Govern agents.
Govern delivery.
Qortara is becoming a family of governed AI and software-delivery products: Agent Governance for what agents may do and how their actions are evidenced, and Qortara SDLC for how software work is understood, planned, governed, verified, and delivered. One shared application shell brings entitled products together without collapsing their authority.
Open-source Qortara Governance adapters are available today. Managed Agent Governance and Qortara SDLC remain pre-production while their hosted product paths are being built and verified.
[01:23:45] agent_42 policy_eval policy=data_egress decision=ALLOW 12ms
[01:23:46] agent_17 saga_step action=db_write status=PENDING_VERIFY
[01:23:46] agent_17 saga_step action=db_write status=VERIFIED 47ms
[01:23:47] agent_89 trust_lookup org=acme.io score=0.94 fresh=12m
[01:23:47] compliance_evidence framework=SOC2 tenant=... state=COLLECTED
* Illustrative only. Managed Agent Governance telemetry and evidence surfaces remain in active pre-production build.
Product family
Two product domains. One shared Qortara shell.
Qortara Agent Governance governs AI-agent execution. Qortara SDLC governs the software-delivery lifecycle around that execution. Qor Oversight and Qor Compliance retain their own evidence and presentation authority and can be composed into the products a tenant is licensed to use. The shared app.qortara.com shell handles entry, organization context, and product discovery; it does not become the semantic authority for the products it hosts.
Qortara Agent Governance
Agent governance · open-source foundation + managed plane
Govern agent identity, policy, trust, actions, evidence, incidents, fleet posture, and adaptive-state transitions. The open-source Qortara Governance adapters are available today; the managed product plane is in active build on Microsoft Agent Governance Toolkit capabilities.
Open-source adapter available · managed plane in active build
Explore Agent GovernanceQortara SDLC
Governed software delivery · active product realization
A visual organizational development workspace for repository and organization state, planning, capacity, governed development, evidence, Oversight, Compliance, decisions, release, and delivery across human, automated, and guided-agentic work.
Cloud Connected path in active build
See the SDLC roadmapShared shell
Authentication, organization context, entitlement-driven product discovery, and shared account experience.
Qor Oversight
Read-only posture, provenance, freshness, source health, drill-down, and attention routing.
Qor Compliance
Evidence normalization, control relevance, evidence packages, exports, and auditor-facing delivery.
Public product roadmap
From agent governance to governed software delivery.
Qortara is evolving into a family of governed AI and software-delivery products behind one entitlement-driven application shell. Status is shown by maturity, not by invented ship dates: available capabilities are separated from active development, planned expansion, and research.
Qortara Governance
Open-source agent governance adapters
Apache-2.0 developer tooling for governed agent execution and evidence capture, with LangChain and LangGraph support available today.
Qortara Agent Governance
Portable trust attestations
Qortara-signed agent attestations can be minted, looked up by agent identifier, and verified with Ed25519.
app.qortara.com
One entitlement-driven Qortara application shell
One authenticated organization context will expose only the Qortara applications and capabilities a tenant is entitled to use. The shell is shared; each product keeps its own domain authority.
Qortara Agent Governance
Managed Agent Governance
A managed governance plane built on Microsoft Agent Governance Toolkit capabilities, with policy, trust, fleet visibility, evidence, incidents, and governed adaptive-state transitions.
Qortara SDLC
Cloud-connected software-delivery governance
The active hosted path combines GitHub-first source onboarding, durable evidence, organizational and repository visibility, Qor Oversight, Qor Compliance, owner decisions, and delivery state without requiring local installation.
Qortara SDLC
Organizational development workspace
A visual workspace for repository and organization state, planning, capacity, governed development, evidence, compliance, oversight, and human or agent-assisted delivery.
Qortara SDLC
Hybrid execution and private-environment support
Optional Runner and hybrid profiles for private networks, local validation, customer-side redaction, deployment evidence, and controlled execution where a hosted connector is not enough.
Qortara SDLC
Broader development clients and connectors
Thin CLI, IDE, agent, and MCP clients plus additional source and delivery adapters, all consuming the same governed SDLC contracts rather than creating parallel product truth.
Qortara Agent Governance
Cross-organization trust federation
Portable trust and policy relationships across independent organizations and agent platforms remain a planned expansion beyond the first managed-governance surface.
Qortara OS
Sovereign agent-native operating system
Architecture and research for governed execution, compartmentalized autonomy, local-first policy and memory, evidence, revocation, and rollback. No production OS image exists today.
Qortara ecosystem research
Governed durable agent memory
Research into durable context, provenance, correction, retrieval, precedent, and authority-aware memory that can support future Qortara products without turning remembered information into permission.
Qortara Agent Governance, Qortara SDLC, Qor Oversight, Qor Compliance, and future Qortara applications retain separate product and domain authority even when the shared app shell presents them together.
Research items are not shipping-product commitments.
Controlled, verifiable agent evolution
The foundation governs the action. Qortara governs how your agents evolve.
Qortara governs how agent memory becomes behavior, and how behavior earns authority. AGT enforces the action now; Qortara decides whether the learned state behind it earned its influence and authority, then delivers that operated and accountable.
