One stack for the intelligent control of every agentic app, model and tool you run.

The Clinaro Enterprise Harness runs beside your agent runtimes, not inside them. Every proposal an agent makes - a prompt, a tool call, a payment - is routed through a typed governance pipeline, resolved in milliseconds, and written to a tamper-evident record before anything executes.

CLINARO STACK BLUEPRINTSELF-HOSTEDINTENTEVIDENCEL5ClientsANY CLIENTHTTPS · mTLS · no code changesAgent runtimesClaude · CodexWorkflowsn8n · DifyCustom appsSDK · RESTtyped requestL4GatewayINTENT NORMALISEDOpenAI-compatible API · MCPModel calls/v1/chatTool callstools/callMemory calls/v1/memorypolicy checkL3Governance7MS MEDIAN DECISIONNine-stage typed pipelineIdentityactor · grantsPolicyscreen · budgetAuditscope · evidenceplanned callL2CognitionMETERED RETRIEVALPlanner service · governed recallPlannerfast · deliberateMemoryfour tiersStoresvector · graphscoped executionL1InfrastructureZERO STANDING ACCESSShort-lived scoped credentialsModelshosted · localTools & dataAPIs · databasesMoneypayment railsLAPTOP · VPC · AIR-GAPPEDTAMPER-EVIDENT AUDIT CHAIN
Pipeline

One pipeline.
Every request.

Every action an agent proposes - including a prompt bound for a model - crosses the same governed seam before it becomes execution.

A prompt is screened, redacted and metered before it leaves the tenant. A tool call is authorised, budgeted and approved before it fires. Nothing bypasses the substrate.

Agent
Clinaro Enterprise Harness
Executor
Intent
Typed proposal
01 · Identity
Who is asking, on whose behalf.
02 · Authorize
Least-privilege policy per agent.
03 · Screen
Prompt injection and content filters, default-deny.
04 · Budget
Hard caps on cost, tokens and rate.
05 · Approval
Human-in-the-loop where policy requires.
06 · Redact
Sensitive data stripped before egress.
07 · Capability
Tool library allow-listed per role.
08 · Access
Scoped, short-TTL token minted just-in-time.
09 · Audit
Immutable, replayable event log.
Act
Deterministic surface
Default-deny · every action · including the model call
Cognition

Beyond
Organisational Memory

The Cognition Plane moves the reason - act - answer loop out of individual AI clients and into an owned enterprise layer.

Runtimes submit an intent. The Clinaro enterprise harness manages reasoning, orchestrates internal tools and services, and returns the answer with complete control and audit trail.

Knowledge from every action compounds into durable enterprise experience, so the intelligence belongs to the organisation, not the model.

01
Feedback
AgentruntimeTools / LLMexecuteactobservesubstrate · every hop governedcompoundsChat dataGovernanceturn n+1
Feedback

The substrate provides a deterministic, controlled feedback loop that lets an agent reason, reach for tools and spawn sub-agents across one or many channels, inside fully governed bounds. Each turn feeds the right context back to drive the next action, and every reasoning step, tool call and spawned agent carries a unique, owner-bound identity, authorized, scoped and recorded before it runs.

02
Memory
AgentruntimeSUBSTRATEChat graphknowledge · organisedGovernanceaudit · access · decisionsdatarecord
Memory

Every run compounds enterprise knowledge with the record of how it was produced, so the substrate accumulates experience, not just data. Recall is recursive: rather than load a whole history into a context window, where accuracy rots as it fills, it reads only what each question needs, grounded and governed.

03
Reflex
AgentruntimeKahnemangateLocalfast · small ctxreflexCloudslow · full ctxdeliberate
Reflex

Beyond memory and feedback, the governed substrate develops finely tuned reflexes. Like a person building expertise, it acquires both fast and slow thinking. Fast thinking is trained over time into highly deterministic paths to ensure queries can be executed instantly at minimal token and compute cost.

100%
of memory reads and writes cross the governance pipeline - screened, audited, attributable
4
memory classes per agent: working, episodic, semantic, procedural - each governed and encrypted
2
planes of record behind every memory: the interaction ledger and the tamper-evident audit chain
1
audit query replays any loop end to end - what it did, why, and what it learned
04Architecture

Engineered for scale.
Deployed your way.

