Lightwork puts AI agents to work on real operations (finance, legal, healthcare) with the governance, audit trail, and proof of safety a regulator requires before an agent touches a system that matters.
In regulated work the blocker isn't capability. It's three questions no one can answer, so the project never leaves the pilot.
No tamper-evident record of the actions an agent took.
No egress control, a hosted black box, or a framework you secure yourself.
No proof it's improving instead of quietly drifting.
Every action an agent takes (every tool call, every payment, every write) passes through one gate before it happens. Then it lands where a human signs off.
Self-hosted or air-gapped, on your data, no required egress, so even a successful prompt injection can't move data out.
Capability tokens, a policy engine, an egress lock, and a signed, hash-chained audit log, verifiable offline. Deep infrastructure, not a prompt over an API.
The workforce mines its own failures into one guidance line, proves it lifts results on held-out work, ships it as a watched canary, and retires it if it stops paying off. Even the evaluator only improves against an immutable anchor. Every change reversible, every change audited.
Least-privilege specialist packs across 53 regulated suites. Run domains-lint yourself.
Six governance invariants — no drafting agent can reach a state-mutating tool, no child can out-scope its parent, hard refusals can't be stripped, budget caps can't be silently exceeded — machine-checked across all 2,020 packs with a non-vacuous fault-injection control (property-fuzzed up to 5,000 iterations).
The platform itself, the specialist workforce that runs on it, a governance plane for the agents you didn't build, and bespoke builds for your operation.
The governed runtime. Every agent action passes one gate (capability, policy, shield, budget, signed audit), self-hosted or air-gapped, on your data.
How it works →Turnkey departments of specialist agents (Finance, Tax, Legal, and 50 more) each with a fixed job, least-privilege tools, and a human who signs off. 2,020 governed packs across 53 suites.
See the packs →Govern and learn from agents you didn't build, Agentforce, Copilot, in-house, open-source. One audited, tenant-isolated memory they all deposit into and recall from.
How it governs →Bespoke departments built by an agent factory that synthesizes a governed pack from a description, or a demonstration of the work, and gets better at building with every run. Custom regime packs, system-of-record connectors, regulated or air-gapped deployment.
What we build →One command signs an offline-verifiable evidence bundle. A live golden path refuses the dangerous action and leaves a receipt for every decision.
Every control your reviewers ask about maps to a mechanism in the platform, not a promise on a slide.
| What your reviewers require | The mechanism |
|---|---|
| Data never leaves your environment | Self-host or air-gap: your VPC or fully offline, on your data. |
| No data exfiltration | Egress lock: a successful prompt injection still can't move data out. |
| Least privilege, per action | Capability tokens (attenuate-only): an agent narrows its rights, never widens. |
| Bounded blast radius | Sandbox, network-off by default · hard budget caps on tokens, dollars, wall-clock, and tools. |
| A provable, immutable record | Signed, hash-chained audit: tamper-evident and verifiable offline. |
Security overview and SOC 2 status available on request. See the security posture →
We're working with a small number of design partners in regulated industries. If that's you, let's scope one workflow.