21 days.
By invitation.

Validate one AI workflow in your controlled environment. Test residency, redaction, monitoring and evidence before production.

ColloxaConsole
Demo tenant administratorTenant_AF_01
Synthetic demonstration dataCustomer data controls @ 2.14.0
Market
Africa regional
Scope
Pilot cohort
Period
21 days
Governed
2,847
Recorded decisions
Intervened
31%
Redacted, reviewed or blocked
Active paths
3
Managed browser and API routes
Unapproved routes
140
Prevented or quarantined

Decision activity

Live synthetic feed
Interactive synthetic Colloxa Console demonstration. Not connected to a live customer environment.

What the 21 days
actually look like.

The pilot validates one defined AI workflow inside your controlled environment. It proves that Colloxa can enforce the agreed controls, route exceptions to people and produce complete evidence at acceptable latency.

01
Day 0 · Architecture and policy workshop

Forty-five minutes. We register in-scope AI use cases, agree surfaces and policies, and define the pilot boundary and day-21 success metrics. You leave with signed scope and signed success criteria aligned to your deployment assurance workflow.

02
Days 1–3 · Colloxa Core deployment

Colloxa Core is deployed inside your controlled environment. Detection, redaction, deterministic policy evaluation and evidence writing are configured against your primary jurisdiction.

03
Days 3–5 · Managed Colloxa for Browser installation

The managed Colloxa for Browser client is installed for your pilot cohort and connected to the deployed Core instance.

04
Days 5–8 · Synthetic testing in Colloxa Lab

Every control path, including allow, redact, review and block, is proven against synthetic scenarios in Colloxa Lab before any real interaction is governed.

05
Days 8–11 · Policy simulation

Proposed rules run in simulation against real traffic patterns, measuring impact before they interrupt anyone's work.

06
Days 11–14 · Limited enforcement

Selected high-confidence controls go live. A mid-pilot committee review on day 14 confirms course or adjusts scope.

07
Days 14–20 · Review operations

Reviewers resolve escalated requests with full context, policy rationale and immutable history.

08
Day 21 · Pilot outcome and evidence report

Signed. Exportable. Mapped to your jurisdictional obligations. Reviewed with Legal, Compliance, Risk and Security together. You leave the review knowing whether your AI deployment evidence is defensible before committing to production.

Pilot
boundary.

Every pilot is scoped before it starts. No exceptions, no scope creep mid-pilot.

  • One defined workflow (customer support, complaints, or a similarly bounded process)
  • One managed user cohort
  • Explicit supported AI surfaces
  • One customer-controlled Colloxa Core instance
  • One primary jurisdiction
  • One approved policy pack
  • Synthetic-first via Colloxa Lab. Controlled production data is used only where separately authorised

Colloxa Lab-ready
by design.

Colloxa Lab defines and tests users, surfaces, data boundaries, approvals, monitoring and fallback paths before the first governed interaction.

Scope

AI tools, APIs, departments and user groups included.

Controls

Policies, prompts, data restrictions, access rules and escalation paths.

Monitoring

Usage logs, anomaly detection, drift indicators, performance and incidents.

Review

Evidence pack, lessons learned, risk register updates and adoption recommendation.

AreaExample success metric
Governance coverage100% of in-scope AI use cases and customer record types registered
Data residencyStorage location, processing location, cross-border flags and redaction status recorded
Control effectivenessAI-readiness decisions applied: eligible, redacted, local-only, copilot-only, review, human-only or block
MonitoringDrift, usage, failure and anomaly logs captured
SecurityPrompt injection, data leakage and unauthorised access attempts logged
FairnessBias and local-language parity tests completed where relevant
EvidenceFinal evidence pack reviewed by governance stakeholders

Who the pilot is built for.

Yes
  • African institutions operating across data-protection, fintech, telecoms, mobile-money, remittance or public-service contexts
  • Organisations with jurisdiction-specific privacy and data-residency obligations
  • Regulated organisations, 500–10,000 employees
  • Active AI usage your committee cannot see, and is accountable for anyway
  • Legal, compliance, risk or procurement at the table
  • A named point of contact in legal, risk, compliance or data protection
Not yet
  • Pre-revenue startups without regulatory exposure
  • Organisations with no AI usage in production
  • Security-only buyers without legal, risk or compliance in the room
  • Anyone looking for a free self-serve trial
  • Organisations expecting universal AI tool inspection across unmanaged devices

Pilot
roles.

Executive sponsor
Legal/compliance lead
Security lead
Data protection lead
Technical owner
Procurement lead

Due diligence topics.

Common diligence questions on deployment assurance, evidence quality, and operating boundaries. For deeper detail, request a scoped architecture review.

Request Architecture Review
The pilot
The first pilot-priority surface is ChatGPT Web on a managed browser path. Claude, Gemini and Perplexity web are assessed after ChatGPT and remain subject to surface-specific validation. Colloxa API, OpenAI, Anthropic, Gemini API and internal LLM endpoints are design-partner expansion after the browser-led pilot. Microsoft Copilot and Microsoft 365 Copilot remain partial or design-partner scope. GitHub Copilot and IDE assistants are contained or detected-only unless a signed scope confirms a reliable control path. Agent frameworks and cloud AI platforms remain roadmap work. Coverage is confirmed in your signed pilot scope. See the supported surfaces matrix.
Access and data handling
No standing access by default. Colloxa defaults to metadata-first capture: enough context to prove the decision without storing full prompt text by default. Fuller capture is opt-in per tenant under agreement. Internal access requires approval and creates an auditable record.
No. Governance applies only to AI tools and paths in your signed scope, not your full network. Scope is defined in the pilot agreement and can be narrowed at any time.
Deployment and operations
Governed paths fail closed by default: if policy, detection, or audit services cannot evaluate a request, Colloxa blocks or quarantines rather than allowing ungoverned submission. Fail-open exceptions require explicit written scope in a signed engagement.
The standard pilot includes one customer-controlled Colloxa Core instance. Hosting geography, approved processors, data movement, retention and residency are defined in signed scope. On-premises and private-cloud variants remain design-partner options unless contracted.
Personal devices outside your corporate management programme are outside pilot scope. Where your organisation has authorised a control path on managed equipment, Colloxa can govern in-scope AI usage there. We document coverage gaps rather than implying universal device coverage.
The standard motion is a 21-day deployment assurance pilot with signed scope and success criteria. Production deployment timing after a pilot depends on channel scope, integrations, and workflow design.
Security posture
Colloxa enforces least-privilege access with MFA and encryption in transit. Current certification status, independent testing status, security posture materials and a security questionnaire are available during diligence under NDA.
Stage and disclosure
Colloxa is pre-general-availability and design-partner ready. Pilot-ready and design-partner capabilities are available for scoped validation; roadmap items remain forward-looking. Final availability and commercial commitments are confirmed in a signed engagement.

Request
invitation.

One short conversation. We will tell you honestly whether the pilot fits, or whether your situation needs something different first. Either answer is useful to you.