Single-tenant in your cloud. Multi-tenant in your data centre. Or an evaluation instance on a developer's laptop. The same byte-identical stack runs everywhere, scaling from local evaluation to enterprise-wide deployment without changing the architecture, controls or security model.

AI agents · autonomous workersthe runtime agent is the actor
Agent apps
Claude Desktop · Cursor
Custom AI apps
your products · dashboards
Pipelines & services
headless callers
Agent fleets
autonomous multi-agent systems
Clinaro · the enterprise harnessindependent of the agent · default-deny
Identity
Authorize
Screen
Budget
Approval
Redact
Capability
Access
Audit
Every actiongoverned dispatch through narrow executors
Enterprise infrastructure · the real worldyou own it
Databases
SQL · Mongo · BQ
APIs & MCP
internal · external
Messaging
email · Telegram
Shell & CI
sandboxed exec
LLMs
cloud · local · fine-tunes
Files
read · write
Easier

One integration seam. No rewrite of agent logic.

Faster

Policy is configuration. Governed agents in hours, not quarters.

Cheaper

Local-first routing and hard budget caps on every call.

Integrations

Full control of models, tools and data
through existing applications.

You can develop any application or agent on the Clinaro Enterprise Harness. Regardless of what you build, every LLM, tool and data interaction passes through the same governed control pipeline before execution.

Prompts are screened, redacted and metered before they reach a model. Tool and data calls are authorised, budgeted and approved before they execute. Every action is logged and auditable.

Full governance of models and tools for third party clients, through simple no code integrations. Point your existing client at the Clinaro gateway: identity, policy, capability scoping, cost management and audit apply to every prompt and every tool call, with no code changes.

Claude Desktop logo
Claude Desktop
MCP + model gateway
Claude Code logo
Claude Code
MCP + model gateway
ChatGPT logo
ChatGPT
OpenAI-compatible
Codex logo
Codex
OpenAI-compatible
OpenClaw logo
OpenClaw
MCP + model gateway
Ollama logo
Ollama
Model gateway + CLI
Workflows

The governance layer
for workflow platforms.

Flowise, n8n, Dify and Langflow plug in at the protocol level: one endpoint change for model calls, MCP for tools. Builders keep their canvas; every step becomes identity-bound, policy-checked, audited and cost-attributed.

Flowise logo
Flowise
visual agent canvas
n8n logo
n8n
ops automation · 500+ connectors
Dify logo
Dify
LLM-app and RAG platform
Langflow logo
Langflow
visual flow orchestration
BYO
+ your platform
any MCP-capable runtime
prompts, branching, retries and memory stay native on the canvas: no rewrite, no new skills to learn
Gate 1 · Every model call
OpenAI or API compatible endpoint governs chat, agents and embeddings.
Gate 2 · Every tool call
MCP or API typed intents enable actor granted node palette catalogue.
Clinaro Enterprise Harness
identity → policy → screening → budget → approval → execute → audit → cost
every workflow runs as a bound, owned actor · every step attributable, priced and replayable
LLMs · cloud + local
routed, redacted, metered
Tools · data · files · messaging
least privilege, approval-gated
Audit stream · cost & compliance
one query replays any workflow
One interface, N platforms: adding a platform is configuration and certification, never new development and governance logic.
Principles

Six principles.
Together, the whole system.

More than a feature - the substrate is the backbone of your enterprise intelligence.

Principle 01

Typed intents

Every action becomes a structured, validated request: understood, authorised and audited before execution.

Principle 02

Governance pipeline

Identity, authorisation, screening, budget, approval, redact, capability, access, audit - the same nine checks on every action, default-deny.

Principle 03

Independent execution

Agents never touch infrastructure. Trusted, deterministic executors act independently of the agent.

Principle 04

Owner-to-agent identity

Every agent is owned by an accountable human. Every action traces back to responsibility.

Principle 05

One substrate, every pattern

From interactive agent apps to autonomous services and fleets: the same governance layer, unchanged.

Principle 06

Control / execution planes

The control plane defines policies, identities and permissions. The execution plane enforces them at runtime.