MASTER ATC Flight Recorder
Tamper-evident custody envelopes for prompts, tools, files, approvals, outputs, and hash-chain verification.

Griff.run product suite
The near-term offer is practical: record what agents do, approve risky actions, govern model traffic, protect tool access, and export proof. Each module can run as a standalone pilot or as part of MASTER ATC.
Suite map
The language below is intentionally concrete. A buyer should be able to pick a pilot, inspect the proof surface, and understand the operating guardrails before a call.
Custody core
Tamper-evident custody envelopes for prompts, tools, files, approvals, outputs, and hash-chain verification.
Risk-tiered approval queues for Tier 4-5 operations before agents touch production, money, secrets, or regulated data.
R2-backed long-term evidence, D1 metadata, and query-ready exports for audits, demos, and procurement review.
Gateway and policy
Remote tool access with scoped identity, policy checks, rate limits, and append-only evidence for each tool call.
Multi-provider model routing, spend controls, prompt-risk events, latency signals, and fallback records.
Partner-tool onboarding, connector registry, scope approval, usage ledger, and investor-ready product packaging.
Security and proof
Red-team prompt tests, blocked and allowed decisions, leakage indicators, and incident replay packets.
Source-custody retrieval, document evidence storage, response traceability, and exportable proof packets.
Modernization task replay, dependency-map proof, review packets, and human approval records for legacy migrations.
Adoption lanes
FedRAMP-aware pilot evidence, policy mapping, source custody, and approval trails for public-sector AI workflows.
Custody envelopes for Claude agents, Claude Code, Cowork tasks, connectors, skills, plugins, and MCP execution.
Image intake, transformation, optimization, delivery, and R2 backup for visual evidence and brand assets.
Evaluator path
Run the safe demo
See policy decisions, event timelines, model routing, and proof handoff in one public flow.
Open proof chain
Inspect real audit entries, hashes, reviewer votes, and signed audit-pack export.
Read evaluator docs
Use the short path through demo, proof, security, OpenAPI, pricing, and PromptGate.
Check security posture
Review what is live, what is guarded, and which controls are roadmap only.
View OpenAPI
Inspect the public API contract without needing a sales call.
Install PromptGate
Try the free prompt preflight utility and LLM-installable GitHub repo.
Operating constraints
Raw MCP is not the public surface
GRIFF exposes governed tool access with identity, policy, rate limits, and custody records.
Tier 4-5 actions are approval-gated
Production, money, secrets, regulated data, and destructive actions need human approval lanes.
Audit packs are exportable
The live proof chain can export HMAC-signed packs that verify against canonical JSON.
Stripe is not usage truth
Checkout and invoices stay separate from the event ledger, cost ledger, and audit evidence.