For public-sector teams

Build a verifiable path to governed model access.

Observe, Shadow, Enforce, explicit workload context, metadata minimization, and AWS infrastructure as code form a baseline—not an authorization for government workloads.

Working sandbox capture
For public-sector teams controls in the working console.Current interface evidence: Artifact visible · Boundary honest · Change reviewable. This sanitized capture contains no customer secrets or prompt bodies.
Implemented organization and workload-key policy
Validated AWS deployment infrastructure as code
Current availability stated for hierarchy, offline bundles, private networks, and retention controls
In plain language

Establish a testable control baseline without implying an authorization.

AI Gateway HQ provides a versioned AWS infrastructure baseline, workload policy, budget controls, metadata minimization, and staged enforcement. Government authorization, offline operation, restricted-network packaging, supply-chain evidence, retention, and agency-specific controls remain separate requirements.

The readiness outcomeTeams can evaluate the governance model in an authorized non-sensitive environment while documenting every prerequisite for broader use.
For the operating team

Treat deployment boundary and update path as controls.

A government-ready package must define network, identity, artifact, key, support, logging, recovery, and change-management ownership.

What administrators configure
Environment boundary

Run pilots only in authorized environments with explicit data, provider, network, and account constraints.

Release path

Require signed release artifacts and automated infrastructure review. Customer-delivered offline bundles are not currently included.

Operations ownership

Document identity, key management, logging, retention, incident, backup, and support responsibilities.

What happens to each request
  1. 01
    Classify

    Use explicit workload and data-class context; never infer authorization from a model name alone.

  2. 02
    Restrict

    Limit eligible providers, models, credentials, and telemetry before the request can leave the gateway.

  3. 03
    Operate

    Run the tested rule in Observe, Shadow, or Enforce according to the approved rollout stage.

  4. 04
    Review

    Retain metadata evidence and administrative change history for authorized operational review.

See the working control

One place to see whether the control is actually in place.

Live API-backed counts for provider connections, routes, policies, requests, latency, and payload-storage posture.

  • Rendered by the real customer console and control API
  • Exercised with safe OpenAI- and Anthropic-compatible simulators
  • Sanitization gate rejects credential-shaped values and private owner email
Follow the operating workflow
Operating overviewOne place to see whether the control is actually in place.

Live API-backed counts for provider connections, routes, policies, requests, latency, and payload-storage posture.

Control surface

Useful on day one. Explainable on day one hundred.

Each control has an operating path, an owner, and evidence that can be reviewed without collecting prompt bodies by default.

01

Incremental evaluation

Begin locally or in a non-sensitive test environment, inspect Observe decisions, and move tested policies to Enforce.

02

Restricted-network package is not currently available

Customer-network data planes, signed artifacts, offline policy distribution, and local credentials require additional implementation and validation.

03

Procurement transparency

Capability status, dependencies, deployment boundaries, and missing assurance are documented instead of implied by badges.

Evidence, not assertions

Show current implementation and missing authorization work separately.

Procurement and security reviewers receive a capability boundary rather than certification language or unsupported badges.

Review security boundaries and current status
  • Reason-coded policy, route, retry, fallback, and denial metadata
  • Bounded tool names, types, MCP hosts, and authorization outcomes—without schemas, arguments, or results
  • Provider-reported usage reconciliation for complete responses and supported terminal streams
  • Tenant-bound credential encryption and fail-closed tenant authorization
  • Signed, retryable administrative audit delivery with payloads and configuration snapshots excluded
  • Clear labels separating available controls from items that still require validation
Questions teams ask

Know the boundary before you deploy.

Clear answers for buyers, administrators, and security reviewers.

Does AI Gateway HQ have a government authorization?

No. The current hosted service does not claim FedRAMP or another agency authorization.

Can it run in a restricted or disconnected network?

Not as a generally available package today. Offline policy, signed artifacts, local credentials, upgrades, and support paths still require implementation.

What can be evaluated now?

Workload identity, provider pools, staged policy, budgets, metadata evidence, and the AWS infrastructure baseline can be evaluated using non-sensitive data in an authorized environment.

Start safely

See what the policy would do before it can block production.

Connect a provider credential, create a workload key, and begin in Observe mode. Move a tested rule to Enforce when your team is ready.

Start guided setup