Sie verantworten Agenten, die Sie nicht selbst gebaut haben.You are accountable for agents you did not build.
Die wenigsten KI-Agenten im Unternehmen stammen aus dem eigenen Haus. Sie kommen von Anbietern, aus Marktplätzen, aus Open Source — und keiner davon wurde von jemandem geprüft, der Ihnen gegenüber haftet. Trotzdem laufen sie in Ihren Systemen, mit Ihren Rechten, unter Ihrem Namen. Vertrauen ist hier keine Haltung, sondern eine offene Position. AXYON macht die Herkunft irrelevant: Jeder Agent läuft durch dieselbe Kontrollschicht, bekommt pro Auftrag nur die nötigen Rechte, braucht für verändernde Handlungen eine fremde Freigabe — und wird im Zweifel verweigert.Few of the AI agents inside a company come from the company itself. They come from vendors, from marketplaces, from open source — and none of them was reviewed by anyone who is liable to you. They still run in your systems, with your permissions, under your name. Trust here is not an attitude but an open position. AXYON makes their origin irrelevant: every agent passes through the same control layer, receives only the permissions a job requires, needs an approval from someone else for any changing action — and is refused when in doubt.
Der Superheld ist kein Modell — es ist der aktive Guard drumherum.The hero is not the model — it is the active guard around it.
AXYON ist die governte Kontroll- und Nachweisschicht zwischen einer KI und den Systemen eines Unternehmens: jede KI-Handlung wird geprüft, bei Bedarf freigegeben und manipulationserkennend protokolliert — als Container-Appliance im eigenen Rechenzentrum oder als native macOS-App, mit identischer Governance.AXYON is the governed control and evidence layer between an AI and a company’s systems: every AI action is checked, approved where required and logged tamper-evidently — as a container appliance in your own data centre or as a native macOS app, with identical governance.
Die meisten „KI-Governance“-Tools sind Kameras: Sie filmen, was Ihre KI getan hat — nachdem es passiert ist. AXYON ist der aktive Guard: Er steht zwischen der KI und Ihren Systemen und greift ein, bevor Schaden entsteht — fängt Manipulation ab, hält verändernde Handlungen an, entzieht unnötige Rechte, zieht den Not-Halt, verweigert im Zweifel. AXYON schaut nicht zu. AXYON greift ein.Most “AI governance” tools are cameras: they record what your AI did — after it happened. AXYON is the active guard: it sits between the AI and your systems and intervenes before damage occurs — it catches manipulation, holds changing actions, strips unnecessary permissions, pulls the emergency stop, refuses when in doubt. AXYON does not watch. AXYON intervenes.
Ein Sachbearbeiter stellt eine Anfrage. Im Hintergrund schlägt eine KI vor, was zu tun ist — einen Vertrag ändern, eine Zahlung anstoßen, einen Datensatz schreiben. In den meisten Systemen würde genau jetzt etwas passieren, unkontrolliert. Bei AXYON läuft der Vorschlag zuerst durch die Mitte.A caseworker submits a request. In the background an AI proposes what to do — amend a contract, trigger a payment, write a record. In most systems something would happen right at this point, uncontrolled. With AXYON the proposal first passes through the centre.
Der Command Core prüft in Millisekunden: Wer fragt an — und ist er überhaupt angemeldet? Wie vertraulich sind die Daten, und darf diese Verarbeitung das Haus verlassen? Versucht jemand, die KI zu manipulieren? Verändert die Handlung etwas — und braucht sie deshalb eine menschliche Freigabe? Erst wenn jede Station grünes Licht gibt, wird gehandelt. Im Zweifel handelt AXYON nicht.The Command Core checks in milliseconds: who is asking — and are they even signed in? How confidential is the data, and may this processing leave the building? Is someone trying to manipulate the AI? Does the action change something — and does it therefore need a human approval? Only when every station gives a green light is the action carried out. In doubt, AXYON does not act.
Und jede Anordnung, jede Freigabe und jede Ausführung steht danach manipulationserkennend verkettet im Protokoll. Aus einer Blackbox-KI wird ein kontrollierter, prüfbarer Geschäftsprozess — beweisbar statt plausibel.And every instruction, every approval and every execution stands in the log afterwards — chained and tamper-evident. A black-box AI becomes a controlled, auditable business process — provable, not plausible.
