Compliance-grade AI control plane

AI you can deploy without a six-month Legal review.

Olympus sits between your business and your model vendors. It enforces policy on every call, masks sensitive data before it leaves your perimeter, records every decision with Delta replay lineage you can replay end-to-end, and survives a provider swap without losing your memory or audit trail.

Replay Rewind any decision to the exact state + context.
Policy Versioned packs, enforced before the call ships.
PII Masked at the gateway, never in vendor logs.
Memory Survives model swaps. Your context is yours.
Providers supported 4+ Google · OpenAI · Anthropic · Copilot
State compression ~91× Delta-encoded session history
Policy enforcement Pre-call Not in prompts. Not after the fact.
Audit export Signed Replay bundle ready for regulators
The problem your CISO already flagged

Legal can't approve what it can't audit.

Your LLM pilot works. Your Legal team is stuck on four questions.

Gateway-only tools (LiteLLM, Portkey, Helicone) handle routing and observability. None of them ship the memory, policy, approvals, and replay stack an auditor actually asks for.

What ships today

Four capabilities, one control plane.

01 · Routing

Provider-independent sessions

Google, OpenAI, Anthropic, and Microsoft Copilot under one API. Midas-driven routing, per-session preference, automatic failover. Swap vendors mid-session without losing state.

02 · Memory

Delta-powered continuity

Session state persists across provider swaps, restarts, and branches. Delta is the continuity engine that keeps operating context reconstructable instead of trapping it inside vendor sessions.

03 · Governance

Policy, approval, and audit

Versioned policy packs. Human-in-the-loop approvals with signed audit entries. PII masking enforced at the gateway, not the prompt. Every call leaves a defensible trail.

04 · Replay

Replay Studio

Inspect any session timeline, diff branches, compare across providers, export a replay bundle. The answer to "what did the model know when it decided that?" in 30 seconds.

Regulatory mapping

Built for the auditor, not the demo.

Each control is a question your auditor will actually ask. Olympus has a surface that answers it.

Control Regulation Olympus surface
Reconstruct model-decision context SOX · FINRA · FDA SaMD Replay Studio + Delta replay lineage
Prove PII did not leave perimeter HIPAA · GDPR Art. 32 Gateway PII masking + identity scopes
Human review of high-risk output FINRA · SR 11-7 Approvals queue + signed audit trail
Policy enforcement on every call EU AI Act · NIST AI RMF Versioned packs enforced pre-call
Continuity under vendor change OCC third-party risk Provider-independent memory + failover
Rate-limit / budget controls FedRAMP · SOC2 CC6 Per-identity limiter + budget caps
Why not just use a gateway

Because a gateway doesn't talk to your auditor.

Capability LiteLLM Portkey Helicone Olympus
Multi-provider routingyesyesnoyes
Observability on callsbasicyesyesyes
Policy packs enforced pre-callnopartialnoyes
Human approval queuenononoyes
PII masking at gatewaynopartialnoyes
Memory across providersnononoyes
Delta replay lineagenononoyes
Signed audit exportnopartialpartialyes

Those companies sell to the VP Eng. Olympus sells to the CISO.

Deployment

Where your data lives is your call.

Managed SaaS

Single-tenant VPC

Your keys, your data, our operators. Fastest time-to-pilot. Best fit for mid-market teams who want the control plane without running it.

On-prem

Docker Compose or Kubernetes Helm

Runs air-gapped. No call-home. HIPAA BAA available. Most regulated enterprises land here.

Hybrid

On-prem gateway · managed dashboard

Data plane stays in your perimeter; control plane is hosted. Common first-year path for banks and healthcare systems.

Security posture

SOC2 Type II · HIPAA BAA · ISO 27001 roadmap

TLS 1.3 in transit, AES-256 at rest, KMS-backed rotation. SAML + SCIM at Team tier and above. Data plane never sees cleartext PII.

Pricing

Priced on events. Stored as deltas.

Compression keeps our gross margin honest so we can price below the cost of "build it yourself."

Team $30–60kper year Mid-market eng leader
  • 10M events / month
  • SSO (SAML + SCIM)
  • 90-day retention
  • Audit export
  • Email support
Enterprise $150–500kper year Regulated enterprise CISO
  • On-prem or hybrid deployment
  • HIPAA BAA · SOC2 evidence pack
  • Policy pack authoring workshop
  • Dedicated CSM + named SE
  • 99.9% SLA
Platform $500k–1.5Mper year F500 / systemic buyer
  • Multi-org / multi-region
  • HSM integration
  • FedRAMP-ready deployment
  • Custom integrations + schema
  • Executive QBRs
Paid first step

Not ready for a pilot yet?

Olympus AI Control Teardown is the fastest way to review one workflow, identify the governance and control gaps, and decide whether a design sprint or pilot is actually justified.

Design partner program

Taking one regulated logo per vertical.

90-day pilot. Two production workflows instrumented. Named executive sponsor + Legal/Compliance reviewer. In exchange: 50% off year-one, influence over the policy-pack schema, and a direct line to the founders.