TorkQ keeps company data out of someone else's model.
Check how much data you're exposing to AI
Type or paste a prompt. Nothing leaves your browser.
Govern every prompt. Prove every decision.
Your teams already use AI. TorkQ puts a control point between them and the model — so sensitive data is masked before it leaves, access is decided by policy, and every action leaves proof you can hand to an auditor.
Unified Governance
One dashboard for the whole organisation. Register your model providers once, then decide which teams reach which models. Change a policy in one place and it applies everywhere — no per-machine rollout, no shadow configurations to chase.
Runs Inside Your Infrastructure
TorkQ deploys on your own server as a single node. Your provider keys stay encrypted on your hardware and your prompts never transit a third-party service. Sensitive data does not leave your infrastructure, because there is nowhere else for it to go.
Evidence, Not Just Logs
Every governed request writes a hash-chained record. Any change to an earlier entry breaks the chain and is detectable. When an auditor asks what happened to a specific piece of data, you produce a verifiable record instead of a filtered log export.
Connects to What You Already Use
Your team gets a chat interface for everyday work and API keys for IDEs and internal tools. Point them at TorkQ instead of the provider and governance applies automatically — no browser extension, no agent on every laptop, no change to how people work.
Everything the control point does.
Sensitive Data Detection
Detects PII and confidential values in prompts before they reach a model, using pattern signatures backed by named-entity recognition.
Tokenization and Rehydration
Sensitive values are swapped for opaque tokens on the way out and restored in the reply on the way back. The model gets a usable prompt; it never gets the real values.
Per-User Model Access
Grant or revoke access to specific providers and models per user or group from the admin dashboard. Provider keys are held centrally and never touch an employee device.
Tamper-Evident Audit Trail
A hash-chained record of every governed request, visible per user in the admin dashboard, with chain continuity verifiable on demand.
Policy-Driven Control
Standard identifier types are detected automatically. Anything specific to your organisation is defined once as policy and enforced from then on.
Multi-Provider Routing
Register cloud provider APIs and your own model servers side by side, and route requests across them. TorkQ runs no inference of its own.
Chat and API Access
A chat interface for everyday use and issued API keys for IDEs, scripts, and internal tools — the same governance applies to both paths.
Flexible Deployment
Run on-premise on ordinary server hardware, or in your own private cloud. Low storage, low compute, single node — it does not need a datacenter.
Same AI prompts.
Two completely different outcomes.
A side-by-side look at what sending prompts straight to a provider actually costs you — and what changes when every request passes through a control point you own.
Raw LLM APIs
Exposed PII and Secrets
Someone Else's Infrastructure
Keys Scattered Across Devices
No Verifiable Record
Locked To One Provider
TorkQ Gateway
Masked Before It Leaves
Runs On Your Own Server
One Control Plane
Tamper-Evident Chain
Multi-Provider Routing
Get a live demo.
We'll walk through TorkQ running against your own traffic patterns — on-premise deployment, what gets masked, and what the evidence chain looks like when an auditor asks.