ColleaiQ logo
Agents Orchestration Frameworks · Guardrails Policy

ColleaiQ

ColleaiQ is a neurosymbolic runtime that binds every AI agent action to a symbolic policy layer before it executes, so each decision traces back to a named rule. Built in Copenhagen for regulated work, deployed EU-sovereign or on-premises.

Active GDPR compliant Contact Sales No public API Verified by Guidaio
Overview

What is ColleaiQ?

ColleaiQ is a neurosymbolic runtime for governed multi-agent AI, built by ColleaiQ ApS in Copenhagen. The company was registered in the Danish business register on 28 May 2025 (CVR 45651053) to develop, market and sell artificial-intelligence products and services. The runtime is a coordination layer placed between the LLMs and tool servers a customer already runs and the policies its operation has to satisfy.

Three named components do the work. A planner proposes each agent's next action. A symbolic policy kernel checks that proposal against the rules the customer has loaded — the vendor's own analogy is the way an OS kernel checks every syscall. A trace surface then writes a structured record. Rules compile into a symbolic graph consulted before every tool call, and each trace is pinned to the policy version that produced it.

Five elements are recorded per action: the agent utterance (proposed action plus reasoning chain), the policy applied (rule and signed version), the evidence captured (inputs seen, sources consulted, tool responses), the human review (reviewer identity where policy required one), and the outcome (taken, blocked or held, with timestamp and trace ID). A session keeps a roster of agents with declared capabilities, the planner picks the next one, and hand-offs between agents are explicit and logged with the rule that authorised them. Agents are read-only by default; authority to change state is granted action by action.

The runtime is deliberately LLM-agnostic — OpenAI, Anthropic, Mistral or self-hosted — and switching provider does not change the traces. It leans on the existing stack: OIDC and SAML through the customer's identity provider, secrets in the customer's vault, tool servers exposed over MCP or REST.

Three deployment models are offered: EU-sovereign cloud inside the customer's own tenant, on-premises or air-gapped inside their perimeter, and partner-managed white-label. SaaS is explicitly ruled out; the product is built for environments where SaaS is not an option.

One domain is in production: manufacturing, at ProPlast, where quality, maintenance and process agents are coordinated on a line in service. Cybersecurity and legal review are announced as engine capability but not yet shipped. The team is four people in Copenhagen, plus one advisor.

What it does

  • Plans each agent's next action through a neurosymbolic planner
  • Checks every proposed action against the loaded rules before it executes
  • Blocks non-compliant actions with a signed rejection that cites the rule, instead of failing silently
  • Writes a structured trace per action: proposal, rule applied, evidence, human review, outcome
  • Replays past traces against a newer policy version to show which decisions would have changed
  • Coordinates several specialised agents across one workflow, with explicit and logged hand-offs
  • Gates every state-changing action behind allow-lists, role permissions and dual control
Audience

When to use ColleaiQ / When not to

A quick filter to help you decide if ColleaiQ is the right fit.

When to use ColleaiQ

  • Operators of regulated processes who want AI agents to run under an explicit, machine-checked rulebook
  • Compliance, audit and risk teams that must produce evidence of what an automated action did and which rule allowed it
  • Organisations where SaaS is ruled out and data must stay inside their own perimeter or their own cloud tenant
  • Manufacturing teams coordinating quality, maintenance and process agents on a live production line
  • Engineering teams that already run LLMs, tool servers, an identity provider and a secrets vault, and want a governance layer between them

When not to use ColleaiQ

  • Teams looking for a self-service product: there is no online sign-up, no trial and no published price
  • Buyers expecting the vendor to write their rules — ColleaiQ enforces the policies you load, it does not generate them
  • Organisations shopping for a compliance certification: the vendor states it certifies no operation against any framework, it only produces the trace artefacts an auditor uses
  • Developers wanting a documented public API, a mobile app or an open demo environment, none of which exist
  • Security operations or legal review teams that need something usable today: both domains are labelled engine capability, not yet shipped
Get started

How to use ColleaiQ

A typical end-to-end flow, from setup to results.

