Skip to content
LAUNCH FILM — LIVEGREENLIGHT · PATENT-PENDINGRUNTIME AUTHORIZATION FOR AI AGENTSMCP CONNECTORS — IN DESIGNISO/IEC 27001 — ROADMAPSOC 2 TYPE II — ROADMAPISO/IEC 42001 — ROADMAPMAS FEAT — DESIGN-ALIGNEDDETERMINISTIC · EXPLAINABLE · TAMPER-EVIDENTAI ACTS · CRELIS DECIDESLAUNCH FILM — LIVEGREENLIGHT · PATENT-PENDINGRUNTIME AUTHORIZATION FOR AI AGENTSMCP CONNECTORS — IN DESIGNISO/IEC 27001 — ROADMAPSOC 2 TYPE II — ROADMAPISO/IEC 42001 — ROADMAPMAS FEAT — DESIGN-ALIGNEDDETERMINISTIC · EXPLAINABLE · TAMPER-EVIDENTAI ACTS · CRELIS DECIDES

The product · patent-pending

GREENLIGHT

The independent authority layer

AI shouldn't hold the keys to your enterprise. GREENLIGHT is the independent authority between an agent's intention and its execution — deterministic, explainable, and provable.

AI Acts. Crelis Decides.

A canonical action envelope is bound into a short-lived, cryptographically signed execution visa, verified by the receiving system.
Execution visaissued on every authorized action

The execution visa

Every authorized action receives an execution visa

When GREENLIGHT authorizes an action, it issues a short-lived, cryptographically signed runtime execution visa — who requested it, exactly what was authorized, the policy decision, and its place in a tamper-evident chain. The endpoint trusts the visa — not the AI.

  • Bound to one action, one resource, one identity
  • Short-lived and single-use by design
  • Carries its own audit lineage
  • Verified independently of the model that asked

On the wire the visa is an execution grant: an Ed25519-signed, single-use token bound to the exact action, tenant, policy-engine version and audit-chain state, which your systems verify with a standard JWT library or the Crelis SDK.

Before an AI agent acts, check its visa.

Why it holds

Built like a control, not a wrapper

GREENLIGHT sits beside your systems, not inside your model. Crelis authorizes; your system executes; the optional gateway proxies only when you choose it.

Model- and vendor-neutral · runtime authorization for agents built on

OpenAIAnthropicGoogle GeminiMicrosoft CopilotSalesforce AgentforceAWS BedrockCiscoGenesysMCPLangChainMistral AIHugging Facen8n

All product names, logos, and brands are property of their respective owners and are used for identification purposes only. No endorsement or partnership is implied.

One independent evaluation

Each consequential action you route through Crelis passes through one authoritative, deterministic evaluation — your policies, risk rules, approvals, regulation, and human authority — before it can execute.

Protected policy floors

Customer policies can tighten outcomes but can never weaken a protected control. Proven per decision by the precedence trace, not promised in a slide.

Tamper-evident by construction

Every decision is chained with a key held outside the database and is reproducible from its recorded context — byte-for-byte replay when raw retention is enabled. Audit becomes “re-run it”, not “trust the log”.

A ladder, not a leap

SHADOW observes. ADVISORY informs. ENFORCE governs. Three modes, set per organisation — move one business line at a time, with no flag-day integration and no mandatory proxy: the optional gateway sits in the path only when you choose it.

See it running

The GREENLIGHT console

Real product, real decisions — the operations overview, the decision studio, and the hash-chain-verified audit center.

Operations overviewdecision volume & routing
AI Decision Studioevaluate a proposed action in plain language
Audit Centerhash-chain verified decision log

Where this is going

Authority as infrastructure

The destination: agents that hold no standing power at all — every consequential action individually authorized, individually provable. We are building the layer the autonomous enterprise will stand on.

ISO/IEC 27001

On the certification roadmap

SOC 2 Type II

On the certification roadmap

ISO/IEC 42001

Design-aligned · on the roadmap

MAS FEAT

Design-aligned

Statuses denote roadmap and design alignment — not current certification. We will never claim a certification we do not hold.

Authority, handed over properlyfrom the launch film

FAQ

Questions we get asked

Straight answers on how GREENLIGHT decides, what it stores, and how it fails safe.

What is GREENLIGHT?

