GatedFlow is the AI portfolio operating system for regulated organisations. Fast where it's safe, controlled where it's risky, and provable to anyone.
Australian-built · APRA / OAIC / Privacy Act aligned · self-hostable
AI is moving from pilots into production faster than the governance around it, and in Australia the regulators are closing the gap fast. Most organisations are trying to keep up in spreadsheets and email, where governance quietly decays. Shadow AI spreads, pilots stall, and the board can't get a straight answer.
GatedFlow runs the whole AI lifecycle, proportionate by design, so governance enables adoption instead of blocking it. An AI co-pilot helps your teams write better governance inputs along the way, and refuses to fake the parts that matter.
Every AI use case in one register, classified by how it entered, including the vendor-added and shadow AI most inventories miss.
A deterministic tiering engine scales oversight to risk: fast-lane the safe, full review for the high-stakes.
Stage gates and the right forums review each use case, with decisions and accountability on the record.
Keep watch after go-live, and produce a regulator-ready, tamper-evident evidence pack on demand.
One operating system, four lenses. Each buyer gets the outcome that matters to them, from the same running system.
Move from pilots to production with no shadow AI, proportionate by design. For the Chief AI Officer.
A stage-gated delivery system built for AI: stage, owner, next action, status. For the Program Office.
Fund or kill every AI bet on value and risk-adjusted return. For the Portfolio Manager.
Regulator-ready, tamper-evident evidence in a day, not weeks. For the CRO and Board.
For banks, insurers, super funds and customer-operations teams putting AI in front of customers and claims.
Aligned to APRA, OAIC and the Privacy Act, not an EU-Act-first generic platform.
A running tier → gate → forum system your teams actually use, not another document register.
Self-hostable for data-residency-sensitive organisations. Your data stays yours.
Feeds evidence to your existing GRC and advisory work. It doesn't replace them.
Honest about the stage: GatedFlow is working with a small number of design partners. It assembles defensible, regulator-ready evidence and enforces the controls that matter. It doesn't replace your professional judgement, your GRC, or your regulator.
The questions a CISO and a risk officer ask before a demo, answered up front.
Deploy in your own tenancy. Your data stays yours, which removes the fourth-party question before it is asked.
An append-only, hash-chained record with chain verification. Proof the record was not changed after the fact.
A lawful-basis HALT stops anything without a legal basis, and a use case is cleared only when every required forum approves.
Provider-abstracted and mock-by-default. No client data leaves your tenancy unless you deliberately configure a provider.
Honest about the gaps: SSO, MFA and SCIM, and SOC 2 and IRAP certification, are on a demand-gated roadmap. Self-host bridges the assurance set today, and we would rather tell you that than hide it.
If you're scaling AI in a regulated business and want governance that enables adoption rather than blocking it, we'd like to show you a 20-minute walkthrough on a worked example.