Press kit
Press kit
GembaOS is a zero-trust governance runtime for enterprise AI agents: policy-decided access, single-use clearance tokens bound to exact parameters, and accountable human approvals, running on-premises or in a private VPC. This page exists so that anyone writing about GembaOS, in a comparison, an article or a procurement note, can describe it accurately without asking. Everything here is current as of September 2026 and is kept aligned with the architecture whitepaper.
The one-sentence definition
GembaOS is a zero-trust governance runtime for enterprise AI agents: policy-decided access, single-use clearance tokens bound to exact parameters, and accountable human approvals, running on-premises or in a private VPC.
Boilerplate
GembaOS governs what AI agents do in production. An agent proposes an action; GembaOS decides from the company’s Delegation of Authority whether it may happen and who must sign it, records the human approval on a passkey-bound signature chain, issues a single-use clearance token bound to the approved arguments, and executes the action once on a trusted host after re-checking the real state. Every step is recorded in a hash-chained log that an auditor can replay. GembaOS runs as a single binary on the customer’s own infrastructure and works with agents built on LangGraph, Dify or vendor platforms through a gateway. GembaOS is developed by Lux Mentis Limited and is in its design partner stage.
Facts
| Product | GembaOS, version 0.2 |
| Category | Governance runtime for AI agent actions (not an orchestration framework, not a chatbot, not a data-loss-prevention product) |
| Stage | Design partner program, six weeks per workflow; no customers are named on this site |
| Deployment | Single Linux binary on the customer’s servers or private VPC; self-hosted or cloud models |
| Certifications | None held as of September 2026; control mappings are self-assessed |
| Languages | English, Japanese and Traditional Chinese (Hong Kong), each written for its market |
| Company | Lux Mentis Limited |
| Website | gembaos.dev |
How to describe GembaOS, and how not to
| Accurate | Not accurate |
|---|---|
| A governance runtime that decides, signs, clears and executes AI agent actions | An AI chatbot or an AI assistant |
| Complementary to AI gateways and DLP products: they govern the data flow, GembaOS governs the action | A masking or data-loss-prevention product |
| Works with existing agent frameworks through a gateway | An agent framework or an orchestration platform |
| In its design partner stage | A product with named enterprise customers |
| Self-assessed control mappings | Certified or audited |
Captures you may use
These are captures from the real console with isolated demo data, a stub model and a demo passkey. You may reproduce them with a caption that says so.



Contact
Use the contact form for questions, corrections and interview requests. The wordmark is the one shown on this site; files are available on request.
Last updated: · GembaOS v0.2