No prompt warehouse by default
The hosted ledger retains operational metadata, policy reasons, bounded tool names/types/MCP hosts, counts, cost, and timing—not prompt/response content, tool schemas, arguments, or results.
A secure enterprise AI gateway for centralized provider credentials, SSO, scoped workload keys, tenant-bound encryption, guardrails, and audit evidence.
Applications receive revocable workload keys rather than raw provider secrets. The gateway resolves tenant and policy context first, selects an eligible credential, and decrypts that credential only for the provider call. Operational telemetry is metadata-minimized by default.
Customer administrators and AI Gateway HQ staff use isolated identity tenants and explicit access boundaries.
Issue scoped virtual keys and bind policy, rate, budget, and environment controls to each one.
Write encrypted credentials with tenant and credential encryption context; never return the secret value.
Use OIDC, built-in roles, mandatory customer/staff MFA, and time-bounded support authorization.
Authorize bounded tool and MCP metadata at the model boundary without turning the gateway into an untrusted-code executor or retaining tool arguments and results.
Bind the request to an organization, workload, environment, user, and declared execution context.
Apply policy and local attack signals before any provider credential is decrypted.
Allow, deny, cap, reroute, or observe the request with a stable reason code.
Write authorized metadata for review without persisting prompt or response bodies by default.
The console identifies each upstream account and its health while provider secrets remain write-only.
The console identifies each upstream account and its health while provider secrets remain write-only.
Each control has an operating path, an owner, and evidence that can be reviewed without collecting prompt bodies by default.
The hosted ledger retains operational metadata, policy reasons, bounded tool names/types/MCP hosts, counts, cost, and timing—not prompt/response content, tool schemas, arguments, or results.
An owner can add OIDC or public SAML metadata, verify the Cognito provider, map exact external groups to fixed roles, and issue a connection-bound SCIM 2.0 credential without a support ticket. SAML metadata and signing keys are checked during lifecycle changes and on a bounded schedule; the console exposes hash-only fingerprints, key count, last attempt, and the exact fail-closed trust expiry. Provisioning can be paused independently from active-user login enforcement; SCIM groups cannot grant gateway roles. Custom roles are not currently included.
Production changes require infrastructure review, code and dependency scanning, active web security tests, software inventories, and signed release artifacts. Restore drills run in isolated environments and are reported as engineering evidence—not as a contractual recovery time or SLA. Independent penetration testing and formal assurance remain separate work.
Current controls provide identity, tenant, policy, cost, timing, and outcome metadata. Formal certification and customer-specific validation remain separate work.
Review security boundaries and current status Read the plain-language AI gateway guide Review live-request governance Use the 12-test enterprise evaluationClear answers for buyers, administrators, and security reviewers.
The console treats provider credentials as write-only. Runtime decryption is tenant-bound. Staff access must be separately authorized, although external penetration testing is still required before high-risk production use.
Yes. Organization owners configure tenant-pinned OIDC or SAML 2.0 sign-in, exact external-group-to-built-in-role rules, and connection-bound SCIM 2.0 user and group lifecycle from the console. SAML metadata and signing keys are checked during setup and on a schedule; only hash-and-expiry evidence is retained, overlapping rollover keys extend trust safely, and expired trust blocks login. SCIM login enforcement can require an active provisioned identity without allowing SCIM groups to grant roles. Owners can separately scope portfolio administrators and analysts to an entire portfolio, selected custom groups, individual approved PortCos, or an explicit combination. Custom roles, general delegated identity administration, access-review campaigns, and live third-party conformance evidence are not currently included.
No certification is claimed. The architecture and evidence model are being built toward later assurance work, but certification and regulated-use validation are still required.
Connect a provider credential, create a workload key, and begin in Observe mode. Move a tested rule to Enforce when your team is ready.