Policy is easy to write.
Execution is harder.

Designed around African data, infrastructure and regulatory realities.

ColloxaConsole
Demo tenant administratorTenant_AF_01
Synthetic demonstration dataCustomer data controls @ 2.14.0
Market
Africa regional
Scope
Pilot cohort
Period
21 days
Allowed
1,972

69% of scoped activity

Redacted
511

Before onward processing

Sent to review
224

18 awaiting a person

Prevented
140

Blocked or quarantined

Outcomes

Decision distribution

Last 21 days
Allowed
69%
Redacted
18%
Review
8%
Prevented
5%
Evidence records
2,840 / 2,847 ready
Human review
18 open · 2 due
Processing
Approved routes only
Governed activity

Recent decisions

Select a decision
Selected decision traceev_7c42a1
Data detected
Customer identifiers
Policy applied
Customer data controls v2.14
Processing route
Approved regional processor
Human oversight
Not required
Evidence state
Complete
Data handling
Customer-controlled retention
Interactive synthetic Colloxa Console demonstration. Not connected to a live customer environment.

African operating focus

Built for African operating realities.

Colloxa is designed for regulated institutions navigating regional processing constraints, mixed cloud and internal infrastructure, multilingual customer operations and uneven AI governance maturity.

Market-specific regulatory depth develops through signed engagements.

01Regional processing constraints

Control which processors, models and locations may receive sensitive information.

02Mixed technical estates

Support customer-controlled, private-cloud and approved regional environments.

03African customer operations

Address mobile-money, remittance, KYC, fraud and multilingual support workflows.

One governed interaction

See the control path,
not another policy diagram.

Every supported request follows a visible chain from attempted use to reviewable evidence. Unsupported paths are contained or labelled honestly rather than silently counted as governed.

Example: a mobile-money support agent attempts to summarise a customer dispute using an approved AI service. Colloxa checks the record before it reaches the processor.

  1. 01Browser / API

    Attempt

    An authorised AI request enters a governed control path.

  2. 02Colloxa Core

    Inspect

    Sensitive data is detected, minimised or redacted before processing.

  3. 03Policy engine

    Decide

    A versioned rule allows, redirects, escalates or blocks the request.

  4. 04Console

    Review

    The accountable team sees the decision, rationale and required action.

  5. 05Evidence pack

    Prove

    The event becomes an integrity-linked record for later review.

Rule POPIA-PII-04 matchedallow_after_redactionEvidence record prepared

Customer-controlled governance

Govern AI without giving up control of your data.

Sensitive evaluation, policy execution and evidence stay within the deployment boundary agreed with your organisation. Scope and supported control paths are confirmed in writing.

  1. 01

    Customer-controlled deployment

    Deploy Colloxa Core in a customer-controlled environment. The signed pilot defines topology, residency, approved processors, retention and backups.

    Pilot / scoped
  2. 02

    Residency-aware processing

    Configure which approved processors, models and locations may receive particular information categories on supported control paths.

    Signed scope
  3. 03

    Data minimisation by design

    Detect and redact sensitive information before onward processing. Colloxa defaults to metadata-first evidence rather than raw-prompt storage.

    Pilot default
  4. 04

    Customer-controlled evidence

    Retain policy versions, control decisions, review rationale and integrity-linked evidence under customer administration within the agreed environment.

    Governed paths
  5. 05

    Africa-first architecture

    Support mixed technical estates, regional processing constraints, multilingual operations and regulated mobile-money, remittance, fintech and public-service workflows.

    Design principle

Scroll horizontally to follow every route.

A governed AI request moves through Colloxa Core and policy evaluation to approved regional processing, local-only processing, redaction or a blocked external route. Every outcome returns an evidence record to the customer-controlled environment.
Illustrative control path. The signed engagement defines the approved deployment and processor routes.

Public descriptions explain the intended architecture. Your signed engagement defines the live deployment model, data movement, processor routes, retention, contractual data rights and evidence scope.

Operational interface

Operate governance,
not just report it.

Colloxa Console is where security, compliance, risk and operations teams monitor governed AI activity, resolve escalations, configure controls, and retrieve evidence without needing to inspect raw prompts themselves.

Overview / Activity / Reviews / Evidence / Policies / Systems

Controlled validation

Validate one institutional AI workflow.

Define the users, AI surfaces, customer-record boundaries, processing locations, controls and success criteria. Validate them with synthetic scenarios before approved production use is considered.

  • 01
    21 daysScoped validation period
  • 02
    One workflowControlled validation run through Colloxa Lab: users, AI surfaces, customer-record boundaries, residency rules, monitoring rules, fallback triggers and evidence review.
  • 03
    Reviewable evidenceYou leave with a structured evidence pack your legal, compliance, security and governance teams can review.