Tenant-scoped authorization
Tenant context is mandatory across current data access, queue, encryption, audit, and policy paths.
See what is deployed, what remains contract-scoped, and exactly where customer and AI Gateway HQ responsibilities begin.
Tenant context is mandatory across current data access, queue, encryption, audit, and policy paths.
The hosted production cell uses KMS encryption context per tenant and credential. Plaintext is short-lived and excluded from telemetry.
Gateway code does not persist prompt/response bodies or tool schemas, arguments, and results. Events contain identity, route, policy, bounded tool names/types/MCP hosts, usage, cost, and timing metadata.
Protected GitHub OIDC deployments, signed release artifacts, reviewed infrastructure plans, CodeQL, dependency review, and release scanning gate production changes.
A sound architecture can reduce later rework, but certification is never merely administrative: sustained operations, evidence, remediation, legal review, independent testing, and audit work still matter.
Threat model, data inventory, least privilege, encryption, audit, incident response, backups, change evidence, vulnerability handling.
Penetration test, policy review, vendor assessment, evidence sampling, legal and insurance readiness.
SOC 2 audit program, BAAs where applicable, customer-specific mappings, contracted SLA, and private deployment review.
AI Gateway HQ operates a hosted production gateway with published pricing and Stripe-hosted self-service billing. Managed Amazon Bedrock is limited to reviewed U.S. conversational models and requires purchased credit plus a reusable payment method. AI Gateway HQ does not currently claim SOC 2 certification, HIPAA compliance, PCI certification, FedRAMP authorization, or a general-availability SLA. Those commitments require the applicable contracts, operations, independent testing, and audit work.