Platforms
Bowdlr builds the infrastructure that lets AI operate safely inside regulated environments. Each platform solves a different part of the problem. Together, they make intelligence deployable.
The sovereign AI governance gateway. Field-level access control, data sovereignty, surgical redaction, and deterministic audit trails for regulated industries. It guards questions, not just files.
↓ Available nowThe fund-administration orchestrator. Investors, funds, trades, subscriptions and redemptions, pricing, NAV, reconciliation and corporate actions — with Charger, the built-in fee, tax and charge engine. Live in production.
↓ Available nowThe governed limits monitor. Notional, count and market-value ceilings across product, counterparty, country and tenor — every limit change under four-eyes approval on a tamper-evident ledger, and the same ceiling that binds a trader binds the agent. Embedded in ai.gap’s admin plane.
↓The curated reference-data estate: forty-plus masters — entities, instruments, taxonomies, rating crosswalks, calendars, sustainability — each with provenance, cadence and licence posture, maintained by a consensus curation pipeline and served to agents as governed, entitled truth.
Some things are best left unsaid — for now.
Bowdlr ai.gap
Ai.gap sits between your enterprise and your AI agents, your agents and your data, your data and the outside world. Every query governed, every response scoped, every decision auditable. Your data never leaves your perimeter.
In plain terms
ai.gap is a checkpoint in front of your AI. Before a question reaches a model, and before an answer reaches a person, ai.gap decides — for that user, at that moment, under the rules that apply — what may be seen, what must be hidden, and writes down exactly why. Ordinary access controls guard files; ai.gap guards questions. The result is AI that can finally go live in a regulated environment: useful enough to trust in the room, governed enough to explain to a regulator.
Data sovereignty by architecture, not policy
Six things ai.gap does, each of which solves a problem that has been stopping your AI from going live.
Field-level permission control that determines what each user sees within each document, not just whether they can open it. Jurisdiction-aware, temporally bound, role-specific.
PermissionsYour data never leaves your perimeter. Ai.gap processes governance decisions locally, sending only structural metadata externally. Client information stays on-premise by architecture, not just by promise.
Data SovereigntyEvery permission decision is fully reconstructable. Who asked, what they were shown, what was redacted, which rules applied, and when. Built for the regulator who will eventually come asking.
ComplianceDetection and restriction of Material Non-Public Information based on deal timelines, blackout periods, and wall-crossing events. Time-aware, not just role-aware.
Financial ServicesEvery agent has a named human owner, a cryptographically pinned system prompt with drift detection, a registry-bound environment (a test agent cannot claim production), and promotion between environments only by passing evaluation under approval — an SDLC for agents, shaped like your model-risk framework.
Agent GovernanceBring your own models — hosted frontier or in-cluster. Stage-bound policy sets a residency ceiling and an allowed-model set per processing step; constraints can tighten but never widen, high-risk work is forced local, and prompts are masked before any external model sees them.
Model PolicyThrough Monocle, the desk’s own limits govern agent activity — beginning with AI spend itself, extending to the transactions agents attempt. Not a token budget: the same notional ceiling a human trader answers to.
MonoclePolicy ships as versioned, cryptographically signed rule packs — finance first, with public-sector, HR and legal-privilege starter packs following the same mechanism. The gateway refuses unverified packs by default.
Multi-SectorYour policy matrix and audit ledger export in open formats, verified by an automated test rather than a contractual promise. You can walk away and lose nothing — which is exactly why you won’t need to.
SovereigntyWhat happens when a governed query meets your data.
Pre-configured and extensible. Built with regulators, not around them.
Annex III high-risk classification on every governed query. Article 50 disclosure on human-review release. Fundamental-rights assessment hooks. Record-keeping by hash-chained ledger.
Article 9 special categories. Right to erasure with semantic purging. Data minimisation enforcement. Cross-border transfer controls.
MNPI detection and restriction. Best execution audit trails. Client categorisation-aware access. Market abuse surveillance integration.
Deterministic, replayable decisions with no model in the allow/deny path. Evaluation-gated promotion for agents, on the same shape as model-risk governance for quantitative models.
Senior Managers Regime accountability trails. Consumer Duty obligations. Operational resilience reporting.
Signed domain packs carry sector rules beyond finance — public sector, HR, legal privilege — and the control architecture maps onto NIST AI RMF and ISO/IEC 42001 programmes.
Where we stand, precisely
Under the EU AI Act, ai.gap is the tool a deployer uses to discharge deployer obligations — human oversight, log retention, informing affected persons, the fundamental-rights assessment. It is not a high-risk AI system provider, and we do not claim to be one: that would import duties no gateway can meet. Nor can any product be “ISO 42001 certified” — that standard certifies an organisation’s management system. What ai.gap supplies is the operating evidence yours will need at audit.
We maintain a control mapping across all three frameworks, verified against source code rather than documentation, in which every partial control, every default-off switch and every absent artifact is named. Your second line will ask for the gaps; we would rather hand them over than have them found.
Bowdlr Monocle
A governed limits monitor for the business itself: what may be done, how much of it, and by whom — human or agent. Monocle consumes risk measures; it does not invent them. Deliberately narrow, deliberately auditable.
In plain terms
Every desk lives under limits — so much exposure to this counterparty, so much notional in that currency. Monocle holds those limits under maker-checker control on a write-once ledger, watches utilisation against them, and answers one question for anything that wants to act: allowed, warn, or no. Because it speaks the same governed language as ai.gap, an AI agent’s spending and transactions are held to the same ceilings as the humans they act for — which is the sentence your risk committee has been waiting to hear.
Four-eyes lifecycle on every limit; verify-on-read snapshots; breach workflow with waivers; headroom and utilisation on demand.
Author, submit, approve — separate roles, enforced. Limits by notional, count or market value; absolute or relative thresholds; warning bands before hard ceilings; netting-set-aware aggregation.
Four-EyesPre-trade and per-action evaluation with headroom queries; a governor that vetoes downstream can reverse the accrual, so the book never drifts from reality.
EvaluationAcknowledge, resolve, or request a waiver — each step attributed and ledgered. Escalation is a state, not an email.
WorkflowDelegated-identity tokens attribute every agent-driven check to both the acting agent and the governing gateway. AI spend and agent transactions meet the desk’s own ceilings through ai.gap.
AgenticBowdlr Convex()
Convex() runs the operational spine of a fund administrator — from investor onboarding to NAV strike — on the same governed Bowdlr substrate as ai.gap. Live in production with its first administrator client.
The full administration lifecycle, with the arithmetic handled by Charger, its built-in fee, tax and charge engine.
Investors, funds, share classes and securities, with versioned records and a clean onboarding path. One source of truth for the entities everything else references.
ReferenceTrades, subscriptions and redemptions, cash, lots and holdings — movement tracked end to end against a business calendar.
OperationsMulti-source pricing with overrides, FX rates with automatic inversion, a full day-count library, and a NAV strike-and-publication state machine from indicative to audited.
ValuationReconciliation, corporate-action processing and migration cutover, with a confidence-routed operator review queue for the exceptions that need a human.
ControlThe built-in calculation engine: management and performance fees, cascading tax, and per-charge overrides — compiled, deterministic and reproducible.
ChargerEvery NAV publication and material decision writes an immutable audit row on Bowdlr’s append-only, hash-chained ledger — the same trust root as ai.gap.
ComplianceWe’d rather show you than tell you. A thirty-minute walkthrough with your own use case.
Request a demo