Operational support for Article 9 and Article 12 readiness.
Evidence for the AI systems you actually run.
Costile turns production AI traffic into audit records, risk signals, ownership, retention controls, and procurement-ready answers. The goal is simple: when someone asks how your AI behaved, you can show them.
AI usage has moved from experiment to operating line item. Costile helps organizations explain AI spend, governance, ownership, incidents, and operational evidence from a single source of truth.
Prompts and responses are not stored by default.
Calls map to keys, workflows, agents, teams, and people.
Subprocessors, retention, and review materials are documented. Request DPA
Open the section procurement, compliance, or leadership asks about.
Each dropdown keeps the page scannable while preserving the operational detail buyers need during review.
EU AI Act: risk management and record-keeping
The EU AI Act (Regulation 2024/1689) entered into force in August 2024. Its main rules apply from , with Article 6(1) high-risk systems following on 2 August 2027. Costile supports two operational evidence needs:
- Article 9 risk management: incidents include cause, impact, owner, and recommended action.
- Article 12 record-keeping: AI calls become traceable records attributed to keys, agents, teams, and workflows.
- Review evidence: administrators can use incident history and audit records in procurement or governance reviews.
The Act does not ask what organizations intend to do. It asks what systems actually did. Costile helps teams maintain a running operational record that can be reviewed after the fact and traced back to specific activity.
Because risk management is a continuous process rather than a one-time policy exercise, teams can use incident history, ownership records, and operational evidence to demonstrate ongoing monitoring over the lifecycle of a system.
Security and privacy posture
Costile is a diagnostic proxy designed around metadata minimization. The hosted product stores operational metadata needed to explain spend and governance events.
- Costile does not store prompts or model responses by default.
- Prompt capture can be enabled only by a workspace owner or admin for short-retention debugging.
- Customer provider API keys stay in the customer runtime or self-hosted server environment and are not stored in the dashboard or database.
- Costile does not use customer data to train AI models.
Operational metadata includes request attribution, budgets, alerts, dashboard activity, ownership records, and governance events needed to explain AI behavior and spend.
Prompt capture is disabled by default and intended only for short-term debugging when explicitly enabled by workspace administrators.
Provider dashboards tell you what was spent. Costile records why it happened and who owns the workflow, so the record is actionable instead of just historical.
- Requests are attributed to API keys, agents, workflows, people, and teams.
- Incidents include affected requests, incident window, cost impact, monthly risk, and recommended fix.
- Workspace administrators retain a running record for audits, leadership reviews, and procurement follow-up.
Provider invoices and usage dashboards typically show totals. Costile connects spend, incidents, and operational behavior to the workflows and owners responsible for them.
- Who owns this workflow?
- Which agent caused the spike?
- Was the behavior expected or abnormal?
- When did the issue begin?
- What action should happen next?
Incidents can include supporting evidence, attribution, root-cause indicators, and remediation recommendations so teams can investigate and respond quickly.
Retention and prompt capture controls
Request metadata is retained for 90 days by default and then deleted automatically. Prompt capture is off by default. When enabled by a workspace owner or admin, captured prompt and response bodies are retained for the configured short retention window, defaulting to 7 days.
Subprocessors and DPA readiness
Costile maintains review materials for enterprise customers, including a DPA template covering processor obligations, retention, subprocessors, data subject support, deletion, and security measures.
| Provider | Purpose |
|---|---|
| Railway | Application hosting and infrastructure |
| Cloudflare | DNS, routing, and edge security |
| Anthropic | AI model provider for proxied requests |
| Resend | Transactional email and alerts when enabled |
Enterprise customers can request the latest DPA and security review materials during procurement and vendor assessment processes.
AI cost is increasingly an operational management problem rather than solely an engineering metric. As AI adoption grows, leaders need to understand which workflows, owners, and teams are responsible for spend.
Costile connects AI usage to ownership and operational context so organizations can answer questions such as:
- Where did the spend come from?
- Who owns the workflow?
- Was the increase expected growth or abnormal behavior?
- What evidence supports the conclusion?
- What action should happen next?
Instead of only reporting the bill, Costile helps explain the workflow behind it, making spend attribution, governance, and operational review possible from the same record.
Who this helps during review
- Enterprise sellers who need something concrete for procurement instead of a policy promise.
- Teams operating high-risk AI systems in hiring, credit, customer decisioning, or other Annex III contexts.
- Leaders who need to show the board that AI usage is monitored, attributed, and controlled.
- Finance, engineering, product, security, compliance, and procurement stakeholders who need operational evidence rather than policy statements alone.