Constrain data paths
Policies filter configured provider/model routes before a credential is decrypted or request is sent.
Centralize credentials, enforce model boundaries, integrate OIDC identity, and retain metadata-only policy evidence.
The gateway does not eliminate shadow AI by itself. It gives approved applications and agents a safer path: centralized provider credentials, workload identity, model and data-class policy, local attack signals, budget limits, and reason-coded evidence.
Preventive controls act locally before provider forwarding. Metadata-only administrative events can leave through signed generic HTTPS delivery; native SIEM, DLP, ticketing, and lifecycle adapters retain explicit availability labels.
Require tenant, workload, environment, client mode, and user context before any route is considered.
Evaluate built-in attack, secret, and PII signals plus organization-specific RE2 formats in Observe or Enforce mode; redact or block response matches without retaining payloads.
Use a distinct staff identity plane and customer-authorized, time-bounded support access.
Send HMAC-signed administrative event metadata to up to five customer-owned HTTPS receivers with at-least-once retries, evidence, and replay—without exporting prompts, responses, secrets, snapshots, or tool payloads.
Bind the request to an organization, workload, environment, user, and declared execution context.
Apply policy and local attack signals before any provider credential is decrypted.
Allow, deny, cap, reroute, or observe the request with a stable reason code.
Write authorized metadata for review without persisting prompt or response bodies by default.
The live ledger shows workload, route, reason code, upstream attempt, outcome, latency, configured cost, and audit-chain integrity.
The live ledger shows workload, route, reason code, upstream attempt, outcome, latency, configured cost, and audit-chain integrity.
Each control has an operating path, an owner, and evidence that can be reviewed without collecting prompt bodies by default.
Policies filter configured provider/model routes before a credential is decrypted or request is sent.
Prompt and response bodies are not retained by default; telemetry settings are explicit.
Control mappings support later SOC 2, HIPAA, and regulated-customer reviews without inventing unsupported claims today.
Security reviewers can inspect identity, policy, route, timing, cost, and outcome metadata while prompt persistence remains off by default.
Review security boundaries and current statusClear answers for buyers, administrators, and security reviewers.
The current runtime includes configurable local pre-forward attack signals, tenant-defined bounded patterns, and Observe or Enforce modes. Response controls can detect, redact, or block built-in secret and PII formats plus organization-specific formats. These layers complement—not replace—provider safety controls and application validation.
Customer and staff identity pools are separate. Support access is designed to require explicit, time-bounded authorization rather than routine customer impersonation.
Not yet. Automated security gates and AWS perimeter controls are implemented baselines, but independent penetration testing remains a production assurance gap.
A generic signed HTTPS audit webhook is implemented for administrative event metadata. Native Splunk HEC, Sentinel, Chronicle, Datadog, object-storage, and syslog adapters are not currently included; do not treat the generic receiver as native integration certification.
Connect a provider credential, create a workload key, and begin in Observe mode. Move a tested rule to Enforce when your team is ready.