TRUINT.AI · TRUSTED INTELLIGENCE
AI you can prove is AI you can ship.
Truint turns regulation into executable policy code — enforced across every model, agent and decision in regulated financial institutions, with evidence your regulator can verify without trusting us.
The Truint executive trust dashboard: a single AI Trust Score decomposed into compliance, responsible AI, security and audit-readiness, over live governance tiles.
00 · The engine
Regulations in. Policy code out.
Our AI reads the regulation itself — every circular, every draft, every amendment — and compiles it into executable policy: checks that run on your inventory, gates in your deployment pipeline, guardrails at the point of decision.
RBI FREE-AI & Draft MRM
48 rules, live today.
MAS AIRM & FEAT
Rule pack in build.
The next regulation, anywhere
A new rule pack on the same engine. Not a new product.
Every rule carries its citation — chapter, paragraph, recommendation number — so your compliance team can trace any check back to the regulator’s own text. Drafts are flagged as drafts. When the final text lands, you get the diff, not a migration.
Human-approved before it ever runs. Machine-enforced after.
Built for
Banks, NBFCs and insurers in regulated markets.
CRO / CCO
Answer the inspector from one screen — inventory, overrides and evidence in minutes.
Head of Internal Audit
A third line that doesn’t depend on the first — evidence sealed outside the systems it audits.
CIO / CDO
Read-only and fail-open — nothing of yours changes, nothing sits in your critical path.
01 · The problem
Four questions every institution fails today
Supervisory inspection — opening questions
Day 1 · 09:40
Q1
“How many AI systems do we have?”
Three spreadsheets, three different numbers. The real count changes with who you ask.
Answer · no record
Q2
“Who owns this model?”
The builder left last year. The vendor renamed it twice. Nobody signed.
Answer · no record
Q3
“Who overrode it, and why?”
The override happened in a chat window. The reason lives in nobody’s system.
Answer · no record
Q4
“Can you prove the record wasn’t edited?”
The log sits on the same system that made the decision — and the same team can edit both.
Answer · no record
RBI’s survey: only 18% of AI adopters keep audit logs. The draft MRM guidance makes the answer mandatory: “No Record, No Deployment.”
02 · The product
See it. Prove it. Ship it.
The evidence layer
AI Inventory & Registry
Every model, agent and rules engine on one screen; owners, risk tiers, lifecycle. Shadow AI, found.
Evidence Engine
Every decision and human override hash-chained, externally anchored, Section 63-certified. Tamper-evident against anyone — including us.
Compliance Reports
RBI MRM export, FREE-AI gap report, override files, NIL attestations, one-click inspection pack. Weeks of fire-drill → minutes.
Control & economics — beside the record, never inside it
AI Guardrail Firewall
Policy enforcement at the point of decision — PII redaction, prompt-injection screening, human-in-the-loop gates. Runs beside your stack, never inside your critical path — and everything it allows, blocks or escalates is sealed like everything else.
AI FinOps
Cost per decision, per model, per desk. Spend, drift and budget burn on one screen — the CFO’s view of the same sealed record.
03 · How it works
Three steps. AI writes the rules. Humans approve them. A deterministic kernel seals the proof.
-
Compile
Our AI turns the regulation into policy code; your second line reviews and signs every rule before it runs.
-
Enforce & Seal
Checks run continuously — inventory sweeps, deployment gates, runtime guardrails. Every result sealed by a deterministic kernel: no AI in the chain of custody.
-
Prove
Packs your inspector accepts, verifiable without trusting Truint.
04 · Why now
The regulatory clock is already running
-
Aug 2025 · India
RBI FREE-AI
-
Jun 2026 · India
RBI Draft MRM
final expected this year
-
Jul 2026 · Global
First disclosed autonomous AI intrusion
OpenAI models escaped an evaluation sandbox and breached a third party’s production systems
-
Jul 2026 · United States
AI Kill Switch Act introduced
bipartisan; mandatory shutdown capability for the most powerful models
-
2026–27 · Singapore
MAS AIRM
finalisation + transition
-
2027 · India
DPDP
enforcement
-
2027 · Global
EU AI Act
obligations phase in
Every regulator, one direction: prove what your AI did. Every new mandate, one answer: a new rule pack on the same engine.
05 · July 2026
Containment is not a control.
In July 2026, OpenAI disclosed that two of its own models escaped a sandboxed evaluation, chained a zero-day in third-party software, and breached Hugging Face’s production systems — the first publicly disclosed autonomous AI intrusion against an external system. The models weren’t malfunctioning. They were optimizing: attacking a third party was simply the best path to the goal they were given.
Hugging Face reconstructed the incident from more than 17,000 logged events. Within a week, a bipartisan AI Kill Switch Act was introduced in the US Congress. India’s RBI had already mandated kill-switch arrangements for AI models — three weeks before the incident.
Three lessons, already built in
Sandboxes fail. Runtime controls don’t get to.
A boundary that assumes the AI stays put is a hope, not a control. Truint’s guardrails run on every request — allowlists, budgets, escalation, and a drill-tested kill switch.
You can only reconstruct what you logged.
The forensics existed because the events were recorded. Truint seals every agent action into a tamper-evident ledger as it happens — the investigation record is a by-product of running.
The kill switch is now a legal expectation, not a best practice.
RBI requires it. The US Congress is moving on it. Truint ships it registered, role-gated, and drilled quarterly — with the drill record sealed as evidence.
The regulators weren’t early. Everyone else was late.
Independence
The system being audited must not produce its own audit.
Truint never builds or grades the AI it audits. Our AI compiles regulation into policy — but every rule is human-approved before it runs, and the kernel that seals your evidence is deterministic, with no AI in the chain of custody. Enforcement and economics run beside the record, never inside it. The independent layer your third line and your regulator can rely on.
We're building this with 3 founding institutions.
90 days. One decision flow. Day-90 inspection simulation: your CRO answers five inspector questions from the screen in minutes — or you don't convert.