About
SubPolicy was founded on a simple belief:
AI governance should be reusable infrastructure, not application code.
As AI agents gain access to tools, infrastructure and sensitive data, every request becomes a security decision. Today, those decisions are typically embedded inside individual applications, making them difficult to understand, audit and verify.
We’re building an open platform that separates governance from application logic. Developers compose reusable security classifiers with deterministic policies to define what AI agents are allowed to do, while organisations gain transparent, reproducible decisions that can be independently verified.
SubPolicy is designed to integrate with the growing ecosystem of AI coding agents and frameworks, allowing governance to move with the agent rather than being rebuilt for every application.
Our long term vision is to establish an open ecosystem where the community can develop, publish and improve reusable governance components, enabling trustworthy AI systems across every platform.