AI SECURITY · CASE STUDY
2024–26

Daxa — Zero-Trust AI Governance

TwinGuard architecture enforcing context-aware access control on enterprise data before it reaches an LLM.

Summary

Daxa is an AI security engagement running 2024–26. TwinGuard architecture enforcing context-aware access control on enterprise data before it reaches an LLM. Recognised in the 2025 Gartner Market Guide for AI TRiSM.

Facts

Client
Daxa
Sector
Ai Security
Dates
2024–26
Key result
Pre-retrieval policy on every query
Site
daxa.ai
Engagement
Discovery sprint → build alongside → hand-off

The problem

Enterprise RAG pipelines pull from sources that have existing identity-based access controls — but the LLM doesn't honour them. Daxa enforces those policies pre-retrieval.

The architecture

SafeConnectors generate a live data bill-of-materials. SafeRetriever wraps the retrieval call and applies identity-aware filtering before chunks reach the model.

  1. 01SafeConnectorsgenerate a live data bill-of-materials across the enterprise sources feeding retrieval.
  2. 02SafeRetrieverwraps the retrieval call and applies identity-aware filtering before any chunk reaches the model.
  3. 03Policy planethe access controls already on the source systems, enforced pre-retrieval rather than restated in a prompt.
  4. 04Auditevery query carries the policy decision that shaped its context window.
Daxa architecture, top to bottom — safeconnectors, saferetriever, policy plane, audit.

The results

Recognised in the 2025 Gartner Market Guide for AI TRiSM.

Enforcement point
Pre-retrievalPolicy applied before chunks reach the model, not after generation
RAG hallucination
− 68 %Baseline to live, measured on the engagement's eval suite
Gartner Market Guide for AI TRiSM
2025Recognised in the published guide

The source systems already knew who was allowed to see what. The work was making retrieval honour that, one hop earlier than everyone else was trying to.

Binary AI Labs · Engagement lead, Daxa

Written by Binary AI Labs · Reviewed