Solution · the control layer, end to end

The enterprise AI control layer

R2 does not compete with the models. It governs them. R2 helps regulated organisations deploy AI safely by controlling how employees, enterprise data and AI models interact, and by proving every interaction with an audit trail.

US enterprises must adopt AI, but regulated data cannot go to public models

HIPAA and BAA

PHI cannot enter a public model without a signed Business Associate Agreement. Consumer AI tiers do not sign one.

SEC · FINRA · NYDFS 500

Firms stay accountable for third-party AI. Supervision, books-and-records, access control and audit trails are required.

Federal and defense

FedRAMP, CJIS and ITAR rule out public-cloud AI. DFARS 7012 still binds 221,000+ defense suppliers to NIST 800-171 self-assessment. Workloads run in GovCloud or air-gapped.

R2 turns AI adoption from a compliance risk into a governable, auditable workflow.

Use any AI model. Data never leaves your tenant.

R2 sits between the applications your people use and the models they want to use. Everything above the line is where work happens. Everything below it is where models answer. R2 is the line.

Where your people already work

OutlookWordExcelPowerPointOneNoteTeamsGmailGoogle DocsGoogle SheetsChrome extensionR2 web appTelegram
R2 control layerEncrypted on the device, role-controlled, policy-enforced, audit-logged. This is the line.

Any model, any cloud, any environment

GPTClaudeGeminiGrokLlamaDeepSeek R1Open-weight models you host
Model governanceAI routingData residencyEncryptionPolicy enforcementAuditability

Users

Role-based access, policy-based authorization, human accountability.

Data

PII and PHI control, data residency, tenant isolation.

AI models

Public APIs, self-hosted models, private models.

Governance

Audit trail, policy engine, evidence export.

Every AI interaction is encrypted, policy-controlled and audit-ready.

R2 does not compete with the models. It governs them.

Four other things get bought for this problem. Each solves a piece of it.

Public AI subscriptions

Excellent models, and a business tier that improves the terms. The data still reaches the vendor, the deployment cannot follow you into a private or air-gapped environment, and you are tied to one lab's lineup.

Native platform controls

Strong inside one vendor's estate, and worth having. They govern that vendor's own assistant, not the eight other models your people want and not the traffic that never touches the platform.

Private AI platforms

Real privacy, usually in exchange for a fixed model set and a new application to adopt. Your team has to move to the tool rather than the tool arriving in Outlook, Gmail and the browser.

AI security gateways

Good at seeing and blocking. They sit outside the work, so what they mostly produce is a policy that says no, rather than a governed path your people would choose anyway.

R2 is the overlay: patented isolation, any model, and audit evidence, inside the tools employees already use.

Why now

Shadow AI is already here

43% of breaches now involve shadow AI, up from 20% a year earlier. 59% of workers use unapproved AI tools. There is no rolling this back.

Enforcement has started

The EU AI Act became fully applicable on 2 Aug 2026, with penalties to €35M or 7% of global turnover. US states enacted hundreds of AI laws; Colorado's ADMT rules bind from 1 Jan 2027.

Copilot forces a control plane

Microsoft added Copilot oversharing alerts and DLP controls to the M365 admin center in Oct 2026. Every agent rollout now needs permissions, logging and evidence.

The category is funded

Gartner opened its first Magic Quadrant for AI governance in Jun 2026. Zscaler's AI-security ARR passed $400M, growing over 80% year over year.

Compliant AI is no longer discretionary, and the layer that delivers it is still missing.

Where we are

337enterprise customers
220,000users
40+patented inventions

Patented technology

SDNP granted as US 9,998,434 B2 in June 2018, assignee Listat Ltd, filed across US, EP, CN, JP, CA, AU, SG, KR, IL, TW, UA, RU and AE. Last Mile Protection filed as US 2021/0014939 A1. 40+ inventions behind the platform.

The team

Founded by Evgen Verzun, 20+ years in cybersecurity and secure communications for critical infrastructure and inventor of the SDNP protocol, with Ahmad Qazi leading regulated go-to-market. 26 engineers across AI, applied cryptography, security and enterprise systems.

Company figures as of August 2026.

Bring the security review forward

See how the control layer fits your applications, models and regulatory perimeter.