AI was never the problem.
Deploying it without
sovereignty was.
OAIS builds the sovereign infrastructure that makes AI yours — captured, blocked, governed, and mathematically verified. Native zero-knowledge runtime governance deployed across AWS Bedrock, Microsoft Azure OpenAI, Google Cloud Vertex AI, and Private Sovereign AI.
What Is OAIS?
OAIS (Optimized Artificial Intelligence Systems Inc.) is a Canadian company that builds AI sovereignty infrastructure for regulated enterprises. Founded by Daniel Fruman, OAIS provides two products — Sentinel Core and Sentinel Guard — that capture, block, govern, and optimise the AI interactions an organisation routes through them, creating a cryptographic chain of custody that is independently verifiable.
OAIS serves financial institutions, insurers, and other regulated enterprises preparing for OSFI E-23 (mandatory May 2027), the EU AI Act, and ISO 42001 compliance. The platform is metadata-only by default — OAIS never sees client content, only cryptographic fingerprints. Sentinel natively integrates across multi-cloud and sovereign environments: Amazon Bedrock, Microsoft Azure OpenAI, Google Cloud Vertex AI, Cohere, and self-hosted open-source models.
Two Products. One Chain.
Sentinel Core captures and anchors the AI interactions you route through it. Sentinel Guard intercepts them at the browser. Together, they form a cryptographic chain of custody across your organisation's governed AI interactions.
Sentinel Core
Universal Hardware-Attested AI Ledger · Multi-Cloud & SovereignOne line of code. Designed natively to govern inference across Amazon Bedrock, Microsoft Azure OpenAI, Google Cloud Vertex AI, and sovereign private models (Cohere, Ollama, vLLM). Every AI interaction is HMAC-hashed with a key only you hold, Ed25519-signed in hardware memory (AWS Nitro Enclaves, Azure Confidential VMs, AMD SEV-SNP), Merkle-anchored (RFC 6962), and timestamped by an independent RFC 3161 authority. OAIS sees the cryptographic fingerprint. Never your plaintext data.
HMAC-SHA3-256 Hashing
Content hashed with a tenant key that OAIS never holds. Inputs and outputs become irreversible fingerprints.
Ed25519 Signing
Each record is signed by the client agent. Tamper-evident from the moment of capture.
RFC 6962 Merkle Anchoring
Records are batched into Merkle trees. Any single change invalidates the entire chain above it.
RFC 3161 Timestamping
An independent timestamp authority proves records existed at a specific time. No OAIS infrastructure access required to verify.
Any third party can verify the entire chain with a standalone script. No OAIS account, no API access, no trust required.
Sentinel Guard
Browser Extension for Shadow AI Detection & DLPDeployed via Chrome Enterprise Policy or Intune. Sentinel Guard detects AI tool usage across Chrome and Edge, enforces DLP rules before data leaves the browser, and feeds metadata records into the same Sentinel Core registry.
From AI Interaction to Verifiable Proof in Four Steps
When an employee interacts with any AI system, Sentinel captures that interaction and produces a tamper-evident, independently verifiable record. Here is exactly how the process works.
Interaction Capture
Sentinel Core intercepts the AI interaction at the API layer (or Sentinel Guard captures it at the browser layer). The raw content never leaves the client environment. Instead, it is immediately processed locally.
Cryptographic Hashing
The interaction content is hashed using HMAC-SHA3-256 with a key held exclusively by the client. The result is a fixed-length fingerprint. OAIS receives this fingerprint. It cannot reverse the hash to recover the original content. This is the zero-knowledge guarantee.
Signing and Anchoring
The fingerprint is signed with an Ed25519 key (proving who created the record), then batched into a Merkle tree (RFC 6962). Any modification to any record in the batch invalidates the tree root. The Merkle root is then submitted to an independent RFC 3161 timestamp authority, proving the batch existed at a specific time.
Independent Verification
Any third party — a regulator, auditor, or internal compliance team — can verify the entire chain using a standalone verification script. No OAIS account is required. No API access is needed. The proof is mathematical, not institutional.
The result: a tamper-evident, independently timestamped chain of custody across the AI interactions Sentinel governs. If capture is ever interrupted, the system records a cryptographically signed gap attestation rather than leaving a silent hole — evidence fails closed while operations fail open, so you can always tell a network blip from tampering. Every record is verifiable without trusting OAIS. This is what separates independent audit custody from platform governance logging.
One Governance Plane.
Every Cloud & On-Premises Stack.
