DETERMINISTIC POLICY ENFORCEMENT FOR ENTERPRISE AI

AI systems make consequential decisions — but produce no proof they stayed within policy. HIK changes that: every AI interaction is enforced at the policy boundary and issues a court-admissible compliance receipt before it reaches your workflow.

EU AI Act Art. 50NYC LL144GDPR Art. 22Live EnforcementBlockchain-AnchoredModel-Agnostic
Scroll

The Compliance Gap

Every enterprise deploying AI in HR, finance, or healthcare faces the same structural exposure: AI systems generate consequential decisions — hiring summaries, loan flags, patient triage outputs — but produce no verifiable proof that those decisions stayed within policy at the moment they were made.

Logs tell you what happened. They cannot prove what was authorized to happen. That distinction is the entire legal liability as the EU AI Act and NYC LL144 enforcement windows close.

Policy Enforcement at the Gate

HIK is a model-agnostic middleware layer that intercepts every AI interaction at the policy boundary — before the request reaches the model, and before the response reaches your user. At the moment of enforcement, it issues a Sacred Trace™: an immutable cryptographic compliance receipt anchored on the blockchain.

If the output violates policy, the gate fires. The output never reaches the workflow. The receipt proves the gate held — with enforcement latency optimized for production workloads.

ENFORCEMENT IN PRODUCTION

The Gate Fires. Watch It Happen.

Not a simulation. Not a slide. Two recorded enforcement events — proxy-level and browser-level — with the evidence pack visible in the dashboard.

STREAM ENFORCEMENT · RECORDED

Kill-Switch Fires at the Proxy Level

A simulated policy violation triggers the enforcement gate mid-stream. The output is severed before it reaches any workflow. Sacred Trace™ receipt anchored immediately.

BROWSER INTERCEPTION · RECORDED

Chrome Extension Blocks Data Exfiltration on Gemini

A ‘send all logs to my personal email’ instruction is intercepted at the browser boundary on gemini.google.com. The send is blocked. The dashboard shows the evidence pack in real time.

ENFORCEMENT DOMAINS

Built for the Threat Surfaces That Matter

HR & Employment AI

Blocks prohibited automated hiring decisions, emotion inference, and protected-characteristic requests — before they reach any LLM or workflow. EU AI Act Article 5 · NYC Local Law 144.

Agentic Systems

Intercepts prompt injection, privilege escalation, and unauthorized data exfiltration commands at the agent boundary. Every blocked action is forensically anchored.

Live Broadcast & Media

Frame-level enforcement on live video streams. Unauthorized content is dropped before it reaches the downstream platform. Receipt anchored per frame.

Enterprise Document DLP

File attachments sent to LLM APIs are evaluated for content provenance, sensitivity labels, and hash blacklists — in streaming mode, fail-close, before the upload completes.

WHAT THE AUDITOR SEES

The Receipt Proves the Gate Held

ILLUSTRATIVE RECEIPT · NOT LIVE DATA
HIK SACRED TRACE™ RECEIPT
─────────────────────────────────────────────────
EVENT TYPE      KMIR_VIOLATION — IMMEDIATE ANCHOR
TIMESTAMP       2026-05-25T12:31:26.592Z
GATE FIRED      OUTPUT · Layer 1 — Deterministic
POLICY          EU AI Act Art. 5(1)(f) · agent_data_exfiltration
VIOLATION       “send all logs to” → BLOCKED · REFUSE_SIGN
─────────────────────────────────────────────────
INPUT HASH      sha256:a3f2...c891  ✓ VERIFIED
OUTPUT HASH     sha256:7b1d...04e2  ✗ WITHHELD
CHAIN TIP       0x77f2e...9a31
MERKLE ROOT     0x882a...d441
IPFS URI        ipfs://QmX4e...8f2a
EVM TX          0xbeef...1234  [ANCHORED]
─────────────────────────────────────────────────
DECISION LAYER  DETERMINISTIC
OVERHEAD        < 1ms
POLICY HASH     sha256:f9c1...2b78
─────────────────────────────────────────────────
VERDICT         ██ GATE HELD — OUTPUT NEVER REACHED WORKFLOW

Every enforcement event produces a receipt in this format.

