One control layer for organizational AI
Vayon AI governs every organizational AI request end to end: identify, classify, enforce, route and audit — before eligible model execution. One control layer across internal and approved cloud models.
Govern. Route. Audit.
From entry surface to approved model
A single governed path between entry surfaces and approved model execution.
Pick a request type and play it. Vayon AI runs inside your organization; cloud egress happens only through an approved policy gateway.
Pick a request type above to see its governed path.
-
User chat
An employee sends a question or a file through the enterprise chat.
-
Identity & permission
Who is asking, their role and what they may do — RBAC/ABAC and activity windows.
-
Sensitivity & content
Content is classified, sensitive data detected, and the egress decision made.
-
Queue & routing
Eligible requests are routed according to configured policy and available destinations, with internal models preferred where policy permits.
-
Internal model
The model runs inside the organization and returns an answer — the default.
Internal / on by default -
Evidence & audit
The decision is recorded as safe metadata — without keeping the sensitive content.
-
Response to caller
The answer returns through the same secure channel it came from.
-
System via API
An enterprise system sends a request through a secure gateway.
-
Identity & permission
Who is asking, their role and what they may do — RBAC/ABAC and activity windows.
-
Policy
Where it may be processed, which providers are approved, and the organization’s rules.
-
Queue & routing
Eligible requests are routed according to configured policy and available destinations, with internal models preferred where policy permits.
-
Internal model
The model runs inside the organization and returns an answer — the default.
Internal / on by default -
Evidence & audit
The decision is recorded as safe metadata — without keeping the sensitive content.
-
Response to caller
The answer returns through the same secure channel it came from.
-
Developers · VS Code
A dev tool or coding agent asks for help — the content stays internal.
-
Identity & permission
Who is asking, their role and what they may do — RBAC/ABAC and activity windows.
-
Policy
Where it may be processed, which providers are approved, and the organization’s rules.
-
Queue & routing
Eligible requests are routed according to configured policy and available destinations, with internal models preferred where policy permits.
-
Internal model
The model runs inside the organization and returns an answer — the default.
Internal / on by default -
Evidence & audit
The decision is recorded as safe metadata — without keeping the sensitive content.
-
Response to caller
The answer returns through the same secure channel it came from.
-
Enterprise agent
A system invokes an agent that acts on the organization’s behalf.
-
Identity & permission
Who is asking, their role and what they may do — RBAC/ABAC and activity windows.
-
Policy
Where it may be processed, which providers are approved, and the organization’s rules.
-
Human approval
An impactful action pauses for a person — preview → approve → execute.
Conditional on controls -
Queue & routing
Eligible requests are routed according to configured policy and available destinations, with internal models preferred where policy permits.
-
Internal model
The model runs inside the organization and returns an answer — the default.
Internal / on by default -
Evidence & audit
The decision is recorded as safe metadata — without keeping the sensitive content.
-
Response to caller
The answer returns through the same secure channel it came from.
-
Knowledge source
Files or SharePoint feed content into the knowledge base.
-
Sensitivity & content
Content is classified, sensitive data detected, and the egress decision made.
-
Process & embed
Documents are chunked, classified and embedded — and stay internal.
-
Knowledge store
Stored with source permissions and domain scoping: each asker sees only what they may.
-
Evidence & audit
The decision is recorded as safe metadata — without keeping the sensitive content.
-
Browser extension
Text is checked before it is sent to an external AI service.
-
Identity & permission
Who is asking, their role and what they may do — RBAC/ABAC and activity windows.
-
Sensitivity & content
Content is classified, sensitive data detected, and the egress decision made.
-
Policy
Where it may be processed, which providers are approved, and the organization’s rules.
-
Decision
Allow · mask · route internally · block — before any cost is incurred.
Illustrative — the stations represent the control steps, not a live recording.
Beyond the gateway: the managed browser
Vayon AI governs what passes through it. A managed-browser client extends that reach to the AI services people open directly — the public AI assistants — checking what a person sends and what they attach against the same organizational rules that govern internal chat. The client carries no rules of its own: every decision is made by the platform, so a rule written once applies to a typed sentence and a spreadsheet cell alike. Managed extensions provide this complementary real-time path across Chrome, Edge and Firefox, deployed through enterprise browser policy rather than asked of each person. Governance covers the AI sites the organization configured, on managed browsers — it is not a claim to see every possible route to an AI service. The managed-browser client is part of the Endpoint AI Governance extension.
What Vayon AI is — and is not
A quick orientation to prevent confusion: Vayon AI is a governed control layer for organizational AI, not another model and not just a chat.
Vayon AI is
- An Enterprise AI Gateway
- An organizational AI control plane
- A central policy and routing layer
- One governed integration surface
- A control layer for internal and approved cloud models
- A reviewable decision and usage layer
Vayon AI is not
- Another AI model provider
- Only an enterprise chat
- A replacement for every business application
- A system that automatically selects a model without governance
- A monitoring tool that acts only after model execution
- A cloud service required for customer runtime
The governed request lifecycle
Identify, classify, enforce, route and audit. Enforcement — identity, entitlements, domain access and context egress — runs before any model executes.
