Private alpha · request access

The agent workforce a regulated enterprise can actually deploy.

Lightwork puts AI agents to work on real operations (finance, legal, healthcare) with the governance, audit trail, and proof of safety a regulator requires before an agent touches a system that matters.

Self-hosted or air-gapped Signed, tamper-evident audit Provably improving
Built for regulated operations in
FinanceHealthcareInsuranceLegalGRCPrivacy
The problem

Agents pass the demo. They fail the diligence review.

In regulated work the blocker isn't capability. It's three questions no one can answer, so the project never leaves the pilot.

“What did it do?”

No tamper-evident record of the actions an agent took.

“Could it exfiltrate our data?”

No egress control, a hosted black box, or a framework you secure yourself.

“Will it get worse?”

No proof it's improving instead of quietly drifting.


How it works

Not a chatbot. Not a framework. A governed runtime.

Every action an agent takes (every tool call, every payment, every write) passes through one gate before it happens. Then it lands where a human signs off.

01
Capability
Attenuate-only tokens. An agent can narrow its rights, never widen them.
02
Policy
Allow, deny, or require a human, bound to every action.
03
Shield
Scans for the dangerous action and the prompt injection.
04
Budget
Hard caps on tokens, dollars, wall-clock, and tools.
05
Audit
A signed, hash-chained entry you can verify offline.

Self-hosted or air-gapped, on your data, no required egress, so even a successful prompt injection can't move data out.

Why Lightwork

Three things no one else ships.

01

Governance on every action

Capability tokens, a policy engine, an egress lock, and a signed, hash-chained audit log, verifiable offline. Deep infrastructure, not a prompt over an API.

02

Provable improvement

The workforce mines its own failures into one guidance line, proves it lifts results on held-out work, ships it as a watched canary, and retires it if it stops paying off. Even the evaluator only improves against an immutable anchor. Every change reversible, every change audited.

03

2,020 specialists, built in

Least-privilege specialist packs across 53 regulated suites. Run domains-lint yourself.

2,020
governed specialist packs
53
regulated suites, already built
0
required egress · your data never leaves

Six governance invariants — no drafting agent can reach a state-mutating tool, no child can out-scope its parent, hard refusals can't be stripped, budget caps can't be silently exceeded — machine-checked across all 2,020 packs with a non-vacuous fault-injection control (property-fuzzed up to 5,000 iterations).

The product line

Four ways to put governed agents to work.

The platform itself, the specialist workforce that runs on it, a governance plane for the agents you didn't build, and bespoke builds for your operation.

Proof

We don't say it's governed. We show it.

One command signs an offline-verifiable evidence bundle. A live golden path refuses the dangerous action and leaves a receipt for every decision.

lightwork golden-pathevery row tamper-evident
boot finance specialistSEALED
$60,000 wireDENY
$6,000 releaseREQUIRE_HUMAN
runaway loopCAPPED
alter an audited rowCAUGHT
lightwork proof-pack● Ed25519 signed
# PROOF.md · verifiable offline
governance✓ PASS
reliability✓ CERT
performance✓ SLA
shield✓ PASS
Security & deployment

Built to clear your security review.

Every control your reviewers ask about maps to a mechanism in the platform, not a promise on a slide.

What your reviewers requireThe mechanism
Data never leaves your environmentSelf-host or air-gap: your VPC or fully offline, on your data.
No data exfiltrationEgress lock: a successful prompt injection still can't move data out.
Least privilege, per actionCapability tokens (attenuate-only): an agent narrows its rights, never widens.
Bounded blast radiusSandbox, network-off by default · hard budget caps on tokens, dollars, wall-clock, and tools.
A provable, immutable recordSigned, hash-chained audit: tamper-evident and verifiable offline.

Security overview and SOC 2 status available on request. See the security posture →

Who it's for

Where governance is the buying criterion.

Finance
Reconciliation, vendor risk, controls, under audit. Highest regulatory pain, clearest ROI.
Healthcare
Operations on PHI, self-hosted, with a record a compliance officer can stand behind.
Insurance
Claims and underwriting work, governed and reversible, with proof of every decision.
Legal
High-stakes document work where accountability and a tamper-evident trail are non-negotiable.
GRC
Every agent action mapped to a control, with audit-ready evidence (SOC 2, EU AI Act, model risk) generated as the work happens.
Privacy
DSAR, erasure, and retention under governance, GDPR/CCPA coverage and a defensible record of every decision.
Get started

Put your agents to work, under governance you can prove.

We're working with a small number of design partners in regulated industries. If that's you, let's scope one workflow.