v2026.8.1 is out. The first full release: security-reviewed, hardened, and out of beta. What's new →
Solutions

Same gateway, 3 different first questions

The gateway does 1 thing: it sits between your applications and your AI services and gives you control over what crosses. What you care about first depends on which side of that you own.

Security and risk teams

You need to know what AI is running, enforce a control that genuinely blocks, prove it works against a named framework, and hand someone the evidence.

Shadow-AI inventoryOWASP-scored testingAudit evidence
Start here

Platform and infrastructure

You need it to be boring: 1 process to deploy, a latency budget it respects, blast-radius control when a provider misbehaves, and metrics without writing instrumentation.

One 37MB binaryCircuit breakersPrometheus · OTel
Start here

Agent and app builders

You need client auth to configure itself, tools scoped to what the agent actually calls, PII kept out of the provider, and a spend limit that stops a runaway loop.

OAuth DCRFail-closed toolsHTTP 402 budgets
Start here
Common ground

What everyone gets regardless

These are not tier-gated or role-specific. They are how the gateway works.

44 Capabilities Nothing held back behind a tier
$0 To run it No licence key, no metering
100% On your network No telemetry, no call home
Opt-in Every control Existing proxies keep behaving

Pick a starting point and run it locally

All 3 paths begin the same way: download it, start it, and create 1 proxy.