Qortara product family · open + managed · active development

Govern agents.
Govern delivery.

Qortara is becoming a family of governed AI and software-delivery products: Agent Governance for what agents may do and how their actions are evidenced, and Qortara SDLC for how software work is understood, planned, governed, verified, and delivered. One shared application shell brings entitled products together without collapsing their authority.

Open-source Qortara Governance adapters are available today. Managed Agent Governance and Qortara SDLC remain pre-production while their hosted product paths are being built and verified.

Agent_Governance_Evidence

[01:23:45] agent_42 policy_eval policy=data_egress decision=ALLOW 12ms

[01:23:46] agent_17 saga_step action=db_write status=PENDING_VERIFY

[01:23:46] agent_17 saga_step action=db_write status=VERIFIED 47ms

[01:23:47] agent_89 trust_lookup org=acme.io score=0.94 fresh=12m

[01:23:47] compliance_evidence framework=SOC2 tenant=... state=COLLECTED

* Illustrative only. Managed Agent Governance telemetry and evidence surfaces remain in active pre-production build.

Product family

Two product domains. One shared Qortara shell.

Qortara Agent Governance governs AI-agent execution. Qortara SDLC governs the software-delivery lifecycle around that execution. Qor Oversight and Qor Compliance retain their own evidence and presentation authority and can be composed into the products a tenant is licensed to use. The shared app.qortara.com shell handles entry, organization context, and product discovery; it does not become the semantic authority for the products it hosts.

01

Qortara Agent Governance

Agent governance · open-source foundation + managed plane

Govern agent identity, policy, trust, actions, evidence, incidents, fleet posture, and adaptive-state transitions. The open-source Qortara Governance adapters are available today; the managed product plane is in active build on Microsoft Agent Governance Toolkit capabilities.

Open-source adapter available · managed plane in active build

Explore Agent Governance
02

Qortara SDLC

Governed software delivery · active product realization

A visual organizational development workspace for repository and organization state, planning, capacity, governed development, evidence, Oversight, Compliance, decisions, release, and delivery across human, automated, and guided-agentic work.

Cloud Connected path in active build

See the SDLC roadmap

Shared shell

Authentication, organization context, entitlement-driven product discovery, and shared account experience.

Qor Oversight

Read-only posture, provenance, freshness, source health, drill-down, and attention routing.

Qor Compliance

Evidence normalization, control relevance, evidence packages, exports, and auditor-facing delivery.

Public product roadmap

From agent governance to governed software delivery.

Qortara is evolving into a family of governed AI and software-delivery products behind one entitlement-driven application shell. Status is shown by maturity, not by invented ship dates: available capabilities are separated from active development, planned expansion, and research.

Available now
  • Qortara Governance

    Open-source agent governance adapters

    Apache-2.0 developer tooling for governed agent execution and evidence capture, with LangChain and LangGraph support available today.

  • Qortara Agent Governance

    Portable trust attestations

    Qortara-signed agent attestations can be minted, looked up by agent identifier, and verified with Ed25519.

Active build
  • app.qortara.com

    One entitlement-driven Qortara application shell

    One authenticated organization context will expose only the Qortara applications and capabilities a tenant is entitled to use. The shell is shared; each product keeps its own domain authority.

  • Qortara Agent Governance

    Managed Agent Governance

    A managed governance plane built on Microsoft Agent Governance Toolkit capabilities, with policy, trust, fleet visibility, evidence, incidents, and governed adaptive-state transitions.

  • Qortara SDLC

    Cloud-connected software-delivery governance

    The active hosted path combines GitHub-first source onboarding, durable evidence, organizational and repository visibility, Qor Oversight, Qor Compliance, owner decisions, and delivery state without requiring local installation.

  • Qortara SDLC

    Organizational development workspace

    A visual workspace for repository and organization state, planning, capacity, governed development, evidence, compliance, oversight, and human or agent-assisted delivery.

Next
  • Qortara SDLC

    Hybrid execution and private-environment support

    Optional Runner and hybrid profiles for private networks, local validation, customer-side redaction, deployment evidence, and controlled execution where a hosted connector is not enough.

  • Qortara SDLC

    Broader development clients and connectors

    Thin CLI, IDE, agent, and MCP clients plus additional source and delivery adapters, all consuming the same governed SDLC contracts rather than creating parallel product truth.

  • Qortara Agent Governance

    Cross-organization trust federation

    Portable trust and policy relationships across independent organizations and agent platforms remain a planned expansion beyond the first managed-governance surface.

Research
  • Qortara OS

    Sovereign agent-native operating system

    Architecture and research for governed execution, compartmentalized autonomy, local-first policy and memory, evidence, revocation, and rollback. No production OS image exists today.

  • Qortara ecosystem research

    Governed durable agent memory

    Research into durable context, provenance, correction, retrieval, precedent, and authority-aware memory that can support future Qortara products without turning remembered information into permission.

Qortara Agent Governance, Qortara SDLC, Qor Oversight, Qor Compliance, and future Qortara applications retain separate product and domain authority even when the shared app shell presents them together.

Research items are not shipping-product commitments.

Controlled, verifiable agent evolution

The foundation governs the action. Qortara governs how your agents evolve.

Qortara governs how agent memory becomes behavior, and how behavior earns authority. AGT enforces the action now; Qortara decides whether the learned state behind it earned its influence and authority, then delivers that operated and accountable.

