Incremental evaluation
Begin locally or in a non-sensitive test environment, inspect Observe decisions, and move tested policies to Enforce.
Observe, Shadow, Enforce, explicit workload context, metadata minimization, and AWS infrastructure as code form a baseline—not an authorization for government workloads.
AI Gateway HQ provides a versioned AWS infrastructure baseline, workload policy, budget controls, metadata minimization, and staged enforcement. Government authorization, offline operation, restricted-network packaging, supply-chain evidence, retention, and agency-specific controls remain separate requirements.
A government-ready package must define network, identity, artifact, key, support, logging, recovery, and change-management ownership.
Run pilots only in authorized environments with explicit data, provider, network, and account constraints.
Require signed release artifacts and automated infrastructure review. Customer-delivered offline bundles are not currently included.
Document identity, key management, logging, retention, incident, backup, and support responsibilities.
Use explicit workload and data-class context; never infer authorization from a model name alone.
Limit eligible providers, models, credentials, and telemetry before the request can leave the gateway.
Run the tested rule in Observe, Shadow, or Enforce according to the approved rollout stage.
Retain metadata evidence and administrative change history for authorized operational review.
Live API-backed counts for provider connections, routes, policies, requests, latency, and payload-storage posture.
Live API-backed counts for provider connections, routes, policies, requests, latency, and payload-storage posture.
Each control has an operating path, an owner, and evidence that can be reviewed without collecting prompt bodies by default.
Begin locally or in a non-sensitive test environment, inspect Observe decisions, and move tested policies to Enforce.
Customer-network data planes, signed artifacts, offline policy distribution, and local credentials require additional implementation and validation.
Capability status, dependencies, deployment boundaries, and missing assurance are documented instead of implied by badges.
Procurement and security reviewers receive a capability boundary rather than certification language or unsupported badges.
Review security boundaries and current statusClear answers for buyers, administrators, and security reviewers.
No. The current hosted service does not claim FedRAMP or another agency authorization.
Not as a generally available package today. Offline policy, signed artifacts, local credentials, upgrades, and support paths still require implementation.
Workload identity, provider pools, staged policy, budgets, metadata evidence, and the AWS infrastructure baseline can be evaluated using non-sensitive data in an authorized environment.
Connect a provider credential, create a workload key, and begin in Observe mode. Move a tested rule to Enforce when your team is ready.