GREENLIGHT is the independent runtime authority for AI agent actions. Before an AI agent does something that matters — move money, change a record, contact a customer — GREENLIGHT decides whether it should happen: allow it, require human approval, escalate it, or block it. Every allowed action earns an execution visa, and every decision is recorded as proof. Crelis authorizes or routes the action; your own system executes it.

Does an AI model make the final decision?

No. The final decision is never made by an AI model. It is made by fixed, deterministic rules — so the same request always gets the same answer, and every answer can be explained. AI signals can inform the decision; they can never be the decision.

Do we have to rip out our stack to adopt it?

No. Day one is SHADOW mode: one small configuration change, nothing else touched — and you immediately see a complete, audit-ready record of each consequential action your AI agents attempt through Crelis, alongside what policy would have said. ADVISORY and ENFORCE are modes you switch on later, per organisation, at your own pace.

What if one of our systems doesn’t understand Crelis yet?

Nothing breaks. Systems that don’t know about Crelis keep working exactly as they do today, while each consequential action routed through Crelis is still checked and recorded. You bring each system under ENFORCE only when you’re ready.

Which AI models and agents does it work with?

Any agent whose consequential actions you route through Crelis — model- and vendor-neutral by design. Crelis evaluates what an agent tries to do, not how the model works inside, so agents built on different models, vendors and frameworks are authorized the same way, and switching AI vendors doesn’t change your controls. Tested so far with the agents and SDKs running in our hosted pilot environment; no vendor is certified or endorsed.

What happens if Crelis goes down?

The safe thing: consequential actions fail closed — if authority can’t be determined, they wait and are never silently allowed. Routine work is not held hostage: an organisation can run in ADVISORY mode, where nothing is blocked, and execution visas already issued can still be verified for signature and binding without calling Crelis (replay and revocation checks need Crelis online). Bluntly: our outage can pause a consequential action; it cannot approve one.

Do you store our customers’ personal data?

Crelis is designed to decide on decision metadata — what was requested, what was decided, and proof it happened — not on raw personal data. A decision needs “identity: not verified”, not the identity document, so your integration keeps personal information, account numbers and message contents out of the request. That shrinks your compliance surface rather than expanding it.

What if an execution visa is stolen?

Each execution visa is single-use, expires in seconds, and is locked to one specific action for one specific system. Stolen, it is of little use to an attacker — by design it can’t be reused, redirected, or stretched to cover another action. And a stolen password or API key alone is no longer enough to act, because the visa is also required.

Can two customers’ data or authority ever mix?

No. Every customer has its own sealed identity inside Crelis. An execution visa issued for one customer simply does not work for any other — the separation is enforced by the engine, not just a settings switch.

Have you security-tested it?

Partly, and we are precise about it: an automated adversarial (“red-team”) test suite runs in CI on every build — if a defence weakens, the build fails. No third-party penetration test has been performed yet; one is on the roadmap ahead of customer deployments.

Is the technology protected?

Crelis is patent-pending: our first application, covering the core authority runtime, was filed in Singapore, and we continue to invest in protecting the architecture as it matures.

Our AI agents already have access to our systems. How does Crelis govern them?

Two options, chosen per system. In both, Crelis decides and your own system carries out the action — Crelis never executes it. The first is the optional Crelis gateway: consequential requests are routed through it, and it forwards to your system only what policy allows, which then executes — your systems don’t change at all. The second is the check at the door: your own system verifies the Crelis execution visa before it executes — your team switches that check on once. Everyday read-only work is untouched in both.

Does our backend have to change to adopt Crelis?

Not on day one, and for many systems never. SHADOW and ADVISORY require zero changes anywhere. ENFORCE is a choice per system: either route consequential actions through the optional Crelis gateway (no backend change), or have your system verify execution visas at its own door — a small, standard step your team enables when ready.

What stops an agent from simply bypassing Crelis?

We never rely on the agent’s good behaviour — that’s the whole point. Depending on the setup, either the agent has no direct route to the sensitive system except through the gateway, or the system itself refuses consequential actions that arrive without a valid Crelis execution visa. A misbehaving or manipulated agent gets a clean refusal — and the attempt goes on the record.

Why can’t a large cloud provider just build this?

They may build something similar — inside their own ecosystem. Crelis is deliberately independent: one place that decides authority across the AI ecosystems a company uses, rather than a feature that optimises for a single vendor’s stack. That neutrality is the point, and it is structurally hard for a platform to offer.

Give your agents a green light — safely.

Start in shadow mode on non-production traffic. See every decision GREENLIGHT would have made — before you let it make one.