Back to the platform

Policy, Architecture and Audit

Decide the rule before the next commit. Prove it after.

Tzu is context super-management: it turns the policy and architecture a company has already agreed on into detailed plans a team can check against, and keeps the evidence that the delivered system followed them. One of its capabilities, the audit in depth, is open today as audit.tzu.

Policy, Architecture and Audit

Context, plans, governed access to models and audit evidence, decided before the work and proven after it.

Context super-management that turns company policy and architecture into detailed, checkable plans before delivery begins. Systems, decisions and standards are held as one connected memory behind those plans. Tzu also sits in front of every call to a model, keeps the secrets that call needs, and makes its cost visible, so governance, AI access and spend are answered in one place.

Status: Beta

Every product delivers against a written rule, and the evidence that it did exists without anyone assembling it.

Capabilities

Six capabilities, one governed platform

Plans a team can work from, governed access to models, custody of what the work needs, and a record that is already assembled when someone asks for it.

Context super-management

One governed source for plans, standards and decisions. What was agreed is in one place, in a form a delivery team can actually work from.

Knowledge graph

Systems, decisions and standards are connected behind every plan. A question about one of them reaches the others, with the reasoning kept alongside the rule.

LLM gateway

Every call to a model is routed, attributed and kept inside your boundary. Which provider answered, for which project and at what cost, is on record.

Token optimization

Caching and context reuse cut what each run spends. The cost of a workflow is visible while it runs, not on an invoice a month later.

Secrets custody

Strict permission boundaries. Raw credentials never travel with the work, and every read of a secret is recorded.

Audit in depth

Governance checked in code and infrastructure, not in the documents describing them. Findings, scores and evidence are kept as an auditable record. This is the capability audit.tzu opens to you.

audit.tzu

audit.tzu is one window onto Tzu

Of the six capabilities, one is open to the company being audited as a subscription: the audit in depth. The other five reach you through a mission with our team.

Subscription, open today

audit.tzu

The audit in depth, read from your side: the maturity score, the findings, the follow-up and the delivered report. Hosted by euphile in the EU, at audit.tzu.euphile.eu. Two plans, a free trial, and you can cancel at any time.

Through a mission with us

Tzu, the platform

Policy and plan management, the knowledge graph, the model gateway, secrets custody and token optimization run behind audit.tzu, on euphile's side. Tzu is in beta and is not sold as a subscription yet. If your question is about Tzu itself, meet an expert: we build a commercial offer around your situation, on infrastructure you control, inside the borders of one country when that is the requirement.

audit.tzu in detail

What every audit.tzu plan includes

Standard and Premium both start here: a score, a radar on every repository, and analyses that run in the EU.

360° Review

Your maturity score by dimension, with recommended objectives for the short, medium and long term.

Code Radar, per repository

Health grade from A to F, refactoring priorities, security findings, and leaked secrets reported by location and rule, never by value. Performance and privacy findings alongside.

Dependencies, SBOM and structure

Dependency vulnerabilities (SCA), an SBOM with licence obligations, contributor activity, an interactive structure explorer and file search.

Analyses run in the EU

On OpenAI models deployed in Microsoft's EU Data Zone (Microsoft Foundry) and on Mistral models served from Mistral's EU endpoint. The platform supports other providers of many kinds.

Premium, beta and rolling out

What Premium adds, and what is on its way

Each card says where a feature stands: in Premium, in beta with limits, rolling out in the next weeks, or alpha.

Automated audit report (Premium)

One fuller tour of your code per month by the AI auditor: scope, business context, executive summary, technical maturity, findings across eight domains, strengths, risks, recommendations and roadmap. A locked, numbered PDF, downloadable and sent by email, in English or French. We calibrate the first one with you.

Dedicated database (Premium)

Your own database, started seconds before use and shut down after one hour idle.

Manage my users (Premium)

Premium manages its own users. Distinct roles for everyone, viewer, contributor and client administrator, are rolling out in Standard.

Threat analysis (beta)

Start it yourself from any security finding: attack paths, what blocks them today, likelihood over three time horizons, and what you can do now. The number of runs is capped and the portal shows what is left. Premium has three times more.

Kubernetes cluster connection (beta)

Add a read-only token; replace or withdraw it at any time. The next analysis reads your live cluster. The credential never enters the analysis sandbox.

Who accessed my data (rolling out)

A daily record of every read of your project, ours included, with refusals and failed sign-ins. Pseudonymised; you choose how long it is kept.