Identity and client context
Requests are attributed to a user, application, integration client and use case.
Sensitivity and policy
Content is classified and evaluated against policy before routing or execution.
Authorization and context-egress controls
Domain authorization and context-egress gates apply before retrieval and before external execution.
Hybrid Routing and Best Eligible Fit
Vayon AI does not select a model by raw power. It first establishes which destinations are eligible for the request — identity and authorization, policy, sensitivity and the trust boundary decide that. Inside the allowed set, Hybrid Routing can consider task fit, verified capability, availability, observed reliability and cost to select the Best Eligible Fit, with a governed fallback drawn from that same eligible set. A caller model preference is a hint to Hybrid Routing, never an override of policy.
- Capabilities are measured where they can be proven — a capability the product has refuted is never restored by declaring it.
- Repeated failures can change candidate priority without silently widening policy.
- Cost influences selection only after governance has established what is eligible; price never opens a route that policy, sensitivity, trust or capability would deny.
Governed failover within the eligible set
If a selected model is unavailable, Vayon AI fails over to a governed fallback within the eligible set — governed, not a random round-robin.
- A primary eligible candidate is selected
- The candidate becomes unavailable
- Vayon AI does not bypass policy
- Only the remaining eligible candidates are considered
- The Best Eligible Fit is recalculated
- An eligible fallback is selected
- The fallback reason is recorded safely
Availability does not override policy.
A concrete governed routing decision
See a request classified and routed by policy, with an explainable reason.
Configured vs verified capability
Vayon AI can preview which registered models are eligible by capability. Configured capability is not verified capability — verification requires current validation evidence. Where the serving server describes a model, the answer is taken from the server rather than from the model's name: a declared context ceiling is narrowed to what the server reports and never widened, and vision support is recorded as a three-state fact — supported, not supported, or not yet known. Recording that a model accepts images is not the same as transporting them; governed image execution is not part of the gateway today, and a non-text request is refused rather than passed through.
Model fleet: internal and approved cloud models
Manage internal and approved external models behind one governed gateway — including GCP Vertex AI, AWS Bedrock and Azure OpenAI — so changing destination is an administrative decision rather than an application change.
AI FinOps: cost visibility, not a bill
See estimated AI spend across the organization over selectable time ranges, attributed to model, provider, connected system and consumer — and to task where available. Showback, forecast and efficiency views turn usage into an operating picture, and the product is explicit about which numbers are measured and which are estimated.
- Estimated operational cost, month-to-date and over selectable ranges — not provider billing actuals.
- Attribution by model, provider, connected system and consumer; task attribution where available.
- One versioned AI service cost catalog with effective dates, an optional validity end and price history — and a usage event keeps the price that applied when it was recorded, so a later price change never rewrites history.
- Free and Unpriced are different states, and token and cost provenance distinguish measured evidence from an estimate.
- Price lists, quotes and invoices import from PDF, DOCX, XLSX or CSV, with every proposed line confirmed by a person before it enters the catalog.
- Connected-system spending caps, budgets, pricing-quality coverage and rule-based anomaly signals on unusual usage.
- Budgets are advisory by default; where budget enforcement is explicitly enabled, an over-budget request can be denied before a model runs.
- Cost-aware routing can prefer the cheapest capable option inside the same trust tier — price never overrides sensitivity, policy, trust or capability.
Metering and safe audit metadata
Usage is metered and every governed action leaves reviewable metadata and reason codes — not raw content.
Extend Vayon AI around your AI workloads
Everything above is VAYON Core — the Enterprise AI Gateway and AI control plane: system integrations, Hybrid Routing, models and providers, security and policy, data and egress protection, observability and audit, governance and compliance evidence, and FinOps and operations. Four optional extensions add capabilities around the Core platform. Each is licensed once per customer organization and applies across all licensed VAYON servers — never per server and never per user.
- Chat & Knowledge — governed employee chat and organizational knowledge: permission-aware retrieval with citations, knowledge administration, content quality, source access controls, knowledge connectors, file Q&A and answer-quality feedback. Chat is an extension — Vayon AI itself is a control plane, not a chat product.
- Agent Platform — organizational AI agents under governance: the agent inventory, Agent Studio, workflows, human-in-the-loop approvals, resources with explicit operation grants, tools, scheduling, run audit and activity views, and the AI Organization Map. Agents built elsewhere can be governed through Vayon AI where supported.
- Developer AI Governance — AI-assisted development under policy: the Developer Portal, IDE and VS Code integration, coding-assistant governance, and secure-coding controls and profiles. The System Gateway and Integration Clients that connect applications remain part of VAYON Core.
- Endpoint AI Governance — governance extended toward endpoints: Shadow-AI discovery, browser governance, preflight decisioning, application and traffic discovery, and managed distribution of the browser extension. Discovery covers configured, managed surfaces — it does not claim to detect every possible bypass.
See the governed path on a real request
The fastest way to judge a control layer is to watch one request go through it: identified, classified, routed and recorded.