Sentinel operates as a vendor-neutral, zero-knowledge runtime governance plane. Whether your teams build on hyperscale cloud APIs, sovereign private clouds, or air-gapped on-premises clusters, Sentinel integrates natively with single-line SDK interception and universal reverse proxies.
Amazon Web Services
Native SDK interception for Amazon Bedrock and SageMaker. Hardware attestation with AWS Nitro Enclaves (PCR0 sealing). Procure directly via AWS Marketplace Private Offers to draw down existing EDP commitments (Product Code: 6nguei3sp0crq9xj0bij6yn1i).
Microsoft Azure
Seamless drop-in governance for Azure OpenAI Service (GPT-4o, o1) and Azure AI Studio. Enforces Canadian data residency in Canada Central/East tenancies with full OSFI E-23 cryptographic audit receipts.
Google Cloud
Full-stream governance for Vertex AI and Gemini foundation models. Provides sub-millisecond cryptographic hashing, real-time DLP redaction, and tamper-evident Merkle ledger anchoring.
Private & Sovereign AI
Engineered for Cohere (Command R/R+), self-hosted LLMs (vLLM, Ollama), and sovereign telecommunications AI fabric. Language-agnostic reverse proxy for air-gapped enterprise deployments.
We are not here to make the
Large Liability Model more powerful.
We are here to make you sovereign over it.
Capture
Every AI interaction, in and out, hashed with a key only the client holds. OAIS sees the fingerprint, never the content.
Block
DLP enforcement at the browser and API layer. Stop what you don't want leaving before it leaves.
Govern
AI output that triggers autonomous action passes through a deterministic governance gate before it executes.
Optimise
The audit chain is data. Use it to optimise tokenomics, fine-tune models, build proprietary datasets, demonstrate ROI, streamline workflows.
The Audit Chain Is Data
Once your AI interactions are captured cryptographically by Sentinel Core, new capabilities emerge that were previously impossible.
Regulatory Evidence on Demand
OSFI E-23, EU AI Act, ISO 42001. Export a verifiable, timestamped chain for any audit window in seconds.
Shadow AI Discovery
Surface AI tool usage on managed Chrome and Edge browsers where Sentinel Guard is deployed — visibility across your governed fleet before a regulator asks.
Proprietary AI Datasets
Your interaction data, structured and labelled. Build proprietary datasets for fine-tuning and competitive advantage.
Token Optimisation
Cost per outcome, not cost per call. See which interactions produce value and which waste tokens.
Governed Autonomous Agents
AI that acts within your boundaries. Deterministic governance gates that are architecturally incapable of being bypassed.
Workflow Streamlining
Audit chain insights reveal bottlenecks, redundant interactions, and optimisation opportunities across your AI-augmented workflows.
Platform Governance Logs vs.
Independent Audit Custody
Most AI platforms offer built-in usage logs. These logs record what happened. They cannot prove the log is true. This distinction is critical for regulatory compliance.
Platform Governance Logging
OAIS Sentinel — Independent Audit Custody
For a detailed analysis, read: Your AI Platform Logs What Happened. It Cannot Prove the Log Is True. — by Daniel Fruman, May 2026.
Tailored to Your Environment
Every deployment is different. Pricing is scoped to your systems, data volume, integration requirements, and compliance objectives.
30 days. One AI system. Full Sentinel Core functionality with dedicated onboarding. We’ll define scope, integration approach, and success criteria together.
- Full Sentinel Core functionality
- Cryptographic chain of custody
- RFC 3161 timestamping
- Independent verification
- Dedicated onboarding support
Priced by the number of AI systems monitored, interaction volume, and integration complexity. Includes platform licensing, implementation, and ongoing support. Consulting and advisory services available.
- Full compliance-grade audit trail
- Cryptographic chain of custody with RFC 3161
- Real-time and batch integration options
- OSFI-aligned governance reporting
Per-seat licensing for Chrome and Edge. Volume-based pricing scaled to your organization. Annual and multi-year options available.
- Shadow AI discovery
- DLP enforcement
- Chrome Enterprise / Intune deployment
- Records feed into Sentinel Core
Universal Multi-Cloud Deployment & Procurement: Deployable across AWS, Microsoft Azure, Google Cloud, and On-Premises environments. Enterprise agreements can be licensed directly or transacted via AWS Marketplace Private Offers to draw down existing cloud commitments (Product Code: 6nguei3sp0crq9xj0bij6yn1i).
Every engagement starts with a scoping conversation. No commitment required.
Built by Practitioners,
Not Observers
Daniel Fruman
Designed and built the Sentinel architecture. Over a decade of hands-on experience in healthcare privacy compliance and data governance, building and enforcing governance systems in regulated Canadian environments. Specialises in cryptographic audit systems, AI risk management, and regulatory compliance (OSFI E-23, EU AI Act, ISO 42001).
