Engineering-first · Regulated data

Secure infrastructure for agents handling protected data.

We build software from the ground up for organizations running AI agents on protected health information. Scalable, extendable platforms for the regulated data industry — starting with public health.

Explore the platform
Ogma Oversight emblem
FOCUSPUBLIC_HEALTH
DATA_CLASSPHI / CUI
COMPLIANCEFISMA/HITRUST

Purpose-built platforms and tooling for agentic systems operating inside regulated, high-trust environments.

How we build

Software for agentic systems in the regulated data industry.

01

Engineering-first

We are builders. Every platform, library, and tool is designed from the ground up by engineers who treat security and compliance as architecture, not an afterthought.

02

Scalable by design

Foundations that grow with you — from a single agentic workflow to fleet-wide deployments — without re-platforming as your regulated workloads expand.

03

Extendable & open source

Open, composable primitives and clean integration points so your teams can inspect, adapt, and extend our software to their own environments, frameworks, and controls.

04

Built for regulated data

Designed for organizations managing protected health information and other regulated data, where provenance, auditability, and trust are non-negotiable.

Oversight

Centralized repository scanning that monitors agentic tool definitions and logic chains. Detect vulnerabilities before deployment with real-time logging to a unified dashboard.

  • //CI/CD Integration Hooks
  • //Logic-chain Sanitization
  • //Central Policy Management

Undersight

The ground-level agent. Scans local at-rest operating environments for configuration drifts and runtime violations, feeding high-fidelity signals directly up to Oversight.

  • //At-rest Binary Analysis
  • //Environment Integrity Check
  • //Upward Signal Telemetry
Standalone scanner

Inspect agentic environments in place.

Undersight is a standalone, in-place system scanner for agentic environments. It hunts for rogue skills, misbehaving MCP connections, and prompt injection vectors across the full runtime surface — then uploads findings to any Oversight implementation for centralized review.

  • Rogue skill detection in agentic runtimes
  • Misbehaving MCP connection analysis
  • Cross-system prompt injection scanning
  • At-rest configuration drift monitoring
TYPEIN_PLACE_SCANNER
TARGETAGENTIC_RUNTIMES
OUTPUTOVERSIGHT_COMPATIBLE

Run Undersight locally against any agentic host — container, workstation, or server — and stream results to your existing Oversight dashboard, or export them for offline analysis.

Open by default

Three ways to deploy Oversight.

We believe core security infrastructure should be open and inspectable. Start with the free Community edition, scale with Enterprise, or let us host it for you in the Cloud.

Community

Free & open source

A pre-packaged, self-hosted distribution of Oversight. Download, audit, and run the full platform on your own infrastructure — no license required, no usage limits.

  • //Full source available
  • //Self-hosted
  • //Community support

Enterprise

Self-hosted at scale

The same core platform hardened for production scale. Built for regulated environments with advanced telemetry, fleet management, and priority support.

  • //High-availability ready
  • //Advanced policy engine
  • //Dedicated support

Cloud

Fully managed

Oversight hosted by us so you can focus on your mission. SOC-2 aligned operations with zero infrastructure overhead for your team.

  • //Zero infrastructure
  • //Automatic updates
  • //99.9% SLA
Where we start

Starting with public health.

We build for anyone managing regulated data with AI agents — and we are beginning where the stakes and the trust requirements are highest: public health organizations safeguarding protected health information.

  • Agentic workflows handling PHI across intake, triage, and reporting
  • Environments accountable to FISMA, NIST 800-171, and HITRUST
  • Public health programs modernizing on AI without sacrificing trust
Planned Compliance Mapping
FISMANIST 800-53
NIST 800-171CUI Control
HITRUSTCSF v11
SOC2Type II Audit