
Dylan Banks
Co-Founder · Strategy & Systems
- Board-level AI strategy across growth-stage, mid-market and enterprise businesses
- Cross-sector: infrastructure, commercial real estate, engineering, biotech, deep tech, consultancy
For the Head of AI · status as at 29 September 2026
Kovac is software that checks requests to your data against your policy before they reach it: requests from people and from pipelines built on it. It checks three of the seven data paths today, and all seven by October 2026. It is in beta.
This page is for whoever owns the AI-use policy, the AI register and the board's question: what can our AI reach, and what stopped it?
From written policy to enforced refusals
The free Scoping Review is the first step: one working session with both founders, no data, nothing installed, and a written pack within 48 hours of the session. If you want it in writing before a pilot, the policy dry run is the paid second step. For each rule in your policy, it gives one of three answers:
Enforced today
On the data paths Kovac checks: three of seven today.
By a date
Only from a dated roadmap commitment, with its month. All seven data paths checked against your policy by October 2026.
Not at all
Said plainly, including rules neither Kovac nor, from what you tell us, anything you run today can enforce.
The policy dry run · £1,500 fixed, not credited
Send us your AI-use policy (or tell us you don't have one) and the AI and confidentiality clauses from up to five client contracts. Redacted extracts only, with no names, signatures or contact details; send nothing your client contracts forbid you to share. After a 90-minute working session with a founder, within two weeks, you get:
£1,500 fixed, not credited. A product in its own right, not a deposit on a pilot.
It starts once a data processing agreement is in place (no date yet), under a confidentiality agreement Koralis AI Limited signs at the same time. Send us nothing before then. It is not legal advice. Professional indemnity insurance: not held today.
On Microsoft 365? Ask for it as a Microsoft 365 (M365) gap check: the same session and price, working from your Microsoft 365 settings, not content. What the dry run and M365 gap check cover →
For the board
Two of our buyer's guide's questions are the board's question put to a vendor. Our answers, as the guide gives them.
Yes, on the paths Kovac checks. An object, action or deploy request that policy refuses is denied, and the refusal is recorded. File reads, previews, code run directly (/execute) and connection reads are not checked today, so on those paths there is no denial to show. Ask to see the denial on the path you care about.
When: All seven data paths checked against your policy by October 2026.
The record is searchable, but any signed-in user can add an entry in anyone's name, and entries are not signed or linked together when written. By question 4's own test – an audit trail that can be quietly edited is a log – ours is a log today.
When: Only Kovac itself can write to the record by October 2026; every entry signed as it is written, permitted requests as well as refusals, by December 2026.
| Area | Today | By when |
|---|---|---|
| Data paths checked against policy | Today:3 of 7 | By when:As the denial answer above. |
| Refusal record | Today:Refusals only, searchableA log any signed-in user can add to. Permitted requests are not recorded yet. | By when:As the audit-log answer above. |
| Failure behaviour | Today:3 failure cases let a request through | By when:Every path blocks a request when the policy check cannot run, by October 2026. |
What you can take to the board today: the refusals on three of seven data paths, in a searchable record. What you can't yet: a record of what was permitted, or a record only Kovac itself can write.
What Kovac does and doesn't touch
On your AI register, Kovac is one entry, not the register: it governs requests to data loaded into it.
Bring your Microsoft 365 or Google Workspace questions to a free Scoping Review →
Your regulatory frame
You may answer to the EU AI Act, where your organisation is in scope; to ISO/IEC 42001, if you run an AI management system against it; and to the ICO, and a sector regulator such as the FCA or the SRA. We name them as context only. Kovac is designed to produce one part of the evidence: a record of which requests to your data were refused, and which clearance was missing, on the paths it checks. Today that record is a log that any signed-in user can add to; every entry signed as it is written from December 2026.
We give no dates for these frameworks here. When an obligation applies to you is a question for your own counsel, not for a vendor's website.
What we hold, and when each gap closes →Three steps; the second is optional
Until December 2026 we run one pilot at a time. A pilot on personal data waits for a data processing agreement; it has no date yet.
Who you'll talk to

Co-Founder · Strategy & Systems

Co-Founder · AI & Architecture
Book a free Scoping ReviewOne session, with both of us.
The free Scoping Review, with both founders: which data path the rule sits on, whether that path is checked yet, and a written pack within 48 hours. No data, nothing installed.