AIA · Agentic Intelligence Architecture

AI agents for
regulated industries

Open-source AI agent infrastructure for regulated enterprises.

Financial services Healthcare & life sciences Government & defence Manufacturing & supply chain
The problem

Frontier AI ships your records to a vendor's cloud — someone else's servers, someone else's jurisdiction.

And the logs meant to show what an agent did are mutable operator data — not evidence an auditor can rely on.

With AIA, data stays in your perimeter — and your auditor can verify what the agents did.

Industries

Built for regulated industries

Banking & capital markets

Compliance evidence at trade speed

Pre-trade MiFID II checks and DORA evidence on demand, inside your perimeter.

Healthcare & life sciences

Analytics without PHI egress

Federated cohort analytics with zero PHI egress, 21 CFR Part 11 end to end.

Government & defence

Classified work, on your terms

Classified synthesis on air-gapped hardware, sources and methods protected.

Manufacturing & supply chain

Provenance across the supply chain

Supplier due diligence and digital product passports — LkSG, CSDDD, CSRD — with provenance that holds up in audit.

→ Workflows across these four industries

Regulations

Aligned to the frameworks
that govern your industry

DORA
Digital Operational Resilience Act · live since Jan 2025
EU · Financial services
EU AI Act
High-risk obligations · Art. 12 logging · 2 Dec 2027
EU · Cross-sector
NSM-10
Federal post-quantum migration
US · Federal
BSI TR-02102
PQC migration guidance
Germany · Cross-sector

GDPR Art. 32 · NIS2 · MiFID II · HIPAA · 21 CFR Part 11 — and more, mapped in the trust dossier.

Architecture

Four pillars

Four layers: the agent runtime, its memory, the proof of what it did, and post-quantum cryptography underneath.

Pillar 01

Multi-agent orchestration

Specialised agents across security, finance, development, and knowledge — each task routed to the best-fit agent.

Pillar 02

Knowledge graph

A Neo4j-backed graph where answers trace to the exact nodes behind them.

Pillar 03

Audit layer

Actions are signed into a tamper-evident log, designed to anchor a single proof on-chain — your auditor verifies it without the data.

Pillar 04

Post-quantum A2A

A forward-secret, post-quantum agent channel with ML-KEM-1024 — built in, not bolted onto TLS.

How AIA works

Run the agents
where your data already lives

Agents read, reason, and work inside your perimeter; all that leaves is a zero-knowledge proof.

ENTERPRISE PERIMETER · YOUR NETWORK REQUEST user · system · agent t = 0 ms ROUTE L1 · ORCHESTRATION Trust-weighted routing · specialist agents REASON L2 · KNOWLEDGE DKG · graph retrieval COORDINATE L3 · A2A PROTOCOL PQ-encrypted state-sync ATTEST L4 · PQC + ZK SP1 · Groth16 · ~260 B ZKP L1 ANCHOR Ethereum INPUT · PLAINTEXT OUTPUT · ENCRYPTED + ATTESTED PUBLIC · VERIFIABLE
Five stages inside the perimeter. One proof leaves.
The AI audit layer

One audit layer.
Three kinds of proof.

The audit trail that gets your AI agents approved. AIA writes three kinds of proof; each shows that something is true and nothing else.

Architecture
ProofWhat it provesAligned to
Action attestationAn agent did a specific action, unaltered, at a known time. Signed into a hash-chained log whose root is designed to anchor on-chain, so an auditor confirms it offline — without the data behind it.EU AI Act Art. 12 · DORA · NIS2 · HIPAA audit trail
Confidential transferValue moved between parties, amounts and counterparties private. Settled in regulated stablecoins, disclosed only to a party you choose.MiCA · regulated stablecoins · selective disclosure
Verifiable inference
Hardware-attested · zkML research
An output came from an approved model under an approved policy. Hardware attestation for self-hosted models; an attested call envelope for frontier APIs.EU AI Act high-risk obligations

Proofs are batched, so anchoring thousands of actions costs a single settlement.

Deployment

From managed cloud
to air-gapped on-premise

Run it in our EU regions, in your VPC, or fully air-gapped. Three patterns, one codebase — identical APIs and proofs across all three.

01 · Managed

We operate it

013a runs the cluster; you hold the keys.

02 · Hybrid · your VPC

Inside your cloud

Runtime, graph, and keys inside your VPC; only proofs cross the boundary.

03 · Sovereign · on-premise

Air-gapped

Full on-premise install with no outbound connectivity, for classified workloads.

Standards at every boundary — MCP, OpenTelemetry GenAI, EAS, W3C DID/VC, FIPS 203/204/205. → Interoperability

Who builds it

Built in Berlin by 013a

Deep expertise in cryptography, multi-agent systems, and enterprise security — from the EU, for the regulated world.

Made in Germany
More about 013a
Start

Two paths in one conversation

A thirty-minute call to map your workload to the right deployment, agents, and audit evidence. No deck.

Book a call Write to us