● GOVERNANCE & OBSERVABILITY

AI you can put in front of a regulator.

A governed gateway sits between your teams and every model provider — enforcing policy, keeping regulated data on infrastructure you choose, controlling access, and recording an auditable trace of every single request.

Six domains, governed in one place.

Policy & governance

Central policies decide which models, providers, and regions a team may use. Define them once and every key inherits them — no shadow AI, no ungoverned calls.

  • Allow / deny lists per model & provider
  • Per-key and per-team spend caps
  • Default strategy enforced org-wide

Compliance & data residency

Choose which models and endpoints your keys may use, and control what gets logged. Data-residency routing is on the roadmap.

  • Region-pinned routingComing soon
  • PII-aware request classificationComing soon
  • Retention windows you control

Security

Bring your own provider keys; we store them encrypted and never expose them to clients. Inputs and outputs pass through guardrails before they reach a model.

  • Encrypted BYOK secret storage
  • Input / output guardrails
  • TLS 1.3 in transit, AES-256 at rest

Access controls (RBAC)

Least-privilege by default. Roles scope who can issue keys, edit routing rules, view spend, or read traces — so the right people hold the right surface.

  • Role-based permissions
  • Scoped, rotatable API keys
  • Team & workspace isolation

Traceability

Every request carries an end-to-end trace: which rule fired, which model served it, which fallback kicked in, latency, tokens, and cost — fully reconstructable.

  • Per-request distributed traces
  • Routing decision lineage
  • Cost & latency attribution

Audit

An append-only log of who changed keys, budgets and policies, and when — for investigations, access reviews, and the evidence auditors ask for.

  • Append-only audit log
  • Exportable to your SIEMComing soon
  • Access-review ready

Bring AI under control.

Start with policy and audit on day one, or talk to us about dedicated capacity for regulated workloads.