Sovereign AI you can prove.
RHETRA is the sovereign AI platform for banks, government, health and defence: your teams work at full speed in the Governance Platform, while the KRONOS gateway enforces every AI call and signs each decision — verifiably.
NIST-standardised post-quantum signature on every decision (FIPS 204).
Zero-egress architecture, air-gap capable. Your data stays yours.
On your hardware, with written pass/fail criteria.
Sovereign is a proof, not a postcode.
Most of the market sells sovereignty as geography. We replace that with something you can check:
What a postcode gives you
- A location on a map
- A contract that promises restraint
- A certificate PDF from last year's audit
What a proof gives you
- The CPU itself signs which code runs — in memory the operator cannot read (AMD SEV-SNP)
- Every AI decision signed post-quantum (Dilithium5)
- You verify against AMD's public root keys. It checks out or it doesn't.
The safe harbour, operational.
The Governance Platform is where your teams actually work: an enabler, not a blocker. AI at full speed — inside a boundary that holds.
- Paper-to-Policy — your existing guidelines (PDF/Word) become enforceable rules
- Audit Center & approvals — oversight and evidence, built into daily work
- FinOps & ROI — every AI euro visible, per team and model
- Learning Hub — people who can, not just may

One gateway in front of every AI call.
KRONOS is OpenAI-compatible: your applications keep working exactly as before. But every call now passes classification, policy enforcement and routing — and leaves a signed audit record. One control loop, end to end:
Author policy
Define what AI may see and do — data classes, routing, redaction, approvals.
Enforce inline
KRONOS applies the policy to every LLM call in real time: BLOCK / SANITIZE / ALLOW.
Prove cryptographically
Every decision signed post-quantum; the runtime attested with AMD SEV-SNP.
Export evidence
Auditors get verifiable, signed records — mapped to EU AI Act, DORA, NIS2.
The rest of the sovereign stack
Three more products, one architecture — Orchestrate Sovereign Intelligence.
PII shield
Masks PII on-device before it reaches any LLM. Fail-safe, zero-egress.
Free Community download →Sovereign browser
The Shield built into a browser, plus local AI. Air-gap capable.
Free Community download →Sovereign operating system
Boots bare metal into a sovereign desktop. Hardened, memory-encrypted.
Start free. Scale to sovereign.
Try it today
OSI Shield and HERMES Browser for individuals. On-device, zero-egress.
Download →Power users
Custom rules, priority updates, extended detection.
Teams & fleets
Managed policy, fleet control, central reporting.
Government & regulated
KRONOS gateway, post-quantum signed audit, air-gap deployment.
Request a pilot →Install the free OSI Shield, paste a test credit-card number into ChatGPT — and watch it never arrive. That takes two minutes and explains RHETRA better than any brochure. Get the free downloads →
Who's behind RHETRA
"We built RHETRA as a safe harbour — where human intelligence, human creativity and AI capability work as one, because the boundary around them holds."— Antonios Karkalis & Frank Osterloh, Founders
Antonios Karkalis
Security engineer with CISSP and CISA certifications. Architect of the entire RHETRA stack: the post-quantum KRONOS gateway, the OSI Shield, the HERMES browser and the ATLAS operating system. He owns the security architecture and the cryptographic proof chain — the part of RHETRA you can verify yourself.
Frank Osterloh
Three decades of enterprise sales in IT security, serving corporations and the public sector. At RHETRA he leads go-to-market, partnerships and pilot engagements — the person across the table when your 30-day pilot gets its written pass/fail criteria.
Learn — sovereign AI, explained
In-depth guides on the questions regulated buyers ask. Written to be quoted — by people and by AI engines.
What is Sovereign AI? →
Definition, why it matters in the EU, and how to prove it (not just claim it).
EU AI Act compliance →
What the Act requires for high-risk AI, and how to produce living, signed evidence.
Stop PII leaking to LLMs →
Shadow AI, prompt security and on-device PII detection for regulated teams.
AI attestation & confidential computing →
AMD SEV-SNP, post-quantum signatures and encrypted memory, in plain terms.
Frequently asked questions
What is sovereign AI infrastructure?
Sovereign AI infrastructure means AI models and data run under an organisation's full legal and technical control — on-premise or in EU jurisdiction, with no data egress to non-sovereign providers. RHETRA delivers this as cryptographic proof: the KRONOS gateway enforces policy inline and signs every operation post-quantum (Dilithium5). Read the full guide →
How can you prove AI actually runs on-premise / sovereign?
Through hardware attestation. On AMD SEV-SNP the CPU itself signs: this exact measured code runs in encrypted memory the operator cannot read. The signature is verified against AMD's root keys. RHETRA archives the signed report — mathematical proof, not marketing.
What is a post-quantum AI gateway?
A gateway inline in front of every LLM call (OpenAI-compatible) that enforces security/compliance policy before data leaves the building. RHETRA KRONOS is post-quantum because its audit trail is signed with Dilithium5 (NIST PQC) — tamper-proof even against quantum computers.
How do you make AI EU AI Act compliant?
The EU AI Act requires logging, transparency, data governance and oversight. RHETRA lets you author policy, enforce it inline (KRONOS) and export verifiable, signed evidence — the loop author → enforce → prove → export. Compliance becomes a running cryptographic proof.
How do you stop PII leaking to LLMs?
RHETRA OSI Shield (AEGIS) scans text on-device for PII and masks/blocks fail-safe before the prompt reaches a model. Zero egress — no customer data leaves the device.
Make AI sovereign — provably.
Start with a 30-day pilot on your own hardware. Zero-egress confirmed, signed audit, pass/fail criteria in writing.