A data movement, software change, cyber response or machine instruction.
Allow · Deny · Modify · Step Up · Stop the Line
Only the permitted, modified or escalated outcome can proceed.
Existing AI proposes a consequential action.
PF SystemsOperational authority for agentic AIStart with one workflow Operational authority for agentic AI
PF Systems puts an independent authority boundary between AI and consequential action—checking what may proceed and preserving linked evidence of what was decided and done.
UK sovereign · model-agnostic · designed to work with existing systemsA data movement, software change, cyber response or machine instruction.
Allow · Deny · Modify · Step Up · Stop the Line
Only the permitted, modified or escalated outcome can proceed.
Existing AI proposes a consequential action.
PF Systems puts hard rules and approval checks in front of each consequential action proposed by any AI—or multiple AIs—that an organisation chooses to use. This keeps the organisation in control: PF Kernel can Allow, Deny, Modify, Step Up to a human (HITL), another AI (AITL) or a defined sequence, or Stop the Line before an action takes effect. PF Core then preserves linked, tamper-evident evidence of what was proposed, which authority was applied, the decision returned and the effective action recorded, so the governed evaluation can be traced, checked and deterministically replayed. This does not make the underlying probabilistic AI deterministic.
PF Systems can sit around existing AI models, agent frameworks, memory systems, identity services and operational software.
One governed cyber action
A synthetic incident-response agent is authorised to quarantine one endpoint. Before execution, it substitutes a critical finance server. The earlier authority no longer matches.
Quarantine DEV-481
Proposed cyber response
PF Kernel decides
No action proceeds before a decision.
Allow · Deny · Modify · Step Up · StopAn AI agent asks to quarantine endpoint DEV-481.
Illustrative synthetic scenario. It does not represent a customer deployment, certification, guaranteed security or production readiness.
The PF OS triad
PF OS contains only PF Memory, PF Core and PF Kernel. They can work independently or together without turning knowledge into authority or evidence into a decision-maker.
Manages relevant context, origin, permission and lifecycle. It can wrap an existing memory system; it does not decide or execute.
Explore PF Memory ↗02 · PF Core™ProvesPreserves the request, context, authority and recorded effective action needed to trace and check a governed evaluation. It does not decide.
Explore PF Core ↗03 · PF Kernel™DecidesReturns Allow, Deny, Modify, Step Up or Stop the Line before the proposed action takes effect.
Explore PF Kernel ↗Where PF Systems begins
PF Systems works alongside IAM, model safeguards and existing security controls. Its role is to apply organisational authority when a proposed action could create a real consequence.
Choose your level of detail
Connects the existing estate.
Proof Harness™Qualifies against available evidence.
PF Trace™Displays received decision evidence.
These vendor-sponsored surveys indicate a direction of travel; they do not represent every organisation or prove PF Systems performance.
A controlled first step
A shadow pilot runs beside existing work. PF Systems evaluates what the AI would be allowed to do, but does not take the live action.
Governed workflow briefing
Tell us the action, its consequence and where authority currently sits. We will help shape a practical discovery or non-actuating shadow-pilot boundary.