Smartflow vs. WitnessAI: Request Path vs. Network Layer

WitnessAI sees everything that crosses the network and nothing that does not. Smartflow sees every call routed through it, including inside an air-gapped enclave. The coverage trade, stated honestly.

WitnessAI governs AI traffic at the network layer: policy applied on the wire, with no browser extension, endpoint client or SDK. Smartflow governs it at the model request path: an inline control plane applications and agents call directly. Both allow, block and route. The difference is what each one can see, and where the record of the decision lives.

The short version

These two solve the same problem from opposite ends, and the trade is clean enough to state upfront.

WitnessAI sees everything that crosses the network, including consumer AI in a browser and Windows Copilot on a desktop, without anyone integrating anything. It cannot see what does not cross a routable network path. Smartflow sees every call routed through it, wherever that call originates, including inside an air-gapped enclave with no network egress at all — but a call has to be pointed at it.

Most enterprises eventually need both coverage models. Which one you buy first depends on whether the immediate problem is employees using AI you cannot see, or applications and agents making calls you cannot prove you governed.

Feature Comparison

CapabilitySmartflowWitnessAI
Control pointInline on the model request path. Applications and agents call the gateway.Network level. "See AI activity across your entire network without relying on browser extensions or endpoint clients."
Coverage modelEvery call routed through the gateway, from any origin, including with no network egress.Every AI interaction that traverses the network, including native desktop applications, with no integration work.
DeploymentOn-premises, Kubernetes-native, air-gapped capable.SaaS. Data sovereignty addressed through "single-tenant isolation, customer-controlled encryption, executive privacy modes, and multi-region deployment." No on-premises or air-gapped deployment is documented.
Model routingRouting and failover across 37+ providers including local models.Routes "based on risk, cost, and purpose," steering sensitive queries to internal models and routine ones to cheaper options.
CachingMetaCache, a four-phase semantic caching engine using BERT-based similarity matching. Hit rates are workload-dependent.No response caching, semantic or exact-match, is documented.
Agent identityAIDA issues a cryptographic credential to the agent itself, scoped and revocable independently of its launcher.Inherited. "Every agent action maps back to a human identity," described as human-to-agent attribution.
MCP governanceMCP JSON-RPC gateway with tool caching, under agent identity.Organization-wide approved-tool lists of MCP servers "enforced at the network for every agent," which "cannot be re-enabled by a team admin or routed around by an agent switching providers." An MCP Catalog scores tools against OWASP and CVE risk classes.
Regulatory evidenceExamination packages and model inventory for FINRA 3110, HIPAA, SOX and the EU AI Act.Regional sandboxes with policies for standards such as PCI DSS 4.0.1. No product-level mapping to FINRA, HIPAA, SOX, NIST AI RMF or the EU AI Act is documented, and no examination package.
Audit retentionCustomer-controlled. No vendor-imposed ceiling.Audit record per blocked call with user, agent, tool and rule. No retention period is published.
Certifications—SOC 2 Type I and Type II.
PricingPlatform plus usage. Quoted.Published on AWS Marketplace: $180,000 for 1,000 users ($180/user), $60,000 for 2,500 agents ($24/agent), $300,000 for the model protection guardrail.

The coverage trade, stated honestly

WitnessAI's architecture is a genuine advantage in one specific situation, and it is a common one. An enterprise that wants to know what its twenty thousand employees are doing with AI right now — which tools, what data, how often — gets an answer from WitnessAI without asking a single application team to change a line of code. No SDK, no client, no integration backlog. For the shadow AI discovery problem, that is the shortest path that exists.

The constraint is inherent to the design. Governance reaches what crosses a routable network path. An agent running inside a VPC calling a model endpoint in the same VPC, a workload in an environment where traffic does not egress, a deployment inside an accredited enclave — these are exactly the places a regulated institution puts its most sensitive AI, and they are the places a network-layer control has the least purchase.

Smartflow inverts the trade. Nothing is discovered automatically; a call has to be pointed at the gateway. In exchange, coverage does not depend on network topology, and the control plane runs where there is no network to observe.