  1. Expect no self-service start: the site has no sign-up button, no free trial and no download
  2. Write down the workflow you want to govern and the rulebook it has to satisfy — the vendor asks for both up front
  3. Reach the team through the contact form (name, organisation, workflow, policy framework, preferred contact) or by emailing the founders directly
  4. Wait for a founder's reply, promised within 48 hours
  5. Take the 30-minute first call, which walks through the workflow you described
  6. If there is a fit, move to a design-partner pilot; only a limited number run at any one time, and the founders operate them themselves
  7. Pick a deployment model: EU-sovereign cloud in your own tenant, on-premises or air-gapped, or partner-managed
  8. Bring your own LLM provider, tool servers over MCP or REST, your identity provider (OIDC/SAML) and your secrets vault
  9. Load your own policies — the runtime enforces a rulebook, it never writes one
  10. Have your engineering teams replay past traces against updated policies to see which earlier decisions a new rule would have changed
Quick read

Pros & Cons

Pros

  • Control happens before execution: the policy blocks the action rather than reporting it after the fact
  • Refusals are explainable — a signed rejection citing the rule, not a silent failure
  • Traces can be replayed against a later policy, so you can see which past decisions a new rule would have changed
  • EU data residency with no US transfer, customer-owned keys and audit logs, and an on-premises or air-gapped option where nothing may leave
  • Independent of the LLM provider: changing vendor does not change the trace format
  • Slots into the existing stack — identity provider, secrets vault, tool servers — instead of replacing it
  • Unusual candour for a young vendor: a published LIMITS section, a dated and versioned privacy policy with a single named subprocessor, and a named production customer rather than an anonymous logo

Cons

  • No public pricing and no pricing page at all: the cost only emerges in conversation with the vendor
  • No terms of service published — the complete 13-URL sitemap contains none
  • No public API documentation and no openly accessible demo
  • Only one domain actually in production; cybersecurity and legal review remain unshipped engine capability
  • A single named production customer, and a deliberately limited number of design-partner pilot slots
  • Very young company, registered on 28 May 2025, with a four-person team; the founders run the pilots personally, and the domain's first Wayback capture is 16 January 2026
  • One contact channel, the CEO's own address, with no structured support; no security certification (SOC 2, ISO 27001) is claimed and nothing is published about model training on customer data or an opt-out
Pricing

Pricing & Plans

No price is published. ColleaiQ operates no pricing page — an absence confirmed against the site's complete 13-URL sitemap — and names no plan, tier or rate card anywhere. No free plan and no free trial are announced, so no lowest price point and no currency can be quoted. The commercial route is a conversation followed by a design-partner pilot available in limited numbers, which means any figure has to be obtained directly from the vendor.

No priced plan is published
  • the site names no tier
  • package or rate card
  • and no amount or currency appears anywhere
Deployment model, not a priced offer — On-prem / air-gapped
  • inside your own perimeter
  • with no implicit access to data
  • a signed update channel
  • and hardening and deployment packs. Positioned for regulated operations with on-site data
Deployment model, not a priced offer — Partner-managed (white-label)
  • delivered by a managed-service partner with multi-tenant isolation. The partner owns the customer relationship
  • ColleaiQ owns the governance kernel. Positioned for regional scale
  • partner-operated
Special offers — No promotion, discount or promo code is advertised anywhere on the site · For students and researchers: thesis and PhD collaborations of six to nine months on bounded problems — neurosymbolic planning, multi-agent coordination, policy-aware learning — with occasional co-authorship · A limited number of design-partner pilot slots is open at any one time; no pricing terms attached to either engagement are published
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how ColleaiQ handles your data.

GDPR overview

GDPR is addressed in acts rather than slogans. The privacy policy is dated Last updated: June 2026 and versioned (v1.0, June 2026, initial publication). It names the legal bases used — Article 6(1)(b) for pre-contractual steps and contract performance, Article 6(1)(f) for server logs — and lists the Articles 15 to 22 rights: access, rectification, erasure, restriction, portability, objection, and not being subject to an automated decision. Complaints can be lodged with the Danish Data Protection Authority (Datatilsynet). Rights are exercised by emailing christofferdreist@colleaiq.dk with the subject GDPR request: acknowledgement within 48 hours, substantive answer within the 30-day legal deadline, free for a first request in any twelve months. No Article 27 representative applies, the company being established in Denmark, and no DPO is named. Material changes are flagged with a revised date, and pilot customers get 30 days' notice.