KI schlägt vor, das System entscheidetAI proposes, the system decides
Die KI darf vorschlagen, erklären, ausführen — aber nie eigenständig über eine relevante Handlung entscheiden. Die Entscheidung trifft AXYON nach festen, erklärbaren Regeln. Immer gleich, immer protokolliert.The AI may propose, explain and execute — but never decide on a relevant action by itself. The decision is made by AXYON along fixed, explainable rules. Always the same, always logged.
Vier-Augen-Freigabe, verbindlichFour-eyes approval, binding
Vier Augen heißt: zwei Menschen. Wer eine verändernde Handlung beauftragt, kann sie nicht selbst freigeben — das erzwingt die Software, nicht die Dienstanweisung. Jede Freigabe gilt für genau diesen einen Auftrag und nur einmal. Ohne frische, fremde Freigabe wird verweigert.Four eyes means: two people. Whoever requests a changing action cannot approve it themselves — enforced by the software, not by a work instruction. Each approval covers exactly this one job and is valid once. Without a fresh approval from someone else, the action is refused.
Souverän im StandardSovereign by default
Lokales Modell im Haus (Ollama: Gemma, Qwen, Llama). Keine Daten verlassen das Netz. Der Cloud-Pfad ist doppelt abgesichert und standardmäßig abgeschaltet. Sensible Datenklassen bleiben strukturell lokal.Local model in-house (Ollama: Gemma, Qwen, Llama). No data leaves the network. The cloud path is doubly gated and switched off by default. Sensitive data classes remain structurally local.
Prüffähig auf KnopfdruckAuditable at the press of a button
Manipulationserkennend verketteter Audit-Trail, Not-Halt über den ganzen Cluster, Anbindung an vorhandenes SSO, Annex-IV-Doku für den EU AI Act — vorbereitet, verschlüsselt, exportierbar.Tamper-evident chained audit trail, emergency stop across the whole cluster, connection to existing SSO, Annex IV documentation for the EU AI Act — prepared, encrypted, exportable.
Zwei Menschen, eine Handlung.Two people, one action.
Vier Augen heißt schlicht: zwei Menschen. Das Prinzip kennt jedes Unternehmen aus dem Zahlungsverkehr — ab einer bestimmten Summe erfasst ein Mitarbeiter die Überweisung, ein zweiter gibt sie frei, und der Erfasser kann sein eigenes Häkchen nicht setzen. AXYON überträgt genau diese Mechanik auf KI: Sobald eine Handlung etwas verändern würde — eine E-Mail versenden, einen Datensatz schreiben, eine Zahlung anstoßen —, hält das System an und wartet auf einen zweiten Menschen. Welche Handlungen diesen Halt auslösen, legt das Unternehmen fest — die Freigabe sitzt gezielt dort, wo ein unbeaufsichtigter Fehler wirklich zählt, nicht als Pflichtklick über jedem Schritt. Der Unterschied zur Organisationsanweisung: Die Regel steht nicht im Handbuch, sondern im Code. Wer den eigenen Auftrag freizugeben versucht, erhält vom System eine Absage — unabhängig von Rolle und Rechten.Four eyes simply means: two people. Every company knows the principle from payments — above a certain amount one employee enters the transfer, a second one releases it, and the person who entered it cannot tick their own box. AXYON applies exactly this mechanism to AI: as soon as an action would change something — send an email, write a record, trigger a payment — the system halts and waits for a second person. Which actions trigger this halt is defined by the organisation — approval sits precisely where an unsupervised mistake truly matters, not as a mandatory click over every step. The difference to an organisational rule: it is not written in a manual but in code. Anyone trying to approve their own job is turned down by the system — regardless of role and permissions.
