Varanus

AI governance control plane

Adopt AI.
Keep control.

Most tools prove compliance with questionnaires. Varanus measures it: you don’t prepare the evidence for the audit — you already have it.

The single pane over your organization’s AI — govern what passes through your gateway, observe what your teams consume, and prove EU AI Act, DORA and GDPR compliance without slowing anyone down.

Mapped to the frameworks that audit you

  • EU AI Act
  • DORA
  • GDPR
  • ISO 27001
  • ENS

You see all your AI. You govern what passes through you.

Most tools ask you to declare what you use. We measure it from two angles — and tell you plainly what we control and what we observe. Because claiming you govern everything is easy; proving it is another matter.

Governed

The traffic that passes through your gateway

Policies enforced at runtime, blocking of what must not leave, and evidence for every request. Claude Code and any client with a configurable endpoint — against the provider’s API or against Bedrock, Vertex and Azure.

Control at runtime.

Observed

Your teams’ subscription usage

The usage that never passes through a gateway — Claude Code seats, ChatGPT and the like — measured from the provider’s own administrative data: inventory, cost and people, by model. No blocking, no seeing the content.

On the Varanus roadmap.

A CISO who today can’t name who uses AI in their organization gains the full inventory. What passes through Varanus is governed as well.

Who uses AI in your company

AI is already inside your code and your business.

Both developers with their coding tools and business staff pasting documents into ChatGPT. Two different uses, two different risks — and neither passes today through anywhere you can look.

The developers

Assisted code, no visibility

Claude Code, Copilot and others are already in your company. Nobody knows what they cost, which models are used, or what code and data leave with each request. It’s AI’s entry point into development — and the hardest to govern.

Everyone else

Business pasting documents into accounts you don’t control

HR, legal, finance — summarizing files, explaining contracts, analyzing data with ChatGPT or Claude from personal accounts. They upload documents that shouldn’t leave, and nobody knows what or how much. Someone uploading personal data to a personal account is a GDPR breach with a name attached.

Much of it goes through personal accounts, outside your gateway. Today it’s invisible; with Varanus, at least it’s seen.

That is shadow AI: AI the organization uses without knowing it uses it. The problem isn’t that they use it — it’s that nobody knows what is being used, for what, with which data, and at what cost. Varanus is where you see it.

The cost you don’t see

Spend by team, by person and by model — in the provider’s currency and in yours, with the exchange rate frozen on each request. No end-of-month surprises.

The data and documents that leave uncontrolled

Detection of secrets, personal data and sensitive documents in the prompt before they leave. In the traffic that passes through your gateway, it’s blocked; in everything Varanus observes, it’s measured.

The crossing nobody else has

Cost by risk level

Every euro of spend, classified by the risk of the application that generated it. The CIO reads it as spend; the CISO, as regulatory exposure. Same figure — and where the two conversations meet.

All your AI usage, on one screen

Interactions, cost, policies, risk and evidence — by model, by team, by person and by period. All measured on real traffic.

Illustrative view
Varanus panel: summary of cost, risk, policies and evidence over real traffic
A real panel on a test workspace — modest data, but real. We don’t show invented figures: the same rule we apply inside the product.

European by design

Built for the regulated European enterprise

Hosted in the EU

Data and inference inside the European Union. No detours to jurisdictions that would complicate your own audit.

Compliance by design

Governance is not a report generated before the inspection: it’s a property of the system, present on every request from day one.

The frameworks that audit us

EU AI Act, DORA, GDPR, ISO 27001 and ENS — the same ones you’re measured against. We map your AI usage to them, with evidence.

Adopt AI. Keep control.

Start by seeing all the AI in your organization. Govern what passes through Varanus.

Request a demo