v2026.8.1 is out. The first full release: security-reviewed, hardened, and out of beta. What's new →
For security and risk teams

Evidence you can hand to an auditor, not a promise

You cannot govern what you cannot see, and you cannot claim a control works if it has never been tested. The gateway gives you an inventory, a control that actually blocks, and a way to prove both.

  • OWASP LLM Top 10
  • NIST AI RMF
  • SOC 2 · ISO 27001 · HIPAA · GDPR
The problem

What tends to keep you up

Nobody can list what AI is running

Models, MCP tools, and agents get wired in by whoever needed them. The inventory, if 1 exists, is a spreadsheet that went stale months ago.

Controls that have never been tested

A guardrail is configured, so the box is ticked. Whether it actually blocks a real jailbreak on a Tuesday afternoon is a different question.

Data leaving without a trace

PII and secrets ride out inside ordinary prompts. Nothing inspects the payload, so nothing records that it happened.

Audit evidence assembled by hand

When the auditor asks who accessed what, the answer lives across application logs, provider dashboards, and memory.

What you get

Six controls that answer those 4 questions

Shadow-AI discovery and inventory

A governed inventory built in-band from live traffic, not a questionnaire. Anything observed but never sanctioned is flagged automatically, with 15-minute auto-sync and WebSocket alerts.

Read the guide

A control that actually blocks

213 rules holding 1,100+ patterns, evaluated in a deterministic priority order, with real-time blocking rather than after-the-fact reporting. Move an asset to quarantined and it is denied at the proxy on its next request.

Read the guide

Proof that it fires

Guardrails evaluation runs 85 built-in attack cases across 14 categories against your actual deployment and scores the result against OWASP LLM Top 10 and NIST AI RMF. Run it before the audit, not after.

Read the guide

Leak detection, not just prevention

Canary tokens act as a tripwire: when a canary from 1 user or session surfaces in another, you hear about it. Sliding-window extraction defeats the obvious evasions.

Read the guide

Audit evidence as a first-class output

Auth events, authorization failures, data and config changes, privileged admin actions, and security events all emit structured audit records, browsable in the dashboard and replicable to your own database for retention.

Read the guide

Routed to where you already work

Alerts go to SIEM, SOAR, Slack, email, and webhooks, each with its own severity threshold, so this becomes another feed in your existing process rather than another console to watch.

Read the guide

Browse all 46 capabilities

Getting started

Your first half hour

Nothing here is irreversible, and every control is opt-in. You can run the whole sequence against a throwaway proxy before you point anything real at it.

  1. 01

    Start in monitor-only

    Create a proxy with a monitoring policy assigned. Nothing is blocked yet, so there is no risk to production traffic while you calibrate.

  2. 02

    Point 1 team at it

    Move a single team or API key onto the proxy. Within minutes the AI inventory starts filling in with the providers, models, and tools actually in use.

  3. 03

    Run a guardrails evaluation

    Point it at the endpoint you just proxied and run the built-in corpus. You get an OWASP and NIST-scored baseline of what your current controls do and do not stop.

  4. 04

    Turn on enforcement where it hurts

    Switch the policy to a blocking pack, set a budget cap, and enable redaction on the fields that matter. Then export the audit log and see what the evidence actually looks like.

See what is already running

Start in monitor-only and let the inventory populate itself. The uncomfortable part is usually how much it finds.