Der Ablauf in vier Schritten: Jemand stellt einen Auftrag. Die KI bereitet die Handlung vor, führt sie aber nicht aus — solange sie nur liest und vorschlägt, läuft sie frei; in dem Moment, in dem sie etwas verändern würde, stoppt AXYON. Eine zweite, berechtigte Person sieht, was genau geschehen soll, und entscheidet: freigeben oder ablehnen. Erst nach der Freigabe wird ausgeführt — und die Verantwortung ist eindeutig zugeordnet: wer beauftragt hat, wer freigegeben hat, was angestoßen wurde.The flow in four steps: someone submits a job. The AI prepares the action but does not carry it out — as long as it only reads and proposes, it runs freely; the moment it would change something, AXYON stops. A second, authorised person sees exactly what is about to happen and decides: approve or reject. Only after approval is the action carried out — and accountability is unambiguous: who requested, who approved, what was initiated.
Ein Kern, zwei AusführungenOne core, two form factors
AXYON wird in zwei Formen ausgeliefert: als Appliance im Container für den Unternehmensbetrieb und als macOS-App für den einzelnen Arbeitsplatz. Das sind nicht zwei Produkte und auch keine große und keine kleine Version — es ist derselbe Kern in zwei Ausführungen. Die Ausführung bestimmt nur, wo AXYON läuft und wie man es anspricht. Was es tut, ist in beiden Fällen identisch.AXYON ships in two forms: as an appliance in a container for enterprise operation and as a macOS app for the individual workstation. These are not two products, nor a large and a small version — it is the same core in two form factors. The form factor only determines where AXYON runs and how you address it. What it does is identical in both cases.
Was in beiden Ausführungen exakt gleich istWhat is exactly the same in both form factors
Die deterministische Weiche, die Guards gegen Prompt-Injection, das Eval-Gate beim Start, die bindende Vier-Augen-Freigabe, der Not-Halt, das verkettete und verschlüsselte Audit-Protokoll und der Annex-IV-Export. Alles davon sitzt im gemeinsamen Kern, nicht in der Ausführung. Die macOS-App ist deshalb ausdrücklich keine abgespeckte Variante — ein Auftrag, der in der Appliance eine menschliche Freigabe braucht, braucht sie auf dem Notebook genauso.The deterministic decision gate, the guards against prompt injection, the eval gate at startup, the binding four-eyes approval, the emergency stop, the chained and encrypted audit log and the Annex IV export. All of it sits in the shared core, not in the form factor. The macOS app is therefore explicitly not a stripped-down variant — a job that needs a human approval in the appliance needs it on the laptop just the same.
Appliance im Docker-ContainerAppliance in a Docker container
Für Organisationen mit eigener IT: mehrere Fachbereiche, zentrale Anmeldung, Betrieb im eigenen Rechenzentrum, in der privaten Cloud oder On-Premise.For organisations with their own IT: several business units, central sign-in, operation in your own data centre, private cloud or on-premise.
Ein einzelnes Container-Image, das vollständig innerhalb der Grenze des Kunden läuft. Die IT startet es wie jeden anderen Dienst — per Docker Compose oder in Kubernetes —, hängt es an das vorhandene Single Sign-On und bindet es in die bestehende Überwachung ein. Es gibt keine Verbindung nach außen, die dafür nötig wäre.A single container image that runs entirely inside the customer’s boundary. IT starts it like any other service — via Docker Compose or in Kubernetes — attaches it to the existing single sign-on and hooks it into existing monitoring. No outbound connection is required for any of this.
Das Image ist bewusst karg gebaut: Es enthält keine Shell und keinen Paketmanager, läuft nicht als Administrator und schreibt nicht in sein eigenes Dateisystem. Wer in den Container einbricht, findet dort schlicht keine Werkzeuge vor.The image is deliberately bare: it contains no shell and no package manager, does not run as root and does not write to its own file system. Anyone who breaks into the container simply finds no tools there.
