Trust, Compliance & AI Operations

Evidence for the AI systems you actually run.

Costile turns production AI traffic into audit records, risk signals, ownership, retention controls, and procurement-ready answers. The goal is simple: when someone asks how your AI behaved, you can show them.

AI usage has moved from experiment to operating line item. Costile helps organizations explain AI spend, governance, ownership, incidents, and operational evidence from a single source of truth.

EU AI Act Risk and record evidence

Operational support for Article 9 and Article 12 readiness.

Security Metadata-first diagnostics

Prompts and responses are not stored by default.

Audit Attribution by owner

Calls map to keys, workflows, agents, teams, and people.

Review DPA available

Subprocessors, retention, and review materials are documented. Request DPA

Governance answers

Open the section procurement, compliance, or leadership asks about.

Each dropdown keeps the page scannable while preserving the operational detail buyers need during review.

EU AI Act: risk management and record-keeping

The EU AI Act (Regulation 2024/1689) entered into force in August 2024. Its main rules apply from 2 August 2026, with Article 6(1) high-risk systems following on 2 August 2027. Costile supports two operational evidence needs:

  • Article 9 risk management: incidents include cause, impact, owner, and recommended action.
  • Article 12 record-keeping: AI calls become traceable records attributed to keys, agents, teams, and workflows.
  • Review evidence: administrators can use incident history and audit records in procurement or governance reviews.

The Act does not ask what organizations intend to do. It asks what systems actually did. Costile helps teams maintain a running operational record that can be reviewed after the fact and traced back to specific activity.

Because risk management is a continuous process rather than a one-time policy exercise, teams can use incident history, ownership records, and operational evidence to demonstrate ongoing monitoring over the lifecycle of a system.

Security and privacy posture

Costile is a diagnostic proxy designed around metadata minimization. The hosted product stores operational metadata needed to explain spend and governance events.

  • Costile does not store prompts or model responses by default.
  • Prompt capture can be enabled only by a workspace owner or admin for short-retention debugging.
  • Customer provider API keys stay in the customer runtime or self-hosted server environment and are not stored in the dashboard or database.
  • Costile does not use customer data to train AI models.

Operational metadata includes request attribution, budgets, alerts, dashboard activity, ownership records, and governance events needed to explain AI behavior and spend.

Prompt capture is disabled by default and intended only for short-term debugging when explicitly enabled by workspace administrators.

Audit logs and owner attribution

Provider dashboards tell you what was spent. Costile records why it happened and who owns the workflow, so the record is actionable instead of just historical.

  • Requests are attributed to API keys, agents, workflows, people, and teams.
  • Incidents include affected requests, incident window, cost impact, monthly risk, and recommended fix.
  • Workspace administrators retain a running record for audits, leadership reviews, and procurement follow-up.

Provider invoices and usage dashboards typically show totals. Costile connects spend, incidents, and operational behavior to the workflows and owners responsible for them.

  • Who owns this workflow?
  • Which agent caused the spike?
  • Was the behavior expected or abnormal?
  • When did the issue begin?
  • What action should happen next?

Incidents can include supporting evidence, attribution, root-cause indicators, and remediation recommendations so teams can investigate and respond quickly.

Retention and prompt capture controls

Request metadata is retained for 90 days by default and then deleted automatically. Prompt capture is off by default. When enabled by a workspace owner or admin, captured prompt and response bodies are retained for the configured short retention window, defaulting to 7 days.

Subprocessors and DPA readiness

Costile maintains review materials for enterprise customers, including a DPA template covering processor obligations, retention, subprocessors, data subject support, deletion, and security measures.

Provider Purpose
Railway Application hosting and infrastructure
Cloudflare DNS, routing, and edge security
Anthropic AI model provider for proxied requests
Resend Transactional email and alerts when enabled

Enterprise customers can request the latest DPA and security review materials during procurement and vendor assessment processes.

AI cost operations and spend accountability

AI cost is increasingly an operational management problem rather than solely an engineering metric. As AI adoption grows, leaders need to understand which workflows, owners, and teams are responsible for spend.

Costile connects AI usage to ownership and operational context so organizations can answer questions such as:

  • Where did the spend come from?
  • Who owns the workflow?
  • Was the increase expected growth or abnormal behavior?
  • What evidence supports the conclusion?
  • What action should happen next?

Instead of only reporting the bill, Costile helps explain the workflow behind it, making spend attribution, governance, and operational review possible from the same record.

Who this helps during review
  • Enterprise sellers who need something concrete for procurement instead of a policy promise.
  • Teams operating high-risk AI systems in hiring, credit, customer decisioning, or other Annex III contexts.
  • Leaders who need to show the board that AI usage is monitored, attributed, and controlled.
  • Finance, engineering, product, security, compliance, and procurement stakeholders who need operational evidence rather than policy statements alone.
Sources & Articles

The compliance framing is grounded in the regulation itself.

Give your AI stack the paper trail it does not have yet.