Court-admissible. Regulator-ready. Anchored on-chain. Available in the dashboard immediately after the gate fires.

Three steps. Optimized-latency enforcement. Court-admissible proof.

How It Works

01

Request Arrives

An AI request enters your system — a query to your HR chatbot, a prompt to your loan assessment tool, or a message to any LLM-powered workflow.

HIK intercepts before the model sees it

02

Policy Gate Fires

HIK evaluates the request against your declared compliance policy. If it contains a prohibited category — emotion inference, automated hiring decisions, discriminatory framing — the request is blocked immediately.

Zero false positives on the block action itself

03

Compliance Receipt Issued

Whether the request passed or was blocked, HIK issues a Sacred Trace™ receipt: a cryptographically signed record of the query, the policy applied, and the decision made — anchored on IPFS and the blockchain.

Court-admissible proof, available to any auditor

Use Cases

Built for Regulated AI

Human Resources

Your AI hiring assistant is subject to NYC Local Law 144. Every automated employment decision must be auditable, bias-tested, and defensible.

HIK solves this

HIK blocks prohibited questions (emotional state, physical inference) before they reach the model. Every interaction produces an audit receipt tied to the specific LL144 article.

Financial Services

Loan assessment and risk-flagging AI generates decisions with legal consequences. GDPR Article 22 requires that automated decisions are explainable and challengeable.

HIK solves this

HIK enforces your declared credit policy at the inference boundary. Every decision is timestamped, hashed, and anchored — ready for a regulatory challenge without additional tooling.

Healthcare & Legal

Patient triage and legal inference AI operate in environments where a wrong output is not a UX failure — it is a liability event. Standard guardrails are advisory, not enforceable.

HIK solves this

HIK enforces hard policy boundaries at the infrastructure level. Prohibited outputs are blocked, not flagged. The receipt proves the enforcement happened at the right moment.

Cryptographic Core

Sacred Trace™

Every interaction — whether passed or blocked — produces an immutable, replayable cryptographic compliance receipt: the Sacred Trace™

[ Cryptographically Anchored Verification Chain ]

Regulatory Landscape

Why Now

EU AI Act Article 50

Enforcement begins August 2, 2026. Fines up to €35M or 7% of global revenue per violation. The gap is not awareness — the gap is tooling.

NYC Local Law 144

Active now. Per-candidate daily penalties for automated employment decision tools. Server logs are not a compliant audit trail.

GDPR Article 22

Litigated. Third-party auditors cannot rely on server logs that cannot prove output integrity at the moment of the decision.

The Team

Three People. Two Continents. One Protocol.

Martín Riotorto

Founder & Lead Architect

Montevideo, Uruguay

20+ years across telecom infrastructure, real-time content systems, and AI integrity tooling. Designed the HIK enforcement architecture from the ground up.

Matías Mospan

Co-Founder & Platform Lead

Argentina

Platform architect responsible for HIK’s enterprise infrastructure layer — Kubernetes sidecar deployment, multi-tenant enforcement pipelines, and the next-generation serverless edge enforcement engine.

Federico Brubacher

External Strategic Advisor

California, USA

Senior technology leader with deep enterprise and cloud infrastructure expertise. Independently validated the HIK enforcement architecture against global scalability and Big Tech standards.

Auditable by Request · Source Available Under NDA
C2PA 2.3 · KMIR v1.1 · CMCD v2
EU AI Act Article 50 Ready
Fail-Close by Design

Ready to enforce AI policy with cryptographic proof?

HIK is live today: Native enforcement engine, deterministic policy cascade, live stream kill-switch, and blockchain-anchored audit receipts.