Governs how agents evolve
Qortara
Qortara governs how agent memory becomes behavior, and how behavior earns authority: controlled, verifiable agent evolution through governed adaptive-state transitions. Adaptation does not imply authority; memory does not imply procedure; procedure does not imply permission. Native to Qortara, and delivered operated and accountable.
Adaptation is not authority · memory is not procedure · procedure is not permission
Start with the open governance foundation.
Qortara Governance runs as a sidecar across supported agent frameworks, with LangChain and LangGraph supported today. Microsoft Agent Governance Toolkit provides upstream governance capabilities; Qortara adds adapters, evidence, productization, and the broader managed Qortara operating model around them.
Qortara is an independent project and is not affiliated with, endorsed by, or sponsored by Microsoft. AGT is used as an open-source MIT-licensed dependency.
pip install qortara-governance-langchainWith LangGraph:
pip install 'qortara-governance-langchain[langgraph]'Conformance evidence · EU AI Act Article 12 & 14
Evidence from the execution path.
Agent Governance can map real execution and human-oversight records to regulatory obligations. Model-governance and GRC tools document models and paperwork; Qortara adds evidence about what governed agents actually did.
Article 12
Record-keeping
High-risk systems must keep automatic, tamper-evident logs of activity for traceability. Qortara captures each governed tool call from real execution, designed to map to that logging requirement.
Article 14
Human oversight
High-risk systems must let people interpret, intervene, and stop. Qortara records oversight and intervention events as evidence you can present toward an Article 14 assessment.
Qortara produces conformance evidence, not a compliance determination. Using Qortara does not guarantee compliance with any framework; your auditor or counsel decides whether it satisfies your obligations. Regulatory timelines and applicability can change; verify current obligations with your auditor or counsel.
Evidence designed to support
SOC 2 ·GDPR ·EU AI Act ·NIST AI RMF
Qortara Agent Governance is being built to preserve governed execution and human-oversight evidence. Qor Compliance can normalize, package, and map relevant evidence for review without becoming a certifier.
Using Qortara does not guarantee compliance with any framework. Evidence relevance and final compliance determinations belong to your auditor, assessor, or legal counsel.
Agent Governance capability track
Govern execution without pretending activity is authority.
These capabilities belong to the Agent Governance track. Qortara SDLC extends the product family into governed planning, development, verification, evidence, release, and delivery rather than duplicating the same runtime controls.
Controlled Agent Evolution
Govern how your agents' learned state earns durability and authority, controlled and verifiable. Adaptation does not become permission merely because it happened repeatedly. AGT can help govern whether an action may execute now; Qortara additionally governs whether learned or adaptive state has earned durable influence and authority.
- Adaptation is not authority
- Memory is not procedure
- Procedure is not permission
Trust Attestation Lookups
Mint a Qortara-signed attestation for an agent, look it up across organizations by identifier, and verify it with Ed25519.
Agent Activity Evidence
The open-source adapter records governed tool calls from real execution at the dispatch path, creating evidence the managed governance plane can build on.
Managed Governance Operations
A managed governance plane for policy, identity, trust, fleet posture, audit evidence, incidents, and enterprise operation, built on and extending supported AGT capabilities.
Conformance Evidence
Execution and human-oversight records assembled into evidence you can present toward an assessment. Evidence and control relevance are not a compliance certification.
Event Delivery to Your Tooling
Signed event delivery into your SIEM, SOAR, or ticketing system, with retry. Your existing tooling can consume the governance signal without becoming Qortara authority.
Security by design
Built to fail closed.
Governance is only worth as much as the guarantees underneath it. The open-source developer layer already demonstrates fail-closed policy behavior; the managed Agent Governance product is extending that posture into tenant, evidence, trust, and service boundaries.
The default answer
Fail-closed by design
If the policy engine cannot reach a decision, the action is denied. A denied call does not silently degrade into an allow, and uncertainty is not resolved in the agent's favor.
policy.engine → unreachable
decision: DENY
reason: evaluator_unreachable
Tamper-evident audit ledger
Governance evidence is designed to preserve append-oriented integrity so operators can detect unexpected record changes.
Per-tenant isolation
Managed product data is designed around tenant-isolated service and persistence boundaries rather than browser-only separation.
Verifiable agent identity
Agent and trust records are designed to carry explicit identity and verification evidence instead of relying on display names.
Hardened service edge
Managed service traffic is designed to enter through the approved service edge rather than exposing a raw origin as the customer contract.
Fail-closed behavior can be exercised in the open-source governance adapter today. The additional managed-service properties above describe the active Agent Governance architecture and remain subject to production verification before general-availability claims.
Start with what is real today. Follow what is being built next.
The open-source Agent Governance adapters are available now. Managed Agent Governance, the shared Qortara application shell, and Qortara SDLC are being built as the next product layer, with capabilities released only when their evidence and operating boundaries are ready.
Qortara produces conformance evidence, not a compliance determination. Using Qortara does not guarantee compliance with any framework; your auditor or counsel decides whether it satisfies your obligations.
Extends the open-source
Microsoft Agent Governance Toolkit
Compatible with LangChain, CrewAI, AutoGen, OpenAI Agents, Google ADK, and any AGT-supported framework. Built on top of AGT, never a fork. We track Microsoft’s upstream releases to maintain compatibility.