Product

One control plane for every agent you run.

Udal gives platform, security and data teams a single place to build agents, run them safely inside their own boundary, and prove what happened afterwards.

  • Build & orchestrate
  • Deploy anywhere
  • Govern & evidence

The console

See your whole agent estate at once

Active agents, model usage across internal and external providers, spend, PII detections and guardrail alerts — in one operational view.

app.udal.io
Search agents, runs, policies

Good morning, Alex

Your AI agents are running securely

Agents

12

10 running

2 pending

Total Requests

1.2M

+24%

vs last month

Total Cost

£842

18% reduction

this month

Policy Compliance

100%

All checks passing

Active Agents

View all
  • Procurement Analystv2.4 · 312k requestsRunning
  • Document Classifierv1.9 · 486k requestsRunning
  • Citizen Assistantv3.1 · 268k requestsRunning
  • HR Policy Agentv1.2 · 94k requestsRunning

Usage by Model

Internal58%
  • Gwen31%
  • Llama27%
External42%
  • Claude25%
  • GPT17%

3 approvals pending

Review

PII Alerts

7

PII detections blocked

  • Email in Document Classifier
  • NHS number in Citizen Assistant
  • Address in Procurement Analyst

Guardrail Alerts

3

Guardrail alerts

  • Off-topic escalation in HR Policy Agent
  • Budget threshold exceeded
  • Restricted tool call denied

Capabilities

Six parts, one platform

Each layer is independently useful and designed to work together, so you are not assembling an agent stack from unrelated tools.

  • Agent Builder

    Declarative agent manifests define tools, models, data sources and scopes. Version them in Git and promote through environments like any other workload.

    • Declarative manifests
    • Tool and data binding
    • Environment promotion
  • Orchestration Runtime

    Durable execution survives restarts. Fan-out, joins, retries and long-running human approvals are all first-class parts of a run.

    • Durable runs
    • Fan-out and join
    • Human-in-the-loop steps
  • Policy Engine

    Every tool call is authorised against the calling user's entitlements at the point of execution. Empty policy denies; an unreachable engine denies.

    • Least privilege by default
    • Separation of duties
    • Fail-closed decisions
  • Model Gateway

    One routing layer for internal and external models, with an allow-list of in-boundary backends, per-team quotas and full request accounting.

    • Open and private models
    • Egress allow-list
    • Per-team quotas
  • Observability & Cost

    Run traces, token accounting, latency and spend by team, agent and model — with budget thresholds that stop work before it overruns.

    • Run-level tracing
    • Spend by team
    • Budget guardrails
  • Audit & Evidence

    A tamper-evident audit chain records identity, decisions and approvals, and produces sealed, control-mapped evidence reports on demand.

    • Immutable audit chain
    • SIEM forwarding
    • Sealed evidence reports
Highland ridgelines above dark water at blue hour

The Udal control plane

How Udal works

Udal runs inside your environment, providing a secure, governed control plane for the entire agent lifecycle, from development to deployment to ongoing operations.

See the architecture

Your People

  • Developers
  • Analysts
  • Business Teams
  • Operators
  • IT & Security
udalControl Plane
  • Agents & Workflows
  • Policy & Approvals
  • Model Registry
  • Data & Tool Connectors
  • Observability & Monitoring
  • Cost & Budget Controls
  • Audit & Compliance
  • Identity & Access

Your Environment

  • Your CloudAWS, Azure, GCP
  • On premises
  • Private cloud
  • Sovereign cloud
  • Edge locations

Deploy anywhere

AWSAzureGoogle CloudOn premisesEdge

Models

Every model, chosen by policy — not by habit

Udal runs open-weight models in your own environment for secure workloads and internal business processing. Any Hugging Face model can be published inside your boundary. Frontier models are reached only where a task genuinely needs them. One gateway, one allow-list, one bill.

In-house · open weights

Self-hosted on your GPUs, air-gap capable, no egress. Publish any Hugging Face model or use the curated open-weight defaults for secure and high-volume internal processing.

  • QWQwenGeneral reasoning, in boundary
  • LlamaBusiness processing at volume
  • MistralFast European open weights
  • DSDeepSeekLong-context analysis
  • GAGemmaLightweight classification
  • PHIPhiEdge and constrained hardware
  • Hugging FaceAny open model you choose to serve

Frontier · commercial

Available where a task warrants the strongest model, behind an explicit allow-list, per-team quotas and full request accounting.

  • OpenAIGPT models for hard reasoning
  • AnthropicClaude for long-form judgement
  • GoogleGemini for multimodal work
  • MistralHosted large models
  • AZAzure OpenAITenant-bound commercial hosting
  • BRBedrockManaged model catalogue
  • Sensitive by default

    Work touching regulated or personal data is routed to in-house open-weight models running inside your boundary. Nothing leaves the estate.

  • Policy-based routing

    The model gateway decides per request, based on data classification, project and entitlements — not on developer preference.

  • Frontier where it earns it

    Commercial frontier models are allow-listed for tasks that genuinely need them, with per-model cost accounting and egress controls.

Model names and logos are the trade marks of their respective owners and are shown to indicate supported integrations only.

Runtime

Safe by construction, not by convention

Agent code is treated as untrusted. The runtime assumes it will misbehave and constrains it accordingly.

  • Isolated execution

    Agent code never runs in the control plane. Each run gets a short-lived, hardened, kernel-sandboxed pod.

  • Contained networking

    Default-deny network policy limits pod-to-pod traffic to explicitly allowed paths — no lateral movement, no open egress.

  • Caller-bound entitlements

    An agent can never exceed the entitlements of the person or system that invoked it.

  • Signed service calls

    Short-lived, audience-bound service tokens between runner, gateway and tool server. Identity comes from verified claims.

  • Rate and budget limits

    Throughput and spend limits apply per project, per agent and per model backend.

  • Runs where you do

    Kubernetes operator for your cloud, your data centre or the edge. Air-gapped installs are a supported posture.

Lifecycle

From manifest to evidence

  1. 01

    Define

    Describe the agent, its tools, its models and the scopes it may use. Review it like code.

  2. 02

    Deploy

    The operator wires the agent onto the platform behind an explicit deployer role — gated and audited.

  3. 03

    Run

    Every run is isolated, policy-checked at each boundary, and traced end to end.

  4. 04

    Govern

    Approvals, guardrail alerts, budgets and evidence reports keep the estate accountable over time.

Northern sea cliffs and dark water at evening

A more capable, sovereign future.

Put AI agents to work in your environment, with complete control.

  • Sovereign AI
  • Smarter organisations
  • Brighter tomorrows