Context super-management
One governed source for plans, standards and decisions. What was agreed is in one place, in a form a delivery team can actually work from.
Policy, Architecture and Audit
Tzu is context super-management: it turns the policy and architecture a company has already agreed on into detailed plans a team can check against, and keeps the evidence that the delivered system followed them. One of its capabilities, the audit in depth, is open today as audit.tzu.
Policy, Architecture and Audit
Context super-management that turns company policy and architecture into detailed, checkable plans before delivery begins. Systems, decisions and standards are held as one connected memory behind those plans. Tzu also sits in front of every call to a model, keeps the secrets that call needs, and makes its cost visible, so governance, AI access and spend are answered in one place.
Every product delivers against a written rule, and the evidence that it did exists without anyone assembling it.
Capabilities
Plans a team can work from, governed access to models, custody of what the work needs, and a record that is already assembled when someone asks for it.
One governed source for plans, standards and decisions. What was agreed is in one place, in a form a delivery team can actually work from.
Systems, decisions and standards are connected behind every plan. A question about one of them reaches the others, with the reasoning kept alongside the rule.
Every call to a model is routed, attributed and kept inside your boundary. Which provider answered, for which project and at what cost, is on record.
Caching and context reuse cut what each run spends. The cost of a workflow is visible while it runs, not on an invoice a month later.
Strict permission boundaries. Raw credentials never travel with the work, and every read of a secret is recorded.
Governance checked in code and infrastructure, not in the documents describing them. Findings, scores and evidence are kept as an auditable record. This is the capability audit.tzu opens to you.
audit.tzu
Of the six capabilities, one is open to the company being audited as a subscription: the audit in depth. The other five reach you through a mission with our team.
The audit in depth, read from your side: the maturity score, the findings, the follow-up and the delivered report. Hosted by euphile in the EU, at audit.tzu.euphile.eu. Two plans, a free trial, and you can cancel at any time.
Policy and plan management, the knowledge graph, the model gateway, secrets custody and token optimization run behind audit.tzu, on euphile's side. Tzu is in beta and is not sold as a subscription yet. If your question is about Tzu itself, meet an expert: we build a commercial offer around your situation, on infrastructure you control, inside the borders of one country when that is the requirement.
audit.tzu in detail
Standard and Premium both start here: a score, a radar on every repository, and analyses that run in the EU.
Your maturity score by dimension, with recommended objectives for the short, medium and long term.
Health grade from A to F, refactoring priorities, security findings, and leaked secrets reported by location and rule, never by value. Performance and privacy findings alongside.
Dependency vulnerabilities (SCA), an SBOM with licence obligations, contributor activity, an interactive structure explorer and file search.
On OpenAI models deployed in Microsoft's EU Data Zone (Microsoft Foundry) and on Mistral models served from Mistral's EU endpoint. The platform supports other providers of many kinds.
Premium, beta and rolling out
Each card says where a feature stands: in Premium, in beta with limits, rolling out in the next weeks, or alpha.
One fuller tour of your code per month by the AI auditor: scope, business context, executive summary, technical maturity, findings across eight domains, strengths, risks, recommendations and roadmap. A locked, numbered PDF, downloadable and sent by email, in English or French. We calibrate the first one with you.
Your own database, started seconds before use and shut down after one hour idle.
Premium manages its own users. Distinct roles for everyone, viewer, contributor and client administrator, are rolling out in Standard.
Start it yourself from any security finding: attack paths, what blocks them today, likelihood over three time horizons, and what you can do now. The number of runs is capped and the portal shows what is left. Premium has three times more.
Add a read-only token; replace or withdraw it at any time. The next analysis reads your live cluster. The credential never enters the analysis sandbox.
A daily record of every read of your project, ours included, with refusals and failed sign-ins. Pseudonymised; you choose how long it is kept.
Your team moves items itself, from not started to in progress to done, with a comment and an audit trail.
Any supported provider, configured for you. Until then, every plan runs on the EU-hosted models above.
The button lands once the workflow has passed its evaluation. Until then, ask us and we run it for you.
Plans and prices
Two plans for the portal. The free trial starts on your first successful sign-in, and you can cancel at any time. Tzu itself is priced per mission.
Standard
€100per month
For a team that wants its maturity score and a radar on its own repositories today.
Premium
€250per month
For a company that wants a written report every month, its own database and more room for analyses. Available after the trial period.
Tzu, the platform
Priced per mission
Not sold as a subscription yet. The six capabilities, run where you need them, with an offer built around your situation.
Prices apply to audit.tzu. The prices and what each plan includes are read from Plutus, the platform's billing product, every time this page is published.
Getting started
Three steps, none of them a project.
Meet an expert or write to us. We create the project and invite the people who will read the audit.
Repository URL plus a read-only access token (PAT), or invite us to your project on GitHub, GitLab or Azure DevOps.
Your free trial starts on your first successful sign-in. The first analyses follow, and the portal shows what is left of each capped feature.
We do not write to your repository. At this level of collaboration, we do not need write access.
Built for
Write a standard once and have it reach every delivery team as a plan they can check against, instead of a document they will read once.
Ask what a system complies with today and get an answer backed by evidence, rather than a reconstruction assembled from tickets and memory.
Know the rule before the work starts, and finish without a review that asks for three months of rework to satisfy a standard nobody applied.
Why Tzu
Named after Sun Tzu, who argued that battles are won before they are fought, by the planning that precedes them. The same holds for software: what decides whether a system can be governed is settled before the first commit, and almost never written down in a form a delivery team can use.
Almost nobody starts there. Most systems are already running. The policy is in somebody's head, the controls are applied unevenly, and nobody can measure the distance between them.
Tzu works from the other direction as well. It reads what the code and the infrastructure actually do, then rebuilds the policy set from what it finds. Each policy becomes a control that can be checked. The distance between them is measured continuously, and the result is a plan a team can act on. Starting late costs you the head start, and nothing else.
Most governance tools inspect what was built. Tzu works on the plan the work is meant to follow, whether that plan is written before the first commit or rebuilt from a system that is already running.
A claim about a system is worth what its evidence is worth. Every verdict points at the code or the infrastructure it came from.
The record is built as the work happens, so an audit is a question rather than a quarter of someone reconstructing history.
Plans and audit trails are the most sensitive record an engineering organisation keeps. Tzu is designed for teams that cannot hand them to a service somewhere else.
How it works
Policy goes in at one end as something a company has agreed. Evidence comes out at the other as something an auditor can read.
Policy, architecture and prior decisions are brought into one governed source, with the reasoning kept alongside the rule.
The context becomes detailed plans a delivery team can work from and check against, written before the work begins.
Repositories and infrastructure are read as they actually are, so the check is against the running system and not its description.
Each plan is checked against what was found, and every verdict carries the evidence that produced it.
Findings and evidence accumulate as an auditable history, ready for the review before anyone asks for it.
Every step runs inside infrastructure you control. Nothing about your plans or your code has to leave it for the chain to work.
audit.tzu is open today. For Tzu itself, meet an expert and we build the offer around your situation.
Meet an expert