Do you know what your employees are doing with AI?

Staff paste client work into chatbots and nobody can say what left the building. Mandate enforces your AI policy at the point of use and keeps proof of what happened.

Audit event Chain verified
User
j.smith@legalfirm.ca
Tool
ChatGPT (chat.openai.com)
Triggered
SIN pattern · rule SENSITIVE-DATA-001
Action
Redact: 3 fields removed
Timestamp
May 5 2026, 09:04:37 EDT
Correlation
a2f7·9d3e·b1c4·8a00
Hash
sha256:3f9a·…·b712

Illustrative example with synthetic data.

Hosted in Canada today, deployable where you need it · Vendor jurisdiction your counsel can verify

What it costs when your AI policy isn't enforced.

None of this needs an attacker. It needs one person in a hurry and nothing in the way.

  • A privacy breach you have to report

    Client material pasted into a consumer chatbot can be a privacy breach. Where it poses a real risk of significant harm, PIPEDA has you notify the Privacy Commissioner and the people affected, with your firm's name on it.

  • A law society or CPA complaint

    Law societies and CPA oversight bodies have said existing duties cover AI use: confidentiality, supervision, competence. Those duties do not pause because the tool is new.

  • Nothing to show when someone asks for proof

    A client's vendor security review, an insurance renewal questionnaire, a regulator's file. Without a record the honest answer is that nobody knows, and you are asking them to take your word for it.

In May 2026 a Pennsylvania bank filed an SEC disclosure because an employee ran customer records, including names, Social Security numbers, and dates of birth, through an AI app the bank had not approved. There was no attacker in the story. A law firm that tracks these filings called it the first 8-K to pin a material incident on shadow AI.

Sources: American Banker, Wilson Sonsini.

Questions your current tools cannot answer.

  1. Can you name the last time sensitive data entered ChatGPT, and what your organization did about it?

  2. Can you show an auditor a structured record of what your AI policy actually enforced this quarter?

  3. Which legal jurisdiction is your AI vendor actually under? A region label doesn’t answer that, and counsel will ask.

18%

of Canadian organizations have systems in place to govern AI across everyday operations.

IBM Institute for Business Value  ·  May 2026

25%

of full-time office workers who use AI at work rely on enterprise-grade tools. The rest use personal apps or a mix.

IBM  ·  September 2025

57%

of enterprise employees have entered high-risk information into publicly available AI assistants.

TELUS Digital  ·  2025

A policy on paper enforces nothing.

You might already have an acceptable use policy for AI. Is it good enough? Start from our free Canadian template.

And if your policy is already strong, one question remains: can you show what it actually did last quarter? Mandate turns the document into enforcement at the point of use, with a record you can hand to whoever asks.

What Mandate puts in place

  • Mediation layer

    API gateway and network forward proxy connectors route every AI request through Mandate before it reaches any AI provider. No client software distributed to employees.

  • Policy enforcement

    Your configured rules apply at the point of use (allow, warn, redact, block, or escalate) based on sensitive data patterns, tool usage, and content classification.

  • Agent governance

    Each AI agent runs under its own named identity. Mandate reads the tool calls it makes, applies the same rules your people get, and writes every agent action to the same tamper-evident record.

  • Tamper-evident audit trail

    Structured audit records for every request: user, tool, policy rule, action, timestamp. Hash-chained and exportable. The record your auditor can verify.

  • Canadian-hosted infrastructure

    Runs in Canada today on Canadian-owned infrastructure, under a named legal jurisdiction. The architecture isn’t tied to one country.

One audit event per request, hash-chained and verifiable.

One structured audit event and one usage event per request, joined by correlation id and hash-chained. Your auditor verifies the export with no Mandate tooling.

  • Per-row hash chain

    Each event is SHA-256 linked to the one before it. Alter, delete, or insert any record and the chain breaks.

  • Signed checkpoints

    Periodic Ed25519-signed checkpoints with Merkle roots anchor the trail. Public keys travel with the export.

  • Independent verification

    The export alone is enough to verify. No Mandate tooling required. Verify a sample pack yourself →

One policy engine. Every request evaluated and recorded.

The policy engine sits inline between your people, their agents, and every AI provider. The decision (allow, warn, redact, block, or escalate) happens at the connection layer, before anything reaches the provider.

Full product detail →

30 days. Written criteria.

One administrator sets it up in an afternoon, nothing deployed to employees. Criteria agreed in writing before day one; if the pilot doesn't meet them, we tell you why.

Ready to see what Mandate produces
in your environment?

30 minutes to understand your environment and whether a pilot is the right next step.

contact@mandateco.ca  ·  1-905-630-1908