# Difinity > Difinity.ai is the governed agent platform for regulated industries. Enterprises build agents, or connect the ones they already have, and give each a named identity and a bounded job. An agent holds no credentials and cannot reach a system itself: every action it proposes goes to the tool gateway, which decides, holds the credential and acts. Every run leaves one accountable record. ## The platform Difinity has four parts. Three are things an organisation configures or calls. The fourth is where actions happen, and nobody outside the platform calls it. - [Platform overview](https://difinity.ai/platform): How the four parts work together, from configuration through runtime enforcement to evidence. - [Hub](https://difinity.ai/docs): The administrative interface for an organisation: use cases, agents and their versions, connectors, tool servers, people, roles and permissions, billing, and the review of evidence. Hub is an administrative interface, not the system that owns the state. - [Platform API](https://difinity.ai/docs): The system of record at platform.difinity.ai. It holds agents and agent versions, use cases, conversations and messages, connector and tool server registrations, approvals, the run trail, credits and metering, and identity records. It also issues the short-lived tokens an application uses to reach the runtime. - [Flow](https://difinity.ai/docs): The runtime at api.difinity.ai. It runs the guardrail pipeline, the model call, streaming and the agent loop, and holds no state of its own. - The tool gateway: every action an agent takes leaves through it. The gateway holds the credential, applies the rules the organisation set, decides, and acts. It is not reachable from the internet, and neither a customer nor an agent calls it. - [Chat and agent workspace](https://chat.difinity.ai): The production workspace is accessed through Hub sign-in. The [public sandbox](https://chat.difinity.ai/sandbox) lets visitors try three governed sample agents without login or signup; it uses synthetic data, limited turns and session-scoped controls. - [The enterprise agent problem](https://difinity.ai/problem): Why a working agent can still be unsafe to trust with production actions. - [Engagement model](https://difinity.ai/pricing): Start with one bounded agent job, its systems, authority and evidence requirements. ## How a governed run works A turn runs in a fixed order, and that order is in the code rather than in a configuration option. Where the use case configures it, personal information is detected and detected values are replaced. The message is then checked against the use case's rules, routing reads the redacted text, the model is called, and the answer is checked before it goes back. A refusal at any stage stops the turn. A refused request never reaches a provider and is not charged. An agent run puts a loop around that sequence. The agent thinks, proposes an action, the gateway decides, and the result comes back to the agent. An action that needs a person stops the run until that person answers. Credits pay for the model and tool work Difinity funds. Where an organisation's own provider keys are enabled for it, that work is priced by the provider instead and carries no credit charge. One usage record never carries both. Hosting is offered in AWS regions in Australia (Sydney), the European Union (Frankfurt) and the United States. The region for an organisation is agreed in the order form. ## Documentation - [Platform documentation](https://difinity.ai/docs): Architecture, the governed run, agents and agent versions, tools through connectors and MCP servers, per-tool policies, approvals, the chat and agent workspace, the personal information boundary, evidence, metering and credits, and planning a first deployment. - [API reference](https://difinity.ai/docs/api): Creating an application, issuing and exchanging a token, calling api.difinity.ai, chat and streaming, agent runs and resume, run evidence, the provider-compatible endpoints, errors and rate limits. ## Evaluation and comparison - [AI agent governance platform guide](https://difinity.ai/ai-governance-platforms): What enterprise buyers should evaluate across identity, permissions, runtime control, the credential boundary, data protection and run evidence. - [AI agent governance platforms 2026 buyer guide](https://difinity.ai/resources/ai-agent-governance-platforms-2026): A practical evaluation framework for agent governance platforms, platform categories and a complete governed run. - [Compare platform approaches](https://difinity.ai/compare): Compare AI governance programs, compliance automation, cloud agent platforms and governed agent execution. - [Difinity vs Credo AI](https://difinity.ai/compare/credo-ai) - [Difinity vs Holistic AI](https://difinity.ai/compare/holistic-ai) - [Difinity vs OneTrust](https://difinity.ai/compare/onetrust) - [Difinity vs Vanta](https://difinity.ai/compare/vanta) ## Compliance evidence - [EU AI Act evidence](https://difinity.ai/eu-ai-act): How governed-run records can support wider EU AI Act governance and review processes. - [ISO/IEC 42001 evidence](https://difinity.ai/iso-42001): How operational agent evidence can support an organisation's wider AI management system. Difinity contributes operational evidence. It does not determine that an organisation or an AI system is compliant, and it does not provide ISO/IEC 42001 certification. Enforcement and evidence coverage depend on the workload, the configured controls and the governed integration path. ## Resources - [Blog](https://difinity.ai/blog): Research and practical guidance on governed AI agents and enterprise AI governance. - [Resource library](https://difinity.ai/resources): The published guides, answers and explainers. - [AI agents in production governance checklist](https://difinity.ai/blog/ai-agents-in-production) - [AI governance vs agent governance](https://difinity.ai/blog/ai-governance-platform) - [AI agent identity and ownership](https://difinity.ai/guides/ai-agent-identity-and-ownership): Give each agent a distinct identity, bounded job and accountable owner. - [AI agent permissions and access control](https://difinity.ai/guides/ai-agent-permissions-access-control): Scope systems, records, tools, actions, thresholds and delegated access. - [Runtime policy enforcement](https://difinity.ai/guides/runtime-policy-enforcement-ai-agents): Evaluate consequential actions before a target system changes. - [AI agent audit trails](https://difinity.ai/guides/ai-agent-audit-trail): Build one evidence chain across identity, policy, attempts, actions and outcomes. - [AI agent credentials and network egress controls](https://difinity.ai/guides/ai-agent-credentials-egress-controls): Why an agent holds no standing credential, how the tool gateway holds it and decides, and how egress policy bounds what a run can reach. - [PII redaction for AI agents](https://difinity.ai/guides/pii-redaction-ai-agents): Protect sensitive fields across model, tool and evidence boundaries. - [Human approval for AI agents](https://difinity.ai/guides/human-approval-ai-agents): Pre-approve bounded work and route exceptions to accountable review. - [MCP governance for AI agents](https://difinity.ai/guides/mcp-governance-ai-agents): Govern servers, tools, arguments, credentials and delegated action chains. ## Company - [About Difinity](https://difinity.ai/about) - [Team](https://difinity.ai/team) - [Privacy policy](https://difinity.ai/privacy) - [Terms of service](https://difinity.ai/terms) - [Cookie policy](https://difinity.ai/cookie-policy) - [Data processing agreement](https://difinity.ai/dpa) - [Sub-processors](https://difinity.ai/sub-processors) Difinity Pty Ltd (ABN 82 686 692 759), Sydney, Australia.