- Aufbau: distroless, non-root (UID 10001), read-only Dateisystem, alle Linux-Capabilities entzogen, no-new-privilegesBuild: distroless, non-root (UID 10001), read-only file system, all Linux capabilities dropped, no-new-privileges
- Ansprache: HTTP-Fassade auf Port 8080 hinter fail-closed AuthentifizierungInterface: HTTP facade on port 8080 behind fail-closed authentication
- Anmeldung: OIDC gegen Entra ID oder Keycloak, mit automatischer Schlüsselrotation im laufenden BetriebSign-in: OIDC against Entra ID or Keycloak, with automatic key rotation during operation
- Betrieb:
/healthz,/readyzund/metricsfür Monitoring; mehrere Instanzen parallel, wobei Freigaben und Not-Halt über alle Knoten hinweg gemeinsam geltenOperation:/healthz,/readyzand/metricsfor monitoring; several instances in parallel, with approvals and the emergency stop shared across all nodes - Lieferumfang: Image samt Stückliste (SBOM) und Build-Herkunftsnachweis (SLSA-Provenance) über die RegistryScope of delivery: image with bill of materials (SBOM) and build provenance (SLSA) via the registry
- Fail-closed: ohne konfigurierte Anmeldung nimmt die Appliance keinen Auftrag an — sie startet nicht „halb offen“Fail-closed: without configured authentication the appliance accepts no job — it does not start “half open”
Native macOS-AppNative macOS app
Für den einzelnen Arbeitsplatz und kleine Teams: Beratung, Fachbereich, Pilotbetrieb — überall dort, wo keine Container-Infrastruktur bereitsteht.For the individual workstation and small teams: consulting, business units, pilot operation — wherever no container infrastructure is available.
Eine native Desktop-Anwendung für Apple Silicon. Der Governance-Kern läuft dabei direkt im Programm — nicht als lokaler Server, den die App anspricht. Das ist eine bewusste Entscheidung: Ein offener Netzwerk-Port auf einem Arbeitsgerät wäre zusätzliche Angriffsfläche ohne jeden Nutzen. Die App öffnet keinen.A native desktop application for Apple silicon. The governance core runs directly inside the program — not as a local server the app talks to. That is a deliberate decision: an open network port on a work device would be additional attack surface without any benefit. The app opens none.
Damit ist der souveräne Fall vollständig: Auftrag, Prüfung, Freigabe, Modell und Protokoll bleiben auf dem Gerät. Es gibt keinen Weg, auf dem Daten das Notebook verlassen, solange der Cloud-Pfad nicht ausdrücklich freigeschaltet ist.This completes the sovereign case: job, check, approval, model and log all remain on the device. There is no path by which data leaves the laptop as long as the cloud path is not explicitly enabled.
- Aufbau: Tauri-App mit dem Kern in-process — kein HTTP, kein offener PortBuild: Tauri app with the core in-process — no HTTP, no open port
- Modell: lokal auf dem Gerät über Ollama (etwa Gemma, Qwen oder Llama), per Konfiguration austauschbarModel: local on the device via Ollama (e.g. Gemma, Qwen or Llama), interchangeable by configuration
- Vertrieb: Developer-ID-Direktvertrieb, signiert und von Apple notarisiert — kein Mac App Store, Auslieferung als DMGDistribution: Developer ID direct distribution, signed and notarised by Apple — no Mac App Store, delivered as a DMG
- Prüfbar: Gatekeeper meldet auf dem Zielrechner „Notarized Developer ID“Verifiable: Gatekeeper reports “Notarized Developer ID” on the target machine
- Voraussetzung: macOS 12 oder neuerRequirement: macOS 12 or later
- Souverän: keine Serverkomponente, kein Konto, keine Registrierung nötigSovereign: no server component, no account, no registration required
| Appliance (Container)Appliance (container) | macOS-AppmacOS app | |
|---|---|---|
| LäuftRuns | im Rechenzentrum, privater Cloud oder On-Premisein the data centre, private cloud or on-premise | auf dem Gerät selbston the device itself |
| Angesprochen überAddressed via | HTTP-Fassade hinter AuthHTTP facade behind auth | direkt im Programm, ohne Netzdirectly in the program, no network |
| NutzerkreisUser base | viele, über zentrale Anmeldungmany, via central sign-in | ein Arbeitsplatz bzw. kleines Teamone workstation or small team |
| AnmeldungSign-in | vorhandenes SSO (Entra ID, Keycloak)existing SSO (Entra ID, Keycloak) | lokal, ohne zweite Benutzerverwaltunglocal, without a second user directory |
