Sovereign AI
Agents that never have to leave your building.
For organisations where the answer to “where does this data go” has to be “nowhere”. Your infrastructure, your models, and the documentation an assessment will ask you for.
Sovereignty
Nothing about this requires trusting us with your data.
Sovereignty is an architecture question before it is a policy question. This is the architecture.
It runs where your data already is
Docker, Kubernetes or bare metal, inside your own network and in front of your own systems. There is no shared tenancy and no aggregation of your traffic on our side.
The safety models are yours too
The classifiers that inspect content — PII detection, prompt-injection — are CPU-only and self-hosted. Inspecting a request does not mean sending it to a third party.
Small models, where they fit
Not every step needs a frontier model. A governed connector lets a local or small model handle the routine work, with the larger model reserved for the parts that earn it.
We see almost every company building in this space. Most are building MCP gateways for engineering teams of five or ten. Palma is a governance layer designed for enterprise scale and enterprise processes … which is why we did not just invest, we run it ourselves.

Local and small models
Why a smaller model suddenly works.
Teams usually conclude that a local model cannot do agent work. Far more often, the model was handed an impossible surface and no instructions.
The bottleneck is tools, not parameters
A small model fails at agent work mostly because it is handed a hundred ambiguous tools. Give it a curated, governed set and the gap to a frontier model narrows sharply.
A smaller surface per identity
Spaces expose only the tools an identity should see. That is a governance feature that happens to be the single most effective reliability fix for a small model.
The playbook does the reasoning
A Skill carries the sequence and the judgement calls, so the model has to improvise less. Knowledge in the Skill is capability the model does not need.
Swap the model, keep the governance
Access, policy and audit sit at the connector, not in the model. Changing which model runs where does not restart your governance work.
EU AI Act and friends
What an assessment actually asks you for.
Palma does not make anyone compliant — no product does. What it does is produce the material the questions are answered with, as a by-product of running the thing.
-
Provenance
Every model is documented
Licence, source, pinned digest and base model are recorded per model, verified on each bump rather than reconstructed later.
-
Purpose
Intended use and limits, written down
Each model carries its intended purpose and its stated limitations — including whether it is general-purpose or a narrow task model.
-
Evidence
The record of what agents did
Three-principal activity logging and tracked control-plane changes give you the operational history an assessment asks for.
-
Control
Human oversight where it counts
High-risk actions can require a named approver before they proceed, which is the control most oversight obligations are really asking about.
The record
Evidence produced by operating, not by preparing.
The audit trail is not something assembled before a review. Every call already carries the person, the agent and the client, with failures and their reasons alongside the successes.
- Three principals recorded on every tool call
- Control-plane changes tracked with diffs
- Filterable across every space, agent and server

Book a demo
See what governed AI agents look like.
A 20-minute demo on your stack. We'll show Palma working with the agents, tools and identity provider you already run.
- Enterprise security
- Role-based access
- Instant integration
Latest Blog Posts
Stay up-to-date with the latest in enterprise AI, MCP servers, and secure integration strategies.