Governs how agents evolve

Qortara

Qortara governs how agent memory becomes behavior, and how behavior earns authority: controlled, verifiable agent evolution through governed adaptive-state transitions. Adaptation does not imply authority; memory does not imply procedure; procedure does not imply permission. Native to Qortara, and delivered operated and accountable.

Adaptation is not authority · memory is not procedure · procedure is not permission

Qortara Governance · v0.2.0 · Alpha · Apache-2.0

Start with the open governance foundation.

Qortara Governance runs as a sidecar across supported agent frameworks, with LangChain and LangGraph supported today. Microsoft Agent Governance Toolkit provides upstream governance capabilities; Qortara adds adapters, evidence, productization, and the broader managed Qortara operating model around them.

Qortara is an independent project and is not affiliated with, endorsed by, or sponsored by Microsoft. AGT is used as an open-source MIT-licensed dependency.

pip install qortara-governance-langchain

With LangGraph:

pip install 'qortara-governance-langchain[langgraph]'

Conformance evidence · EU AI Act Article 12 & 14

Evidence from the execution path.

Agent Governance can map real execution and human-oversight records to regulatory obligations. Model-governance and GRC tools document models and paperwork; Qortara adds evidence about what governed agents actually did.

Article 12

Record-keeping

High-risk systems must keep automatic, tamper-evident logs of activity for traceability. Qortara captures each governed tool call from real execution, designed to map to that logging requirement.

Article 14

Human oversight

High-risk systems must let people interpret, intervene, and stop. Qortara records oversight and intervention events as evidence you can present toward an Article 14 assessment.

Qortara produces conformance evidence, not a compliance determination. Using Qortara does not guarantee compliance with any framework; your auditor or counsel decides whether it satisfies your obligations. Regulatory timelines and applicability can change; verify current obligations with your auditor or counsel.

Evidence designed to support

SOC 2 ·GDPR ·EU AI Act ·NIST AI RMF

Qortara Agent Governance is being built to preserve governed execution and human-oversight evidence. Qor Compliance can normalize, package, and map relevant evidence for review without becoming a certifier.

Using Qortara does not guarantee compliance with any framework. Evidence relevance and final compliance determinations belong to your auditor, assessor, or legal counsel.

Agent Governance capability track

Govern execution without pretending activity is authority.

These capabilities belong to the Agent Governance track. Qortara SDLC extends the product family into governed planning, development, verification, evidence, release, and delivery rather than duplicating the same runtime controls.

Native Qortara governanceActive build

Controlled Agent Evolution

Govern how your agents' learned state earns durability and authority, controlled and verifiable. Adaptation does not become permission merely because it happened repeatedly. AGT can help govern whether an action may execute now; Qortara additionally governs whether learned or adaptive state has earned durable influence and authority.

  • Adaptation is not authority
  • Memory is not procedure
  • Procedure is not permission
Available today
02Available

Trust Attestation Lookups

Mint a Qortara-signed attestation for an agent, look it up across organizations by identifier, and verify it with Ed25519.

03Available

Agent Activity Evidence

The open-source adapter records governed tool calls from real execution at the dispatch path, creating evidence the managed governance plane can build on.

In active build
04Active build

Managed Governance Operations

A managed governance plane for policy, identity, trust, fleet posture, audit evidence, incidents, and enterprise operation, built on and extending supported AGT capabilities.

05Active build

Conformance Evidence

Execution and human-oversight records assembled into evidence you can present toward an assessment. Evidence and control relevance are not a compliance certification.

06Active build

Event Delivery to Your Tooling

Signed event delivery into your SIEM, SOAR, or ticketing system, with retry. Your existing tooling can consume the governance signal without becoming Qortara authority.

Security by design

Built to fail closed.

Governance is only worth as much as the guarantees underneath it. The open-source developer layer already demonstrates fail-closed policy behavior; the managed Agent Governance product is extending that posture into tenant, evidence, trust, and service boundaries.

The default answer

Fail-closed by design

If the policy engine cannot reach a decision, the action is denied. A denied call does not silently degrade into an allow, and uncertainty is not resolved in the agent's favor.

policy.engine → unreachable

decision: DENY

reason: evaluator_unreachable

Tamper-evident audit ledger

Governance evidence is designed to preserve append-oriented integrity so operators can detect unexpected record changes.

Per-tenant isolation

Managed product data is designed around tenant-isolated service and persistence boundaries rather than browser-only separation.

Verifiable agent identity

Agent and trust records are designed to carry explicit identity and verification evidence instead of relying on display names.

Hardened service edge

Managed service traffic is designed to enter through the approved service edge rather than exposing a raw origin as the customer contract.

Fail-closed behavior can be exercised in the open-source governance adapter today. The additional managed-service properties above describe the active Agent Governance architecture and remain subject to production verification before general-availability claims.

Start with what is real today. Follow what is being built next.

The open-source Agent Governance adapters are available now. Managed Agent Governance, the shared Qortara application shell, and Qortara SDLC are being built as the next product layer, with capabilities released only when their evidence and operating boundaries are ready.

Qortara produces conformance evidence, not a compliance determination. Using Qortara does not guarantee compliance with any framework; your auditor or counsel decides whether it satisfies your obligations.

Extends the open-source

Microsoft Agent Governance Toolkit

Compatible with LangChain, CrewAI, AutoGen, OpenAI Agents, Google ADK, and any AGT-supported framework. Built on top of AGT, never a fork. We track Microsoft’s upstream releases to maintain compatibility.