| Betrieben durchOperated by | die IT des Kundenthe customer’s IT | den Anwender selbstthe user themselves |
| Ausgeliefert alsDelivered as | Container-Image mit SBOM und Herkunftsnachweiscontainer image with SBOM and provenance | signiertes, notarisiertes DMGsigned, notarised DMG |
| AusfallsicherheitResilience | mehrere Instanzen im Verbundseveral instances in a cluster | Einzelgerätsingle device |
| Governance | identisch — gleiche Regeln, gleiche Freigabe, gleicher Not-Halt, gleiches Protokoll, gleicher Prüf-Exportidentical — same rules, same approval, same emergency stop, same log, same audit export | |
Einzigartig — in dieser Form am Markt nicht verfügbar. Beide Ausführungen laufen auf demselben geprüften Kern: gleiche Regeln, gleiche Freigabe, gleicher Not-Halt, gleiches manipulationserkennendes Protokoll, gleicher Prüf-Export. Eine native Desktop-Variante mit voller Governance gibt es sonst nirgends — belegt durch unsere Auswertung von rund 70 Lösungen (Stand 07/2026). AXYON ist lieferbereit.Unique — not available on the market in this form. Both form factors run on the same audited core: same rules, same approval, same emergency stop, same tamper-evident log, same audit export. A native desktop variant with full governance exists nowhere else — established by our review of roughly 70 solutions (as of 07/2026). AXYON is ready to ship.
Der vollständige Governance-Workflow — nachlesbarThe complete governance workflow — in writing
Wie AXYON eine KI-Agenten-Aktion von der Anlage bis zur freigegebenen, protokollierten Handlung führt — jede Station einzeln erklärt, mit drei Ablaufzeichnungen und zehn Einsatzfällen. E-Mail eingeben, Datenschutz bestätigen — das PDF lädt sofort herunter.How AXYON takes an AI-agent action from setup to an approved, logged operation — every station explained on its own, with three flow diagrams and ten use cases. Enter your email, confirm the privacy notice — the PDF downloads instantly.
Wir nennen keine Kunden.We do not name our customers.
Wer eine Kontrollschicht vor seine Produktivsysteme setzt, hat ein berechtigtes Interesse daran, dass niemand davon erfährt. Dieses Interesse schützen wir bei jedem Kunden — also auch bei Ihnen. Den Beweis, dass AXYON hält, führen wir stattdessen am System selbst: Lasttests, Chaos-Tests, SBOM und Herkunftsnachweis der Software liegen jedem Angebot bei.Any organization that places a control layer in front of its production systems has a legitimate interest in keeping that fact private. We protect that interest for every customer — including you. Instead, we prove AXYON on the system itself: load tests, chaos tests, SBOM and software provenance accompany every offer.
Einmal kaufen. Dauerhaft nutzen.Buy once. Use permanently.
Der Preis von AXYON vergleicht sich nicht mit einem Software-Abo, sondern mit der Alternative: eine eigene Kontrollschicht entwerfen, bauen, betreiben und gegenüber der Revision verantworten. AXYON ist eine Kauflizenz — kein Abonnement, keine Gebühr pro KI-Handlung, keine Cloud-Pflicht. Der Preis richtet sich nach der Reichweite, nicht nach dem Funktionsumfang: Jede Ausführung enthält die vollständige Governance.AXYON’s price does not compare to a software subscription. It compares to the alternative: designing, building, operating and defending your own control layer in front of an auditor. AXYON is a purchase license — no subscription, no fee per AI action, no cloud dependency. The price follows reach, not feature scope: every edition ships with the full governance core.
AXYON — macOS-AppAXYON — macOS app
Ein ArbeitsplatzOne workstation
Vollständige Governance — keine abgespeckte Variante.Full governance — not a reduced edition.
- Native macOS-App, Kern in-process, kein offener PortNative macOS app, core in-process, no open port
- Modell lokal über Ollama — keine Daten verlassen den RechnerModel runs locally via Ollama — no data leaves the machine
- Jede KI-Handlung geprüft, freigegeben, protokolliertEvery AI action checked, approved, logged
- Signiert und von Apple notarisiertSigned and notarized by Apple
AXYON — ApplianceAXYON — appliance
Eine ProduktivumgebungOne production environment
Unbegrenzte Nutzerzahl über zentrale Anmeldung.Unlimited users via central sign-on.