Who owns the data?

No terms of service are published, so the privacy policy is the only source. Website and mailbox data sits with Simply.com in Denmark, and access is limited to ColleaiQ staff; the vendor states it never sells, rents or shares personal data with any third party for advertising, profiling or analytics. Pilot data — documents, traces, verdicts — is separate, governed by the pilot agreement, which sets where it is stored and who may reach it. Deployment is framed as your choice, your data, your keys, with customer-owned keys and audit logs and no implicit vendor access on-premises. Court orders are challenged where justified, and the person notified unless the law forbids it.

Reuse rights

With no terms of service published, the privacy policy is the only statement of use. Two categories are collected and nothing else: the emails you send (name, organisation, message content, reply thread) and standard server logs (IP address, timestamp, page requested). The contact form simply opens a message in your own mail client, so it arrives as an ordinary email. The legal bases are Article 6(1)(b) for pre-contractual steps taken to answer you, then contract performance once a pilot agreement is signed, and Article 6(1)(f) legitimate interest for the logs, used only for site security and operation, never for profiling. The site runs no analytics product, sets no tracking cookies, and performs no behavioural profiling, cross-site tracking or advertising pixels; local storage holds only two preferences, the light or dark theme and your answer to the cookie banner. Nothing is published either way about whether customer data is used to train models, so no reuse right can be inferred in either direction.

Data retention & training

Retention summary
Emails sent to the vendor are kept for the duration of the engagement plus up to twelve months of follow-up, then deleted. Pilot data is governed by the pilot agreement, and the stated default is that all customer data is returned and destroyed within thirty days of the engagement closing. Standard server logs are retained by the hosting provider with no published number of days, and are used only for site security and operation. No retention period is published for the traces the runtime produces inside a customer's own environment, which sit with the customer under the pilot agreement rather than with the vendor.
Subprocessors disclosed
Yes
DPA available
Yes

Hosting summary

Two perimeters must be kept apart. The vendor's own infrastructure — this website and its email — runs at Simply.com, a Danish host, with data in the EU; the domain's IP address (94.231.106.113) geolocates to Aarhus, Denmark, on AS48854 team.blue Denmark A/S. Customer and pilot data is a different matter and does not sit in Denmark by default: it lives wherever the chosen deployment model puts it. Three models are offered — EU-sovereign cloud inside the customer's own tenant, with EU data residency, no US transfer and customer-owned keys and audit logs; on-premises or air-gapped inside the customer's perimeter, with no implicit vendor access and a signed update channel; or delivery through a managed-service partner. The pilot agreement fixes where pilot data is stored and who may reach it, and the stated default is that it stays in the customer's own region. No hosting country outside the EU is mentioned anywhere on the site.

Hosting countries
🇩🇰 Denmark
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting ColleaiQ.

  • No public pricing at all: the cost only surfaces in conversation, after a 30-minute first call, which makes budgeting before contact impossible
  • No terms of service are published, so the contractual framework becomes visible only when a pilot agreement is on the table
  • Cybersecurity and legal review are displayed as engine capability with the explicit note not yet shipped — they must not be read as available offerings
  • The vendor certifies nothing against any framework: it produces trace artefacts, and your auditor still does the rest. Policies are not supplied either, so writing and maintaining the rulebook stays your work
  • One production deployment at one manufacturer, a four-person company created in May 2025 and a deliberately limited number of pilot slots: concentration and continuity risk deserve a hard look
  • No security certification such as SOC 2 or ISO 27001 is claimed, and nothing is published about model training on customer data or an opt-out
  • Automation complacency is the human risk: because every action arrives with a policy citation, reviewers can drift into approving whatever looks pre-sanctioned. The runtime only enforces the rulebook you loaded, gaps and errors included
Setup

Setup & Integrations

Technical difficulty

High. There is no self-service start: no account, no trial, no download. The runtime installs inside your own infrastructure — an EU-sovereign cloud tenant, a VPC, or on-premises and air-gapped — and you bring the LLM provider, tool servers over MCP or REST, an identity provider (OIDC/SAML) and a secrets vault. The bigger prerequisite is not technical: you need an existing rulebook, since policies are loaded, not generated. Hardening and deployment packs come with on-premises, a hardened reference architecture with the sovereign cloud, and the founders run pilots themselves. This targets engineering teams, not end users.