Manual follow-up on the 360° Review (rolling out)

Your team moves items itself, from not started to in progress to done, with a comment and an audit trail.

Bring your own AI model (coming to Premium)

Any supported provider, configured for you. Until then, every plan runs on the EU-hosted models above.

Delete my data (alpha)

The button lands once the workflow has passed its evaluation. Until then, ask us and we run it for you.

Plans and prices

audit.tzu plans

Two plans for the portal. The free trial starts on your first successful sign-in, and you can cancel at any time. Tzu itself is priced per mission.

Premium

€250per month

For a company that wants a written report every month, its own database and more room for analyses. Available after the trial period.

  • Everything in Standard
  • One automated audit report per month, as a locked PDF
  • Dedicated database
  • Manage my users
  • Three times more threat analyses
  • 10 unique workflows (beta)
  • Bring your own AI model (coming)
Talk to us about Premium

Tzu, the platform

Priced per mission

Not sold as a subscription yet. The six capabilities, run where you need them, with an offer built around your situation.

  • Everything audit.tzu does
  • Context super-management and the knowledge graph
  • LLM gateway, token optimization and secrets custody
  • On your own hardware, in a cloud account you own, or inside one country
  • Expert-led targeted audit, quoted separately
Meet an expert

Prices apply to audit.tzu. The prices and what each plan includes are read from Plutus, the platform's billing product, every time this page is published.

Getting started

Getting started with audit.tzu

Three steps, none of them a project.

  1. Tell us the project name

    Meet an expert or write to us. We create the project and invite the people who will read the audit.

  2. Give us read-only access to the code

    Repository URL plus a read-only access token (PAT), or invite us to your project on GitHub, GitLab or Azure DevOps.

  3. Sign in

    Your free trial starts on your first successful sign-in. The first analyses follow, and the portal shows what is left of each capped feature.

We do not write to your repository. At this level of collaboration, we do not need write access.

Built for

Built for the people who answer for the system

Architecture

Architects and tech leads

Write a standard once and have it reach every delivery team as a plan they can check against, instead of a document they will read once.

Compliance

Audit and compliance

Ask what a system complies with today and get an answer backed by evidence, rather than a reconstruction assembled from tickets and memory.

Engineering

Delivery teams

Know the rule before the work starts, and finish without a review that asks for three months of rework to satisfy a standard nobody applied.

Why Tzu

Why Tzu?

Named after Sun Tzu, who argued that battles are won before they are fought, by the planning that precedes them. The same holds for software: what decides whether a system can be governed is settled before the first commit, and almost never written down in a form a delivery team can use.

Almost nobody starts there. Most systems are already running. The policy is in somebody's head, the controls are applied unevenly, and nobody can measure the distance between them.

Tzu works from the other direction as well. It reads what the code and the infrastructure actually do, then rebuilds the policy set from what it finds. Each policy becomes a control that can be checked. The distance between them is measured continuously, and the result is a plan a team can act on. Starting late costs you the head start, and nothing else.

The plan is the product

Most governance tools inspect what was built. Tzu works on the plan the work is meant to follow, whether that plan is written before the first commit or rebuilt from a system that is already running.

Checked, not asserted

A claim about a system is worth what its evidence is worth. Every verdict points at the code or the infrastructure it came from.

Evidence without an assembly project

The record is built as the work happens, so an audit is a question rather than a quarter of someone reconstructing history.

Built for a hard constraint

Plans and audit trails are the most sensitive record an engineering organisation keeps. Tzu is designed for teams that cannot hand them to a service somewhere else.

How it works

How it works

Policy goes in at one end as something a company has agreed. Evidence comes out at the other as something an auditor can read.

  1. Capture the context

    Policy, architecture and prior decisions are brought into one governed source, with the reasoning kept alongside the rule.

  2. Turn it into plans

    The context becomes detailed plans a delivery team can work from and check against, written before the work begins.

  3. Scan the system

    Repositories and infrastructure are read as they actually are, so the check is against the running system and not its description.

  4. Verify against the rule

    Each plan is checked against what was found, and every verdict carries the evidence that produced it.

  5. Retain the record

    Findings and evidence accumulate as an auditable history, ready for the review before anyone asks for it.

Every step runs inside infrastructure you control. Nothing about your plans or your code has to leave it for the chain to work.

Start with the audit, or talk about Tzu

audit.tzu is open today. For Tzu itself, meet an expert and we build the offer around your situation.

Meet an expert