Founding Team
Three co-founders with senior experience spanning institutional investment management, insurance operations, and financial services. Combined expertise in enterprise governance, regulatory compliance, actuarial science, and risk modelling — drawn directly from the industries Sentinel is built to serve.
Built in 25 Sheppard Avenue West, Suite 300, Toronto, Ontario M2N 6S6, Canada. Focused on OSFI E-23. Serving regulated enterprises globally.
Contact us: info@oais.ai | Learn more about OAIS | Privacy Policy | LinkedIn
Published Analysis
OAIS publishes technical analysis on AI governance, regulatory compliance, and audit independence for regulated enterprises.
Your AI Platform Logs What Happened. It Cannot Prove the Log Is True.
Why AI platform governance logging is structurally insufficient for regulatory audit purposes. Covers OSFI E-23 requirements for independent audit custody and the architectural distinction between governed AI infrastructure and independent cryptographic verification.
Read the full analysis →Frequently Asked Questions
What is OAIS?
OAIS (Optimized Artificial Intelligence Systems Inc.) builds AI sovereignty infrastructure for regulated enterprises. Its two products — Sentinel Core and Sentinel Guard — capture, block, govern, and optimise the AI interactions an organisation routes through them, creating a cryptographic chain of custody that is independently verifiable.
What is Sentinel Core?
Sentinel Core is a cryptographic AI interaction registry. With one line of code, every AI interaction is HMAC-hashed with a key only the client holds, Ed25519-signed, Merkle-anchored (RFC 6962), and timestamped by an independent RFC 3161 authority. OAIS sees the fingerprint, never the content. Any third party can verify the entire chain without an OAIS account.
What is Sentinel Guard?
Sentinel Guard is a browser extension for shadow AI detection and data loss prevention. Deployed via Chrome Enterprise Policy or Intune, it detects AI tool usage across Chrome and Edge, enforces DLP rules before data leaves the browser, and feeds metadata records into the Sentinel Core registry. It is metadata-only by default — content capture is opt-in.
How does OAIS help with OSFI E-23 compliance?
OSFI E-23, effective May 2027, requires enterprise-wide AI model risk management for all federally regulated Canadian financial institutions. Sentinel Core and Sentinel Guard produce the cryptographic audit evidence used to demonstrate control over AI interactions — tamper-evident records, independent timestamps, and exportable reports for any audit window. OAIS provides the auditability; the compliance determination remains with the institution and its auditors.
Does OAIS see my data?
No. Sentinel Core hashes content with an HMAC key that only the client holds. OAIS sees the cryptographic fingerprint — never the content itself. Sentinel Guard is metadata-only by default; content capture is an opt-in configuration. The entire chain can be verified by any third party using a standalone script, without OAIS infrastructure access.
What compliance frameworks does OAIS support?
OAIS supports OSFI E-23 (mandatory May 2027 for Canadian federally regulated financial institutions), the EU AI Act (mandatory for AI systems in regulated European contexts), and ISO 42001 (the international standard for AI management systems). Sentinel provides the cryptographic auditability these frameworks require.
How is Sentinel Guard deployed?
Sentinel Guard is deployed via Chrome Enterprise Policy or Microsoft Intune. It runs as a browser extension on Chrome and Edge, requiring no changes to existing AI tools or workflows. It detects AI usage, enforces DLP rules at the browser layer, and feeds records into the same Sentinel Core cryptographic registry.
What does OAIS pricing look like?
Pricing is scoped to each deployment: number of AI systems monitored, interaction volume, integration complexity, and compliance objectives. Sentinel Core uses custom platform licensing. Sentinel Guard uses per-seat licensing with volume-based pricing. A 30-day pilot program is available. Every engagement starts with a scoping conversation.
How long does it take to deploy Sentinel Core?
Sentinel Core integrates with one line of code. The initial deployment — connecting one AI system and producing the first cryptographic audit record — can be completed in hours. A full enterprise rollout, covering multiple AI systems, configuring governance rules, and establishing compliance reporting, is typically scoped during a 30-day pilot engagement.
How does independent verification work?
OAIS provides a standalone verification script that any third party can run — a regulator, external auditor, or internal compliance team. The script recalculates HMAC hashes, validates Ed25519 signatures, reconstructs the Merkle tree, and checks RFC 3161 timestamps against the independent timestamp authority. If any record has been modified, the verification fails. No OAIS account, API key, or infrastructure access is required.
