FI·EN

A governed AI layer

All AI usage
in one governed point.

Todenta is AI governance. Who uses AI, what is allowed, what data may leave the building, and what it costs — and every call leaves a record.

Applications no longer talk to AI services directly. Calls run through Todenta, where every request is checked before it goes any further.

Who is using itthe user and the application are identified
What is allowedallowed usage and limits
What may leave the buildingsensitive data is filtered out
What it costcosts are visible, the budget holds
Audit traila record for every call

Why this exists

When AI usage spreads out, no one can see the whole picture.

Every team signs up with its own account and talks to AI services directly. No one knows what data went out, what it cost, or who did it — until something goes wrong.

01

What went out

Sensitive data can end up with an outside service, because no one inspects the content along the way.

02

What it cost

Costs scatter across dozens of accounts. The budget is overrun unnoticed, and the bill arrives late.

03

Who did it, and when

No trail, no accountability. When something needs to be investigated, no one can show what happened.

Simply passing calls through is not a solution — many do that for free. The value of Todenta is in the decisions: what was let through, what was not, and why.

How it works

Four checks that every request passes through.

Every AI request goes through the same gate. Nothing slips past, and nothing leaves without being checked first.

  1. 1 Who is using it Every request can be traced to a user and an application. No anonymous usage, no shared accounts.
  2. 2 What is allowed Each user and application has its own limits: which AI models may be used and how much. Prohibited usage stops before it goes anywhere.
  3. 3 What may leave the building Sensitive data — personal data, contact details, account numbers — is filtered out before the content moves on. The filtering shows up in the log; it is not hidden.
  4. 4 What it cost Costs are visible in real time by user and by application. The monthly and daily budget is a hard limit — when it is reached, usage stops.

Cache

The same question, the same answer — without sending the data out again.

If the same question has been asked before, the answer is already in-house. Then no new request is sent anywhere — and each such time is one time the data did not leave at all.

What caching means

  • Nothing goes out. A hit means the answer was already found — no new call, no new transfer out.
  • Savings. The same answer, no new bill. The more often the same question is asked, the less it costs.
  • A per-application choice. Each application can decide for itself whether storage is used.

Three things we do not compromise on

  • Personal data is never stored. If a question or answer contains personal data, it is not kept in memory — regardless of the settings.
  • Isolation is structural. One tenant's answer can never be visible to another.
  • Deletion leaves a record. When a stored answer is deleted, the deletion is logged — it is evidence, not a promise.

A hit is stronger than filtering: with filtering the data still travels, just modified; with a hit it does not leave at all. A change to the rules also invalidates old stored answers, so that an old answer does not live on under the new rules.

Audit trail

Every call leaves a permanent record.

Todenta does not just store that something happened. It stores what happened, by whom, and on what grounds — and in such a way that a later change is detected.

What the trail tells you

  • Who made the request — user and application
  • What was requested and for which AI model
  • What was filtered out before departure
  • What it cost and how long it took
  • Whether the request was allowed through or blocked

Why it stands up to scrutiny

  • Entries cannot be changed afterwards. Every record is written permanently, not overwritten.
  • Changes are detected. If an entry is tampered with, it is noticed — and it is reported where.
  • Verifiable at any time. The trail can be checked whenever, by an outside party too.
  • Blocked requests are recorded too. What did not get through is as important to know as what did.

The trail is tamper-evident, not tamper-proof. It is only trustworthy once it is taken outside the application — and that distinction is stated plainly, not hidden.

EU rules

Built to EU requirements — not bolted on afterwards.

Todenta answers the same questions that the EU General Data Protection Regulation and the EU AI Act require: what was allowed to leave, what was logged, and what was deleted. The answer is evidence, not a claim.

GDPR

Data minimisation

Only what is necessary is allowed to move on. Sensitive data is filtered out, and what does not need to be sent is not sent — caching reduces outgoing data even further.

GDPR

Right to be forgotten

When data is deleted, the deletion is logged. The right to erasure is evidence, not a promise — for stored answers too.

AI ACT

Traceability

The use of AI must be traceable. Todenta records who, what, when, and on what grounds — including blocked requests.

AI ACT

Oversight and limits

System usage must be known and bounded. Usage is identified and limited, and every blocked request stays visible.

Todenta provides the evidence the rules require — it is not legal advice, and it does not automatically make a company compliant. It makes compliance demonstrable.

Overview

What happened, why, and what it cost.

Dashboard

Usage, cost, errors, budget consumption, and the latest events — at a glance.

Call log

Every request with its filters: who, which model, what was filtered, how long it took, and what it cost.

Governance

Blocks, filters, budgets, and permissions in one view.

Cache and avoided egress

How many times data did not leave the building — and whether the figure is verifiable.

Audit trail

The status of the trail and the latest verification. Can be checked again at any time.

Errors and fallbacks

Failed attempts and their fallbacks — visible, not disappearing.

Applications and services

Applications, permissions, and models. Switching a model needs no coding.

Users

Who can sign in and what each person sees.

For whom

For developers, management, and auditors.

FOR DEVELOPERS

One shared way

All applications use the same route. Switching a model requires no code changes, and the credential always shows who and which application called.

FOR MANAGEMENT

Limits that hold

The budget stops usage, sensitive data does not leave without filtering, and different tenants stay separate. Rules, not wishes.

FOR AUDITORS

A trail that lasts

Every decision and cost is traceable, and the trail is verifiable. There is an answer to the question “why did this go out”.

Get started

Let’s roll it out.

Applications are routed through Todenta and otherwise keep working the same way. Usage is logged, passes through the checks, and can be managed from one place.

What you get right away

  • Visibility into all AI usage — who, what, when
  • Costs and budget in one view
  • Filtering of sensitive data before it leaves
  • Response caching: the same question does not go out twice
  • A trail that stands up to scrutiny — and the evidence the EU requires

Request a demo   Sign in

Rollout is agreed case by case. We start with a review, not with a commitment.