# One-Pager

**The standard for enterprise AI governance, with a deterministic engine that proves it.**

> Confidential · June 2026. All figures are illustrative placeholders unless sourced.

## The problem

Enterprises are deploying AI faster than they can govern it. Boards now carry the liability, regulators are arriving in force — the EU AI Act penalty reaches 7% of global turnover and is already in force — and compliance is the single largest barrier to adoption: Deloitte finds regulatory compliance is the #1 barrier to GenAI at 38%. Meanwhile, most of the AI a company actually uses is invisible. There is no shared, audit-defensible way to see what's running, prove it meets a standard, and keep that proof current.

## The category answer: see, prove, run

govrn.ai is one record viewed through two lenses. **govrn** is the standard — *See it and prove it* — built for the CISO and the board. **Aperture** is the engine — *Run it* — built for the CTO and the CFO. The standard sees it and proves it; the Aperture engine runs it. The two are joined by an interface that carries evidence, not a verdict — so attestation stays independent of measurement.

## What we have

- **The Aperture engine — built and tested.** Deterministic, with no model in the measurement path, so results are reproducible and audit-defensible. It uses pointers, not payloads — metadata only, enforced — to surface shadow AI with a dollar figure and attributed cost and usage. It is pre-MVP on live data: connectors are built but have not yet run against a live API. The $121k / 22%-shadow demo is the real engine on synthetic seed data — modeled, not a customer result.
- **The govrn standard — live.** A three-lens assessment (technology, security, AI), six-framework crosswalks (NIST AI RMF, ISO/IEC 42001, EU AI Act, OWASP, ATLAS, CSF 2.0), independent attestation (never self-certified), and review of the AI a company actually ships.
- **The seam — designed.** The govrn-interface is specified in markdown; code is next.

See [The Standard and the Engine](02-the-standard-and-engine.html) and the [Roadmap](06-roadmap.html).

## The play: entity-first → license → Microsoft

Stand up the company first — entity, team, raise — before any partner conversation. Then license the process, the product, and the brand. **Kelly / MCG Kelly Services is the first channel** — de-risked distribution, not the destination. **Microsoft is the horizon**, reachable through the team's senior-Microsoft relationships.

The annuity is structural: an attestation is valid only against a fresh record, so continuous measurement is required. We deliver coupled and renew decoupled. Evidence stays portable — sovereignty, not lock-in. The durable moat is independence — the body that builds is never the body that attests — plus an accumulated, attributed record that compounds with time. See [Business Model](04-business-model.html).

## The team

Richard Taubin (Founder — standard, brand, GTM), Joe Saba (CAIO — the Aperture engine), Chris Bennett (CTO — enterprise infrastructure, Azure, senior-Microsoft relationships), Roberto Lleras (CSO — data science and AI), and Sean Barlow (full-stack and AI engineering). A repository of the team's combined enterprise SME expertise is incoming. See [Team](05-team.html).

## The market

AI-governance platform spend is projected to grow from $492M to over $1B by 2030 (Gartner), with 75% of the world's economies under AI regulation by 2030 (Gartner) and board AI-risk oversight jumping from 16% to 48% of the Fortune 100 in a single year (EY). See [Market](03-market.html).

## The ask

We are raising $[ amount ] *(illustrative)* to connect the live connectors, stand up multi-tenant isolation, auth, RBAC, and audit, and convert the first channel into measured — not modeled — results.

See [Executive Summary](01-executive-summary.html).