AI governance for regulated organisations

Scale AI with confidence.

GatedFlow is the AI portfolio operating system for regulated organisations. Fast where it's safe, controlled where it's risky, and provable to anyone.

Australian-built · APRA / OAIC / Privacy Act aligned · self-hostable

The problem

Are you actually in control of your AI?

AI is moving from pilots into production faster than the governance around it, and in Australia the regulators are closing the gap fast. Most organisations are trying to keep up in spreadsheets and email, where governance quietly decays. Shadow AI spreads, pilots stall, and the board can't get a straight answer.

How it works

An operating system, not a register.

GatedFlow runs the whole AI lifecycle, proportionate by design, so governance enables adoption instead of blocking it. An AI co-pilot helps your teams write better governance inputs along the way, and refuses to fake the parts that matter.

1

Register

Every AI use case in one register, classified by how it entered, including the vendor-added and shadow AI most inventories miss.

2

Risk-tier

A deterministic tiering engine scales oversight to risk: fast-lane the safe, full review for the high-stakes.

3

Gated review

Stage gates and the right forums review each use case, with decisions and accountability on the record.

4

In-life assurance

Keep watch after go-live, and produce a regulator-ready, tamper-evident evidence pack on demand.

What you get

Value for every seat at the table.

One operating system, four lenses. Each buyer gets the outcome that matters to them, from the same running system.

See the full value breakdown by role →
Why GatedFlow

Built for the Australian regulated market.

For banks, insurers, super funds and customer-operations teams putting AI in front of customers and claims.

AU-native

Aligned to APRA, OAIC and the Privacy Act, not an EU-Act-first generic platform.

Operating model

A running tier → gate → forum system your teams actually use, not another document register.

Sovereign

Self-hostable for data-residency-sensitive organisations. Your data stays yours.

Pairs with what you have

Feeds evidence to your existing GRC and advisory work. It doesn't replace them.

Honest about the stage: GatedFlow is working with a small number of design partners. It assembles defensible, regulator-ready evidence and enforces the controls that matter. It doesn't replace your professional judgement, your GRC, or your regulator.

Trust & security

Sovereign by default, honest about the rest.

The questions a CISO and a risk officer ask before a demo, answered up front.

Self-host + AU residency

Deploy in your own tenancy. Your data stays yours, which removes the fourth-party question before it is asked.

Tamper-evident audit

An append-only, hash-chained record with chain verification. Proof the record was not changed after the fact.

Two hard rules

A lawful-basis HALT stops anything without a legal basis, and a use case is cleared only when every required forum approves.

Sovereign AI co-pilot

Provider-abstracted and mock-by-default. No client data leaves your tenancy unless you deliberately configure a provider.

Honest about the gaps: SSO, MFA and SCIM, and SOC 2 and IRAP certification, are on a demand-gated roadmap. Self-host bridges the assurance set today, and we would rather tell you that than hide it.

Let's talk.

If you're scaling AI in a regulated business and want governance that enables adoption rather than blocking it, we'd like to show you a 20-minute walkthrough on a worked example.

Request a demo