Cleanroom
Ties a movement in an evaluation score to the dataset or pipeline change that caused it, with contamination checks and dataset lineage.
In developmentInterLock is a proxy between AI agents and your databases, files and APIs. It authorizes every request by role and policy, redacts sensitive fields before the agent sees them, holds risky writes for approval and audits everything. Your agents and your data stores do not change.
Two layers need controls once agents reach production. The first is identity and tool permissions, and good products already cover it. The second is the data itself: the query that runs, the rows that come back and the write that changes them. InterLock works there, on the protocols your data already speaks.
Each agent gets its own identity and key. Source roles allow or deny actions per source, and for SQL sources per table and column. SQL is parsed before it runs, and anything a role does not allow is refused.
Deny by defaultPersonal data in results is detected and masked in the response. Policies can also redact named columns, rate-limit an agent or cap the risk of its writes. Policies only ever narrow access; they never grant it.
Masked in the responseEvery write is classified by risk before it runs. Routine inserts pass. Updates, unbounded deletes and schema changes are queued for a reviewer, who approves or rejects them in the console, with an optional Slack notification.
Held until approvedAllowed or denied, each request is written to an append-only audit log with the identity, the source, the decision and what was redacted. Admin actions are audited too, and the log exports as CSV.
Append-only audit logAgents connect to InterLock instead of connecting to your data stores. It speaks the protocols they already use: the Model Context Protocol, the Postgres wire protocol and HTTP. Adoption is a connection-string change, not a code change.
Agents keep their tools and connect with an InterLock key. These sources are active by default and more can be switched on. See every connector and how far it is certified.
Infrastructure in the path of production data has to be trusted, so every capability carries a status and the evidence behind it. If something is not ready, the status page says so.
Ties a movement in an evaluation score to the dataset or pipeline change that caused it, with contamination checks and dataset lineage.
In developmentDistributed tracing for agent runs: every step, tool call and decision, so a failed run can be reconstructed and understood.
In developmentInterLock is working with a small group of design partners running agents against real production data. If that is you, we would like to talk.