Deployment

Web app

Integrations

OpenAI Anthropic Mistral
Company

Behind ColleaiQ

Company name
ColleaiQ ApS
Founded
28/05/2025
Country of origin
🇩🇰 Denmark
Headquarters
Copenhagen, Denmark
UBO
Martin Christoffersen (via TETZSCHNER AI HOLDING ApS, 33.33-49.99%), Mikkel Romvig Grongard (via ROMVIG AI HOLDING ApS, 33.33-49.99%)
UBO country
🇩🇰 Denmark
Domain registrar country
🇩🇰 Denmark

Fundraising

No funding round has been announced: none on the site, and none found by targeted web search
Registered share capital at the Danish business register (CVR 45651053): DKK 20,000, paid up in cash at incorporation on 28 May 2025, with no increase recorded since
A <i>Supported by</i> banner runs on every page with eight logos — DTU, DTU Skylab, SagaLabs, Google for Startups, Copenhagen Fintech, DIREC, Mikrolegat and Scaleway. These are support programmes and ecosystem backers, not announced investors
Registered ownership is three personal holding companies belonging to the three co-founders; no external investor appears on the register

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does neurosymbolic runtime mean here?
An LLM's reasoning is paired with a symbolic policy layer and a structured knowledge graph. The neural side proposes the next action; the symbolic side applies the rules.
When is policy actually checked?
Before the action executes. The vendor's analogy is an operating-system kernel checking every syscall, so it is a gate rather than an after-the-fact audit.
What happens when an action is refused?
It is blocked by a signed rejection that cites the rule which stopped it, rather than failing silently.
What does a trace record?
Five things per action: the proposed action and its reasoning chain, the rule applied with its signed policy version, the evidence captured, the human review where policy required one, and the timestamped outcome with a trace identifier.
Can a trace be replayed later?
Yes, against later policy versions, so you can see which past decisions a new rule would have changed.
Do we have to change LLM provider?
No. The runtime is provider-agnostic — OpenAI, Anthropic, Mistral or self-hosted — and switching does not change the traces.
Where do the data run?
In an EU-sovereign cloud inside your own tenant, on-premises or air-gapped inside your perimeter, or with a managed-service partner. The sovereign model states EU data residency with no US transfer, and keys and audit logs stay with the customer.
Does ColleaiQ write the policies?
No, you load them. The vendor states plainly that it does not generate policies and does not certify your operation against any framework; it generates the trace artefacts your auditor uses.
Is there a public price?
No. There is no pricing page at all. The way in is a conversation, then a design-partner pilot offered in limited numbers.
What is actually shipped today?
Manufacturing is in production at ProPlast, coordinating quality, maintenance and process agents on a line in service. Cybersecurity and legal review are presented as engine capability, not yet shipped.
Conclusion

Should you pick ColleaiQ?

ColleaiQ is unusually clear about its own perimeter, and that clarity is its main asset. It governs what AI agents are allowed to do; it does not write your policies and it certifies nothing. The differentiation is easy to state: the check happens before execution rather than in a report afterwards, refusals cite the rule that caused them, and traces can be replayed against a later policy to reveal which past decisions a new rule would have changed. For an operation answerable to a regulator, that is worth more than a dashboard.

Credibility rests on things most early-stage vendors leave out: a named production customer, a dated and versioned privacy policy naming a single subprocessor, and a published LIMITS section in which the vendor itself lists what the runtime will not do. The deployment story matches the pitch — EU data residency with no US transfer, on-premises or air-gapped where nothing may leave, keys and audit logs owned by the customer.

The reservations are equally plain. The company was registered on 28 May 2025 and has four people, who run the pilots themselves. There is no public price and no terms of service, so the commercial and contractual framework only appears once a pilot agreement is on the table. One domain is genuinely shipped: manufacturing. Cybersecurity and legal review are marked as engine capability, not yet shipped, and should be read that way. No security certification is claimed, and nothing is said about training on customer data.

The way in is a conversation and then a design-partner pilot, not a trial. If you already run LLMs and tool servers under a written rulebook, the 30-minute call is worth taking. If you hoped to sign up and try it this afternoon, this is not that kind of product.