2AYE
Enforcement, privacy, and trust

Enforce intent without making regulated data leave customer control.

2AYE separates policy coordination from runtime enforcement. The protected resource validates short-lived, action-bound grants while regulated fields can remain inside the customer boundary.

Deployment modes

One decision model across three operational boundaries.

SaaS

Managed evaluation for lower-sensitivity workloads. Partial: single-region baseline.

Regulated default

Hybrid

Customer-boundary runtime evaluation with a managed 2AYE control plane. Designed, not yet available.

Customer hosted

Customer-operated enforcement for sovereign and self-hosted environments. Designed, not yet available.

Runtime controls

Designed for the questions security architects ask first.

Data minimization (partial)

Field classification, disclosure manifests, keyed predicates, and local derivation.

Failure behavior (partial)

Risk-class fail rules; consequential writes always fail closed.

Key custody (designed)

Customer-held intent authority, BYOK/HYOK, and separated key roles.

In-flight revocation (partial)

Atomic grant consumption, cancellation, reconciliation, and compensation.

Administrative governance (partial)

Four-eyes changes and tamper-evident administrative evidence.

Approval fatigue (partial)

Risk-tiered intervention, exact-action binding, and behavioral metrics.

What this includes

  • Deterministic failure is final
  • Exact action and destination binding
  • Revocation checked at execution
  • Atomic grant consumption
  • Number matching and expiring approvals
Your governed workflow

Bring the next consequential action under control.

Show us the actor, protected resource, and action that must never execute without exact authority. We’ll map the decision and evidence path with you.

Discuss your workflow Read the implementation guide
Enforcement, Privacy, and Trust | 2AYE