Bart Labs · ForgeShield · Enterprise Early Access
Your teams already buy AI from several vendors — OpenAI, Anthropic, Google, Amazon and others. ForgeShield sits in front of all of them: one set of rules on what can be sent, one record that cannot be altered afterwards, and one memory that survives changing vendor. It runs on hardware you own.
See it work
Runtime capture is deployed in your environment. ForgeShield supports and helps demonstrate compliance workflows — it does not, by itself, make an organization compliant.
Why now
Between 2022 and 2024, US regulators fined financial firms over $2 billion because staff conducted business over WhatsApp and personal text. The firms were not penalised for what was said. They were penalised for being unable to produce it.
AI chat has the same shape — a channel in daily business use, sitting outside retention and supervision. Every additional vendor adds another one, each with its own account, its own logs and its own retention rules.
And it is no longer only messaging. In April 2026, New York's insurance regulator fined an insurer $2.25 million over records and governance failures — and barred insuring or deducting the penalty. The EU AI Act carries ceilings of up to 7% of worldwide turnover. What regulators consistently credit is cooperation: being able to produce the record.
One interaction, one record
What one layer buys you
Ten vendor adapters today — Anthropic, OpenAI, Azure OpenAI, AWS Bedrock, Google Gemini, Cohere, Mistral, Groq, xAI and OpenRouter — plus any other endpoint that speaks the OpenAI format, through the same generic path.
One set of rules screens what staff send, applied identically to every vendor. Sensitive data is removed before the model reads it — flagged, logged, and reversible for audit. Adding an eleventh vendor does not mean writing an eleventh set of rules.
Every exchange is written to a record that cannot be edited or deleted — the database itself refuses. Each AI answer carries a receipt naming the model that produced it, the route, and the rules that were active. An examiner can verify an export without access to the system.
The memory is built and stored locally by a model running inside ForgeShield — no API key, no network call. So changing AI vendor is a routing change. Nothing is exported, re-ingested or rebuilt, and context accumulates in your system rather than a vendor's account.
Running our own operations since March 2026
Measured on our own production instance on 27 August 2026, which also holds 844,171 records across 12 separate tenants and grows by roughly 6,000 a day. We publish the call that produced each figure rather than the figure alone.
Where it earns its place
The same evidence layer, tuned to the record each industry has to keep. ForgeShield assists these teams in demonstrating and investigating AI use — it does not, by itself, make an organization compliant.
When AI touches an underwriting call or a claims decision, someone will eventually ask why — an examiner, a policyholder's counsel, an internal reviewer. ForgeShield keeps the prompt, the redacted input, the model's output, and the policy decision as one sealed record you can reconstruct months later.
Advisors and health-adjacent teams live under a supervision mandate: show what was recommended, on what basis, and that a human stood behind it. ForgeShield records the AI's part of every recommendation so a supervisor — or a regulator — can review the reasoning, not just the outcome.
Law firms, consultancies, and accounting practices carry duties of privilege and confidentiality into every AI-assisted deliverable. ForgeShield keeps the provenance of each AI-touched work product — what was asked, what was seen, what was produced — so an engagement can be defended, not just delivered.
Regulatory references describe the workflows ForgeShield supports. ForgeShield helps teams demonstrate and investigate AI use; it does not certify or guarantee compliance with any rule.
For the person who will take it apart
Most vendors make you find the limits yourself, three months into an evaluation. We keep a written technical sheet that says where ours are — and we will hand it to you before you ask twice.
Each figure we publish is listed next to the exact request that produced it, measured against a running instance on a stated date. Check them yourself.
Where it sits in your traffic, how the audit chain is built and what it costs to verify one record, and why changing AI vendor doesn't touch your stored context.
A plain list of the product's current boundaries — what holds today, where the edge is, and the path past each one. Written by us, before you get there.
Goes to a person, not a drip campaign. If you would rather just ask the awkward question first, that works too — hello@bartlabs.ai.
Already evaluating?
A walkthrough tailored to your role — compliance, security, or leadership. One conversation, no procurement gauntlet.