Tutela Agentic Security by H2H - Runtime Security and AI Governance
H2H Technology · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Tutela Agentic Security by H2H gives security teams visibility and policy control over prompts, files, outputs, tool calls, usage signals, and autonomous actions before sensitive data moves. Approve AI adoption with runtime controls that prevent leakage, govern risky actions, and preserve evidence your security team can inspect.
Key Capabilities
Show the rest of the publisher’s description (26 more lines)
- Runtime AI Governance across four deployment patterns: Browser AI, Embedded AI, Enterprise AI Gateways, and Agentic/MCP Ecosystems
- Sensitive data leak prevention for AI workflows including prompts, files, outputs, API payloads, and tool calls
- Prompt, file, output, and tool-call inspection with granular policy enforcement
- AI usage and token-cost visibility connecting cost, model, app, user, and activity signals to governance records
- MCP trust validation and agent action governance for autonomous tool use
- Searchable audit trail preserving evidence for policy decisions, usage signals, exceptions, and agent actions
How It Works
Tutela sits at the runtime control points where prompts, files, outputs, APIs, tools, models, users, and sensitive data meet. Each pattern gets the same governance record: context, decision, action, and proof.
**Browser AI** - Govern employee use of ChatGPT, Claude, Gemini, Copilot, and other browser-based AI before prompts or files expose sensitive data.
**Embedded AI** - Inspect internal copilots, customer assistants, and SaaS applications that send business context to LLM APIs.
**Enterprise AI Gateways** - Standardize policy, visibility, and audit evidence across centralized model routing and internal AI platforms.
**Agentic and MCP Ecosystems** - Validate trust, govern tool use, and audit requested actions across agents, MCP servers, and connected assistants.
Customer-Owned Deployment
Tutela is designed for customer-owned deployment. Workflow inspection, usage records, policy decisions, and audit evidence stay under customer control. Sensitive context remains in the environment your team controls, ensuring governance data never leaves your operating model.
H2H offers a 60-day software evaluation window. Request a private offer today for your free evaluation. Early adopters can lock in significant multi-year discounts.
Who This Helps
Security, AI governance, IT, legal, finance, HR, sales, support, application security, and platform teams use Tutela to approve AI workflows, investigate incidents, and prove controls without blanket bans. Teams can adopt useful AI workflows without unmanaged workarounds.
Outcomes
- Let teams adopt useful AI workflows without blanket bans or unmanaged workarounds
- Stop sensitive prompts, files, outputs, API payloads, and tool calls before data leaves trusted paths
- Give security teams searchable evidence for policy decisions, usage signals, exceptions, and agent actions
- Connect AI usage, cost, model, app, user, and unusual activity signals to the same governance record
Policy Controls
Protection policies define active controls including coach, warn, redact, block, allow, or review actions for regulated data, prompt injection, payment data, and source-code protection. Each policy decision is preserved as reviewable audit context.
Getting Started
Review your active AI deployment patterns across Browser AI, Embedded AI, Enterprise AI Gateways, or Agentic and MCP ecosystems. Use technical guides and architecture material to align ownership boundaries, operating responsibilities, and commercial review before production use.
Highlights
Highlighted by the publisher on AWS Marketplace.
Runtime AI Governance across Browser AI, Embedded AI, Enterprise AI Gateways, and Agentic/MCP Ecosystems with granular policy enforcement for prompts, files, outputs, API payloads, and tool calls.
Customer-owned deployment keeps workflow inspection, usage records, policy decisions, and audit evidence under your team control while sensitive context remains in the environment you operate.
AI usage and token-cost visibility connects cost, model, app, user, and activity signals to governance records. MCP trust validation helps teams govern tool use and audit agent actions.
Preview
3 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Plans and pricing as listed
1 listed- Units
Refund terms
As stated by the publisher on AWS Marketplace.
The public offer is a paid annual subscription at the USD 125,000 list price and does not include a complimentary trial. Complimentary 60-day evaluations are available only through an H2H-issued AWS Marketplace private offer requested at https://tutelacloud.com/trial. AWS infrastructure, GPU, model download, storage, network, and data-transfer costs are paid by the buyer. Public-offer software charges are non-refundable except as required by law or approved in writing by H2H and AWS Marketplace.
Sources
Publisher resources
2 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