On-premises is not on the menu

WitnessAI is SaaS. Their own AWS Marketplace listing classifies delivery that way, and nothing on their site documents an on-premises or air-gapped option. Data sovereignty is addressed through single-tenant isolation, customer-controlled encryption keys, executive privacy modes and multi-region deployment.

That is a serious set of controls and it satisfies a large number of enterprises. It does not satisfy the ones whose requirement is not "encrypted and isolated" but "does not leave." For a defense program, or a bank whose model-risk perimeter forbids third-party transit of prompt content, this is where the evaluation ends rather than where the negotiation starts. AI sovereignty is the term procurement will use.

Who the agent is

WitnessAI is explicit that agent actions map back to a human identity, and they market it as a feature: human-to-agent attribution. It is the right instinct — knowing which person an autonomous action traces to is genuinely useful, and most products in this category do less.

The limit shows up in supervision. If an agent acts on a credential belonging to a person, the log names the person, and separating what the human did from what the agent did on their behalf becomes a reconstruction exercise. AIDA issues the agent its own credential, so the agent is a party in the record. That lets an agent be revoked without disabling an employee, and lets an information barrier be enforced against the agent as an entity.

Where WitnessAI is strong on agents is the MCP allow list: maintained organization-wide, enforced at the network, and — in their words — not something a team admin can re-enable or an agent can route around by switching providers. That non-bypassability argument is the best version of the network-layer case.

Evidence for a regulator

WitnessAI documents regional sandboxes with policies for standards such as PCI DSS 4.0.1, and publishes SOC 2 Type I and Type II. Their compliance page promotes an EU AI Act checklist and a PCI DSS resource as content rather than as product mappings, and no page names FINRA, HIPAA, SOX or NIST AI RMF as a capability.

So the compliance posture is vendor-attestation plus policy sandboxes, not evidence generation. Smartflow's examination suite produces the model inventory, the policy in force on a given date, and the per-agent supervision record as an artifact. For a firm whose next AI conversation is with an examiner rather than a security questionnaire, that is the distinction that matters.

Where WitnessAI is strong

Zero-integration coverage of employee AI use is the fastest time to first insight in this market, and it extends to surfaces a gateway structurally cannot reach — Windows 11 Copilot, Office 365, consumer tools in a browser. The FinOps story is well developed: route to a cheaper model where a cheaper model will do, and enforce downshifting at runtime. Pricing is published rather than negotiated into the dark, which is unusual here and worth something in a procurement cycle.

They raised $58M in January 2026, shipped Agentic Control in June, and name InComm Payments as a customer. For an organization whose first AI governance problem is visibility across the workforce, WitnessAI answers it directly and Smartflow does not compete on that axis.

When to choose Smartflow

  • The control plane must run inside the perimeter, including air-gapped, where no third-party transit of prompt content is permitted
  • Governing applications and agents, not only employees — including traffic that never crosses a routable network path
  • Agent identity: a credential held by the agent rather than inherited from a person
  • Examination evidence: FINRA, HIPAA and SOX artifacts produced from runtime records

Running both

These compose better than most pairs in this market, because they cover different halves of the estate. WitnessAI at the network for workforce AI use; Smartflow on the request path for applications, agents and anything inside the regulated perimeter. The cost is two policy surfaces to keep aligned. The benefit is that neither product is asked to cover the ground it was not designed for.

Common questions

Can WitnessAI be deployed on-premises? No on-premises or air-gapped deployment is documented. It is delivered as SaaS with single-tenant isolation and multi-region options.

Does WitnessAI require an endpoint agent? No, and that is a deliberate design choice — it operates at the network level with no browser extension or endpoint client.

Does WitnessAI give agents their own identity? No. Agent actions are attributed back to a human identity.

What does WitnessAI cost? Published on AWS Marketplace at $180 per user with a 1,000-user minimum, and $24 per agent with a 2,500-agent minimum.

Govern shadow AI · AI sovereignty · Model Context Protocol · Examination readiness · All comparisons

Verified against each vendor’s published documentation in September 2026. Vendor capabilities change. If something here is out of date, tell us and we will correct it.

WitnessAI sources: witness.ai and its product, control, observe, protect, for-developers, for-compliance, for-finops and about-us pages; the WitnessAI AWS Marketplace listing; and the January and June 2026 press releases on funding and Agentic Control.

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs