1 — Details of processing

  • Subject matter. AI governance and policy compliance monitoring.
  • Duration. Term of the Service agreement.
  • Nature and purpose. Evaluation of AI inputs and outputs against policy criteria; logging; reporting — to enable the Controller to govern AI behaviour in accordance with its own policies.
  • Types of personal data. As determined by the Controller; may include identifiers of employees and end users appearing in AI interactions.
  • Categories of data subjects. Employees of the Controller; end users of the Controller's AI systems.

Annex 2 — Technical and organisational security measures

  • Encryption. TLS 1.3 in transit; AES-256 at rest.
  • Access control. Role-based access; MFA enforced on all access paths; least-privilege principle.
  • Key management. Customer-managed keys (BYOK) available; HSM-backed.
  • Audit logging. Immutable, tamper-evident log of all access and processing events.
  • Vulnerability management. Quarterly penetration testing; SBOM; dependency scanning.
  • Incident response. Defined plan with SLA commitments; NIS2-aligned notification for EU Sovereign deployments.
  • Personnel security. Background checks for production access; annual security training.