What is the difference between platform governance logging and independent audit custody?
Platform governance logging means the AI platform that generated the output also controls the log of that output. The log can be modified or selectively exported by the platform operator, and verification requires trusting the platform. Independent audit custody — what Sentinel provides — captures the audit record in a system architecturally separate from the AI platform. Records are cryptographically hashed, signed, Merkle-anchored, and independently timestamped. Any third party can verify the chain without trusting OAIS or the AI platform. For a detailed analysis, see our published research.
Can Sentinel Core work with on-premises AI models?
Yes. Sentinel Core integrates at the API layer and is agnostic to where the AI model runs. It works with cloud-hosted AI services (ChatGPT, Claude, Gemini), private cloud deployments, and on-premises models. The cryptographic hashing occurs locally, so interaction content never needs to leave the client environment regardless of deployment model.
Why can't our cloud team just write AI logs to an Amazon S3 bucket with Object Lock (WORM)?
Internal S3 WORM buckets create two severe enterprise compliance risks: First, the privacy trap: S3 Object Lock makes stored data permanently immutable. If employee prompts contain customer PII, account numbers, or Canadian Social Insurance Numbers (SINs), that data can never be deleted or redacted, directly violating PIPEDA and Quebec Law 25 statutory deletion mandates. Second, separation of duties: Having internal cloud admins manage the log bucket fails OSFI E-23 independent audit custody requirements. Sentinel solves both: content is hashed in-memory with a client-held HMAC salt before storage—zero plaintext is ever locked—and Merkle tree roots are anchored to public accredited TSAs (Sectigo and DigiCert) for true independent verification.
Won't Microsoft Purview, AWS Bedrock Guardrails, or Cohere just provide this natively?
Model providers have an inherent structural conflict of interest: asking an AI platform to audit its own hallucinations, bias, or data leakage violates regulatory segregation of duties. Furthermore, enterprise banks operate multi-cloud estates (Bedrock for developers, Azure OpenAI for Copilot, Google Cloud for search, and on-premises GPUs). Microsoft will not audit Bedrock; AWS will not audit Azure. Sentinel serves as a vendor-neutral, universal cryptographic audit plane across all foundation models.
What happens to our audit records if OAIS ceases business operations?
Your compliance evidence is contractually protected and architecturally independent. The standalone offline verifier is open-source Apache 2.0 and executes on standard Python standard library with zero network calls. Timestamp anchors are held by independent commercial certificate authorities (Sectigo and DigiCert)—not OAIS. In addition, an independent escrow trustee releases full database exports and source code upon any cessation event, guaranteeing your records remain permanently verifiable for the statutory 7-year retention period under OSFI E-23.
Why should financial institutions address OSFI E-23 today if enforcement is May 1, 2027?
OSFI does not evaluate whether an institution deployed governance software the day before May 1, 2027. Examiners evaluate the historical lifecycle evidence of models already operating in production. If an institution deploys generative AI in 2025 and 2026 without an immutable audit trail, it accumulates massive regulatory debt that cannot be retroactively fixed, guaranteeing a Material Finding during supervisory review. A 30-day sandbox pilot today establishes the baseline evidence trail ahead of OSFI's 2026 exploratory check-ins.
Built on Verifiable Trust
OAIS is founded on the principle that trust must be cryptographically verifiable, not assumed. Every claim we make about audit custody can be independently verified by any third party.
About OAIS
Optimized Artificial Intelligence Systems Inc. is a Canadian company founded by Daniel Fruman, who brings over a decade of experience in healthcare privacy compliance and data governance. The founding team includes senior leaders from institutional investment management, insurance operations, and financial services.
Privacy Policy
OAIS operates a zero-knowledge architecture by design. We never see client content — only cryptographic fingerprints. Our privacy practices are documented transparently.
Contact & Support
Reach our team directly at info@oais.ai. Located at 25 Sheppard Avenue West, Suite 300, Toronto, Ontario M2N 6S6, Canada. We welcome conversations about AI governance, OSFI E-23 preparation, and compliance requirements.
Independent Cryptographic Witnessing: OAIS is a content-blind witness to the sequence and timing of your AI interactions — we see cryptographic fingerprints, never your data. Because the record is anchored independently of the audited party, an interaction cannot be silently altered or omitted after the fact, and any third party can verify the entire chain with a standalone script — no OAIS account or API access required.
Request a Demo
If your organisation is preparing for OSFI E-23 compliance, evaluating AI governance solutions, or needs to demonstrate control over AI interactions — we welcome a conversation.
Or reach us directly at info@oais.ai