- Container-Appliance: distroless, non-root, read-onlyContainer appliance: distroless, non-root, read-only
- OIDC gegen Entra ID oder KeycloakOIDC against Entra ID or Keycloak
- SBOM und SLSA-Provenance mitgeliefertSBOM and SLSA provenance included
- Ein Tag technisches Onboarding enthaltenOne day of technical onboarding included
- LieferbereitReady to ship
Warum wir sie empfehlen: Die Haftungsfrage stellt sich nicht pro Arbeitsplatz, sondern pro Umgebung. Erst die Appliance kontrolliert jeden Agenten, der in Ihren Systemen arbeitet — unabhängig davon, wer ihn startet.Why we recommend it: Liability does not attach per workstation — it attaches per environment. Only the appliance governs every agent operating in your systems, regardless of who launches it.
Konzern & weitere UmgebungenGroup & further environments
Verbund · BetriebCluster · operations
Für mehrere Umgebungen im Verbund.For multiple environments in a cluster.
- Mehrere ProduktivumgebungenMultiple production environments
- Mehrere Instanzen im VerbundClustered instances
- BetriebsunterstützungOperations support
- KonzernlizenzenGroup-wide licensing
Alle Preise netto zzgl. USt. Aktualitäts-Garantie ab Jahr 2: rund 20 % des Kaufpreises pro Jahr, jährlich kündbar — ohne Verlängerung bleibt die vorhandene Version dauerhaft lauffähig. Der Lizenzanteil eines Control-Studio-Kaufs wird innerhalb von zwölf Monaten zu 100 % auf die AXYON-Lizenz angerechnet.All prices net of VAT. Currency guarantee from year 2: around 20 % of the purchase price per year, cancellable annually — without renewal, your existing version remains permanently operational. The license share of a Control Studio purchase is credited in full against the AXYON license within twelve months.
KI-Agenten absichern — die wichtigsten FragenSecuring AI agents — the key questions
Wie kann man KI-Agenten im Unternehmen absichern?How do you secure AI agents in an enterprise?
Ist AXYON ein KI-Modell?Is AXYON an AI model?
Bleiben unsere Daten im eigenen Haus?Does our data stay in-house?
Wie funktioniert die Vier-Augen-Freigabe bei KI-Handlungen?How does four-eyes approval work for AI actions?
Kann eine Vier-Augen-Freigabe umgangen werden?Can a four-eyes approval be bypassed?
Wie lässt sich nachweisen, was eine KI angeordnet und ausgeführt hat?How can you prove what an AI was instructed to do and carried out?
Läuft AXYON on-premise oder auf dem Mac?Does AXYON run on-premise or on the Mac?
Worin unterscheidet sich AXYON von GARION?How does AXYON differ from GARION?
Was unterscheidet AXYON von KI-Governance- und Monitoring-Tools?What sets AXYON apart from AI governance and monitoring tools?
Wie sichere ich KI-Agenten ab, die ich nicht selbst entwickelt habe?How do I secure AI agents I did not build myself?
Warum eine Kauflizenz statt eines Abonnements?Why a purchase license instead of a subscription?
Wie rechnet sich der Preis?How does the price add up?
Womit vergleiche ich AXYON preislich?What do I compare AXYON to on price?
Was passiert, wenn ich die Aktualitäts-Garantie nicht verlängere?What happens if I don’t renew the currency guarantee?
Ich habe Control Studio gekauft. Was wird angerechnet?I bought Control Studio. What is credited?
Einen Ihrer Agenten durch die Kontrollschicht schickenRun one of your agents through the control layer
Wir nehmen einen echten Agenten aus Ihrem Haus: welche seiner Handlungen etwas verändern, wo die Freigabe greifen müsste, wie der Nachweis am Ende aussieht — in unter einer Stunde.We take a real agent from your environment: which of its actions change something, where approval would have to bite, what the evidence looks like in the end — in under an hour.
© ZERYON Systems · Predrag Gasic · Marke der ZERYON-Familiea brand of the ZERYON family