Your agents.
Your ground.

Udal is a self-hosted platform for building and governing AI agents inside your own environment — built for regulated finance and government.

Author agents as code. Ship them through your pipeline. Every action is screened by policy, budgeted per team, and written to a tamper-evident audit log. Your data never leaves.

UDAL_TERMINAL_V1

Technical briefing, not a sales deck. A human replies within one working day.

What's in the box

Signed images + SBOM·SLSA provenance·Hash-chained audit log·Air-gapped install·Runs on EKS / AKS / GKE / OpenShift

Video summary

The Udal promotional video shows an end-to-end governed agent request inside a customer's own Kubernetes cluster. A developer submits a declarative agent manifest; the platform's control plane validates it against policy-as-code, runs eval gates, and promotes it through GitOps. At runtime, an inbound request is screened for policy, permissions, PII, and budget before any tool call happens; a high-stakes action pauses for dual-control approval; every decision, model call, and tool use is written to a tamper-evident, hash-chained audit log and streamed to the customer's existing observability stack. Data never leaves the customer's boundary.

The mandate
“For regulated institutions, AI agents are an operational risk until they are governed on ground the organisation owns outright.”
Frequently asked

Straight answers about Udal.

What is Udal?

+

Udal is a self-hosted platform for building, running, and governing AI agents inside your own environment. It provides a declarative manifest format, a typed Python SDK, an OPA policy-as-code engine, hard per-team budgets with kill-switches, and a tamper-evident audit log. The vendor never sees customer data.

How is Udal different from Microsoft Copilot Studio and SaaS agent platforms?

+

Copilot Studio and other SaaS agent platforms are hosted services: your prompts, tool calls, and often your data traverse and sit inside the vendor's boundary. Udal is installed software that runs inside your Kubernetes cluster. Data never leaves your environment, agents inherit the invoking user's real permissions, and you get the same governance, audit, and cost controls without renting them from an outside landlord.

Does Udal run fully on-premises or air-gapped?

+

Yes. Udal ships as signed container images with an SBOM and SLSA provenance, and there is an air-gapped install bundle. Telemetry is off by default. The vendor has no runtime dependency on your environment.

What does 'governed by default' mean?

+

Every agent request passes through a central control plane before any action happens. That plane enforces policy-as-code (OPA), applies RBAC and PII redaction, requires dual-control approval for high-stakes actions, tracks token spend against per-team budgets with automatic kill-switches, and writes every decision to a tamper-evident, hash-chained audit log.

What Kubernetes distributions does Udal support?

+

Udal runs on Amazon EKS, Azure AKS, Google GKE, Red Hat OpenShift, and bare-metal Kubernetes. The same manifest and control plane runs on all of them, including air-gapped installations.

How do I get access?

+

Request access from the contact page. A human replies within one working day and books a technical briefing for your platform, security, and risk teams — or sends the security pack (signed images, SBOM, SLSA provenance, threat model, and control-framework mappings).

Deploy your first governed agent.

Technical briefing, not a sales deck. A human replies within one working day.

Request access