For operators · ship the LLM feature compliance keeps blocking

Ship the LLM feature compliance keeps blocking.

Sign up to Enterprise. Author one RuntimeAISpec. Wire the SDK into your existing service. Promethean produces the signed receipt chain, the audit bundle, and the regulator-readable handoff packet — under the same Ed25519 trust anchor as the three live references.

€2,499
Enterprise · flat / month
self-service · Stripe checkout · cancel anytime
3
Reference deployments to point at
paysafe · cliniclens · civicgate — pattern-match your domain
7
Framework templates
GDPR · AI Act · PSD3 · DORA · NIS 2 · MDR · HIPAA
1
Regulator handoff packet
signed receipt chain · audit bundle · mandate mapping

You have an AI feature that should already be in production. Fraud classifier. Clinical-note structurer. Citizen message router. Underwriting summariser. Customer-service triage. The product team wants to ship. The model works. Compliance, legal, and audit have been saying "not yet" for two quarters.

The veto is structural, not stubborn. Without a closed-enum output surface there's no way to bound liability. Without a signed receipt chain there's no way to prove what the model decided. Without a regulator-readable handoff there's no way to defend the deployment under PSD3 / HIPAA / AI Act / DORA. Most AI tooling sits on top of the LLM call. Promethean bounds it — and produces, automatically, the evidence pack your DPO and notified body need.

No 90-day engagement gate. No two-engineer retainer. Sign up to Enterprise (€2,499/mo) and ship.

What shipping looks like

Six self-service phases. From signup to regulator handoff.

Week 1–2

Author the spec

Translate your AI feature into a RuntimeAISpec — closed-enum category, output schema, reviewer-gate criteria, fallback behaviour. Pre-register the acceptance criteria your compliance team will use to sign off.

Gate

Spec authored · acceptance criteria written down · stakeholders aligned

Week 3–4

Wire the SDK

The SDK emits the runtime-AI client code from your spec. Your existing product calls runConstrainedAI. Staging environment carries a real signed receipt chain. Differential tests prove your spec matches your intent.

Gate

Staging receipt chain producing entries · internal review passes

Week 5–7

Soak against staging

Staging traffic shadows production. The adversarial test suite runs known attack patterns against your spec. Property-based fuzz exercises 700+ random inputs. Your audit team validates the chain against their evidence requirements.

Gate

Audit-team sign-off · chain integrity verified · zero corruption incidents

Week 8–9

Ship to production

Cut over to production. The receipt chain anchors live to Bitcoin via OpenTimestamps. The continuous-verify daemon reports per-chain integrity to your monitoring stack.

Gate

Production receipt chain live · first regulator-citable receipt · OTS proof complete

Week 10–11

Generate the handoff

The audit-bundle CLI produces the regulator-readable packet: full receipt chain, runnable verifier, mandate-mapping table, RuntimeAISpec lineage. Your compliance team reviews.

Gate

Compliance sign-off · packet ready for first regulator conversation

Week 12

Falsify or extend

Pre-registered acceptance criteria checked against observed reality. Did the receipt chain shorten your DPO's review cycle? Did the closed-enum surface eliminate the liability questions? Did the model fail safely when it failed? Honest assessment, signed, filed.

Gate

Acceptance verdict signed · ready for the next feature

Live · reviewer queue surface

Human-in-the-loop, where the spec demands it. Live, in the console.

Below is the reviewer-queue surface your team would use during the pilot. Approve, amend, or reject — every verdict writes an L12 entry under your trust anchor within seconds.

Promethean · console
● chain ok3 pending verdicts
paysafe-fraud-classifier·conf 0.62

confidence 0.62 < threshold 0.7

€4,200 transfer · GB→NG · new merchant · 02:14 local

{
  "risk": "high",
  "reason": "cross-border, new merchant, off-hours"
}
✕ reject✎ amend✓ approve
civicgate-message-router·conf 0.71

confidence 0.71 < threshold 0.85 (life-impact keywords)

EN · 'My water has been off for 6 days and my elderly father needs dialysis.'

{
  "department": "utilities",
  "urgency": "high"
}
✕ reject✎ amend✓ approve

+ 1 more pending in the live queue

The split

What we bring. What you bring.

Promethean

The product, end-to-end

  • The runtime-AI SDK (TypeScript + Python, Apache 2.0)
  • RuntimeAISpec primitive + reviewer-gate predicates
  • Code emission for your spec (the generator that writes your client)
  • Signed receipt-log infrastructure + key ceremony documentation
  • Continuous-verify daemon + OpenTimestamps anchor automation
  • Regulator-readable handoff packet generator (7 framework templates)
  • Three Promethean-operated reference deployments to pattern-match against
  • Public docs, public verifier, public ADR trail — no NDA gate

You

The workload + the conversation

  • A real LLM-in-the-loop feature with a stalled compliance review
  • An existing product you can wire the SDK into
  • Production traffic to shadow during the soak period
  • Audit / compliance / legal stakeholders to review the handoff packet
  • An Ed25519 signing key (operator-managed env-var custody today; HSM-backed for Enterprise on the roadmap — we document the ceremony)
  • The regulator conversation — you own it; we provide the artifacts
  • Honest acceptance criteria for what production-ready means in your domain

Three regulated archetypes

Pattern-match your domain. Three Promethean-operated reference deployments.

Fintech · PSD3 + DORA

paysafe

Fraud classifier

The classifier flags 0.3% of transactions. Compliance won't allow a model in the decision path without per-call audit. Vendor SOC 2 reports cover the platform, not the model.

Healthcare · HIPAA + MDR + AI Act

cliniclens

Clinical-note structurer

Clinician dictates, model produces structured ICD-coded notes. HIPAA-readable audit trail of every model output. MDR class-IIa device classification under AI Act. Hospital legal says no.

Govtech · eIDAS + GDPR Art. 22

civicgate

Citizen message router

Citizen submits a request. Model classifies and routes to the right department. GDPR Article 22 says citizens have the right to know about automated decisions. The municipality needs to prove it can answer that question.

Pre-registered honesty

When this works. When it doesn't.

Pilot succeeds when ↗

  • Feature ships to production with full audit sign-off
  • L12 chain integrity verified continuously, zero corruption incidents
  • Audit-cycle time reduced by at least 50% vs. prior LLM-feature reviews
  • Regulator conversation moves from "show us the model" to "show us the chain"
  • Adversarial autoplay finds zero spec-bypass paths in production

Pilot fails honestly when ↘

  • RuntimeAISpec can't express your feature's decision surface (some features genuinely need open generation)
  • Reviewer-gate latency overwhelms the user-facing SLA you need
  • Your audit team rejects the receipt-chain format for reasons we can't resolve quickly
  • Production traffic reveals a failure mode the SDK's current generators don't handle
  • The signed evidence didn't actually shorten your DPO's review cycle

Failure modes get recorded as ADRs and tests so the next operator doesn't trip on them. The substrate audits itself; pre-registered acceptance criteria prevent post-hoc rationalisation.

Next step

Promethean produces signed evidence your AI feature can survive a regulator.