Product
One control plane for every agent you run.
Udal gives platform, security and data teams a single place to build agents, run them safely inside their own boundary, and prove what happened afterwards.
- Build & orchestrate
- Deploy anywhere
- Govern & evidence
The console
See your whole agent estate at once
Active agents, model usage across internal and external providers, spend, PII detections and guardrail alerts — in one operational view.
Good morning, Alex
Your AI agents are running securely
Agents
12
10 running
2 pending
Total Requests
1.2M
+24%
vs last month
Total Cost
£842
18% reduction
this month
Policy Compliance
100%
All checks passing
Active Agents
View all- Procurement Analystv2.4 · 312k requestsRunning
- Document Classifierv1.9 · 486k requestsRunning
- Citizen Assistantv3.1 · 268k requestsRunning
- HR Policy Agentv1.2 · 94k requestsRunning
Usage by Model
- Gwen31%
- Llama27%
- Claude25%
- GPT17%
3 approvals pending
ReviewPII Alerts
PII detections blocked
- Email in Document Classifier
- NHS number in Citizen Assistant
- Address in Procurement Analyst
Guardrail Alerts
Guardrail alerts
- Off-topic escalation in HR Policy Agent
- Budget threshold exceeded
- Restricted tool call denied
Capabilities
Six parts, one platform
Each layer is independently useful and designed to work together, so you are not assembling an agent stack from unrelated tools.
Agent Builder
Declarative agent manifests define tools, models, data sources and scopes. Version them in Git and promote through environments like any other workload.
- Declarative manifests
- Tool and data binding
- Environment promotion
Orchestration Runtime
Durable execution survives restarts. Fan-out, joins, retries and long-running human approvals are all first-class parts of a run.
- Durable runs
- Fan-out and join
- Human-in-the-loop steps
Policy Engine
Every tool call is authorised against the calling user's entitlements at the point of execution. Empty policy denies; an unreachable engine denies.
- Least privilege by default
- Separation of duties
- Fail-closed decisions
Model Gateway
One routing layer for internal and external models, with an allow-list of in-boundary backends, per-team quotas and full request accounting.
- Open and private models
- Egress allow-list
- Per-team quotas
Observability & Cost
Run traces, token accounting, latency and spend by team, agent and model — with budget thresholds that stop work before it overruns.
- Run-level tracing
- Spend by team
- Budget guardrails
Audit & Evidence
A tamper-evident audit chain records identity, decisions and approvals, and produces sealed, control-mapped evidence reports on demand.
- Immutable audit chain
- SIEM forwarding
- Sealed evidence reports

The Udal control plane
How Udal works
Udal runs inside your environment, providing a secure, governed control plane for the entire agent lifecycle, from development to deployment to ongoing operations.
See the architectureYour People
- Developers
- Analysts
- Business Teams
- Operators
- IT & Security
- Agents & Workflows
- Policy & Approvals
- Model Registry
- Data & Tool Connectors
- Observability & Monitoring
- Cost & Budget Controls
- Audit & Compliance
- Identity & Access
Your Environment
- Your CloudAWS, Azure, GCP
- On premises
- Private cloud
- Sovereign cloud
- Edge locations
Deploy anywhere
AWSAzureGoogle CloudOn premisesEdgeModels
Every model, chosen by policy — not by habit
Udal runs open-weight models in your own environment for secure workloads and internal business processing. Any Hugging Face model can be published inside your boundary. Frontier models are reached only where a task genuinely needs them. One gateway, one allow-list, one bill.
In-house · open weights
Self-hosted on your GPUs, air-gap capable, no egress. Publish any Hugging Face model or use the curated open-weight defaults for secure and high-volume internal processing.
- QWQwenGeneral reasoning, in boundary
- LlamaBusiness processing at volume
- MistralFast European open weights
- DSDeepSeekLong-context analysis
- GAGemmaLightweight classification
- PHIPhiEdge and constrained hardware
- Hugging FaceAny open model you choose to serve
Frontier · commercial
Available where a task warrants the strongest model, behind an explicit allow-list, per-team quotas and full request accounting.
- OpenAIGPT models for hard reasoning
- AnthropicClaude for long-form judgement
- GoogleGemini for multimodal work
- MistralHosted large models
- AZAzure OpenAITenant-bound commercial hosting
- BRBedrockManaged model catalogue
Sensitive by default
Work touching regulated or personal data is routed to in-house open-weight models running inside your boundary. Nothing leaves the estate.
Policy-based routing
The model gateway decides per request, based on data classification, project and entitlements — not on developer preference.
Frontier where it earns it
Commercial frontier models are allow-listed for tasks that genuinely need them, with per-model cost accounting and egress controls.
Model names and logos are the trade marks of their respective owners and are shown to indicate supported integrations only.
Runtime
Safe by construction, not by convention
Agent code is treated as untrusted. The runtime assumes it will misbehave and constrains it accordingly.
Isolated execution
Agent code never runs in the control plane. Each run gets a short-lived, hardened, kernel-sandboxed pod.
Contained networking
Default-deny network policy limits pod-to-pod traffic to explicitly allowed paths — no lateral movement, no open egress.
Caller-bound entitlements
An agent can never exceed the entitlements of the person or system that invoked it.
Signed service calls
Short-lived, audience-bound service tokens between runner, gateway and tool server. Identity comes from verified claims.
Rate and budget limits
Throughput and spend limits apply per project, per agent and per model backend.
Runs where you do
Kubernetes operator for your cloud, your data centre or the edge. Air-gapped installs are a supported posture.
Lifecycle
From manifest to evidence
- 01
Define
Describe the agent, its tools, its models and the scopes it may use. Review it like code.
- 02
Deploy
The operator wires the agent onto the platform behind an explicit deployer role — gated and audited.
- 03
Run
Every run is isolated, policy-checked at each boundary, and traced end to end.
- 04
Govern
Approvals, guardrail alerts, budgets and evidence reports keep the estate accountable over time.

A more capable, sovereign future.
Put AI agents to work in your environment, with complete control.
- Sovereign AI
- Smarter organisations
- Brighter tomorrows