We build AI companies
and we keep them.
Maluti Corp is an AI venture studio and holding company. We develop AI products in-house, take them to market, and hold stake in the ventures that result — operating across South Africa and the United States.
A studio, a holding company,
and an engineering doctrine.
Most AI businesses pick one of three shapes. A consultancy sells hours. A product company sells one thing. A fund buys into other people's work. Maluti Corp is built as all three at once — and that only works because the ventures share an architecture, a compliance posture and a standard of proof.
Nine products currently sit in the portfolio, spanning education, finance, financial inclusion, agriculture, audience analytics, security, legal, revenue and organisational design. One is live in production; the others are in build. Every one of them inherits the same four commitments: sovereign-ready deployment, bespoke engineering, evidence over assertion, and a human holding the consequential decision.
and held
ZA · US
across the portfolio
engineered for
Two markets, chosen on purpose.
The pairing is not incidental. South Africa provides the hardest constraints — regulatory, infrastructural and economic — and constraints make better products. The United States provides the scale to prove them.
South Africa
Products are engineered against POPIA from the outset, hosted in POPIA-friendly regions, and priced for South African economics — an entire exam platform running on a ~R209/month VPS with serverless inference measured in fractions of a cent.
The market forces problems most AI companies never have to solve: intermittent connectivity, thin credit files, expensive bandwidth, and sectors — education, lending, agriculture, security — where getting it wrong has consequences that a dashboard cannot absorb. Ventures here are regulated under frameworks including POPIA, the National Credit Act and South African Reserve Bank requirements.
United States
The agent-native platforms — Legal AI, the Agentic Revenue Acceleration Engine, and Form — are built for buyers who already run a system of record and need a judgement layer above it, with the forecast credibility and audit trail that a CFO or general counsel will actually stand behind.
Legal AI is grounded in United States court records via CourtListener and packaged single-tenant for firms that cannot let client files leave their own infrastructure. Employee and customer data across the portfolio is handled to the strictest common denominator of GDPR, POPIA and CCPA.
How a nine-venture portfolio
runs without nine platform teams.
Shared architecture
Every product is assembled from the same four layers — substrate, verification, judgement, experience. A guardrail written for one venture is available to the next. An event-sourced graph built for revenue is the same primitive that powers org design. The marginal cost of venture ten is a fraction of the cost of venture one.
Shared compliance posture
Data-protection work is done once, at the holding level, and inherited: consent, export and delete flows; PII masking and egress control; pseudonymised identifier options; tenant isolation; and a standing rule that customer data is never trained on without explicit opt-in. Sector-specific obligations sit on top of that base, not instead of it.
Capital efficiency as a design constraint
The portfolio is deliberately built to be cheap to run before it is expensive to scale. Serverless inference where elasticity wins, edge processing where bandwidth is the constraint, open weights where isolation is the constraint. A hundred-learner pilot on AceirMatric costs single-digit dollars a month. That is a strategy, not an accident.
Equity, not invoices
Maluti Corp holds stake in the ventures it develops rather than billing for the work. That aligns the incentive with the outcome: a product that is genuinely deployable, in a market that genuinely pays, run by a company that is still there in year five.
The lines we do not cross.
These are operating constraints, written into the products rather than into a policy document nobody reads.
A human holds the consequential decision
Supervision reports what footage is consistent with — never intent or identity — and is designed for human confirmation before any response is dispatched. Poultry AI ranks risk but never declares a veterinary diagnosis. Legal AI's output is not legal advice and requires attorney review. Agentic platforms are advisory in v1 and write back to nothing.
The model does not grade itself
Verification is deterministic code, not a second model asked politely. Citations are checked against real records; quotes matched against real text; alerts corroborated across independent signals; preflight gates hard-block a pipeline rather than warn about it.
Evidence travels with the recommendation
Every alert carries its contributing signals and confidence. Every proposal carries the data and reasoning behind it. Every model call logs prompt version, tokens, latency and cost, attributable and reproducible after the fact. Forecasts are versioned so accuracy can be measured, not asserted.
Data minimisation is the default
Employee and customer data is treated to the strictest common denominator across GDPR, POPIA and CCPA — minimisation, pseudonymised identifiers where names are not required, tenant isolation, regional hosting, and no training on customer data without explicit opt-in.
Open items are published, not hidden
Where a compliance objective is not yet fully met, it is tracked as an open item and stated plainly — AceirMatric's inference still leaving South Africa is on the record precisely because it is being closed.
Deployment posture is the customer's call
Sovereign or managed, on-premise or regional, local inference or serverless. We do not require a customer to accept an architecture their regulator, board or clients would not accept.
Two families of venture.
Applied AI products
Built end-to-end for a specific vertical, owning the whole workflow from data capture to interface.
- AceirMatric — education
- ZarloPay — cross-border finance
- microlendr — financial inclusion
- Poultry AI — agriculture
- Behavioural Engine — audience analytics
- Supervision — security
Agent-native & verification-led platforms
A judgement layer above an existing system of record, launching read-only and advisory.
- Legal AI — plaintiff-side research and evidence
- Agentic Revenue Acceleration Engine — pipeline and forecast
- Form — organisational design
Shared traits: event-sourced graphs, goal-holding agents, evidence trails, versioned outputs, and human approval gates written into the domain model.
Partner, pilot,
licence or build.
Tell us the decision you need to get right, and we will tell you honestly whether something in the portfolio fits.