AI Gateway
Every AI request through one door, supervised.
See and control how your organisation uses AI. A single point of control between your teams and the AI services they use — built from open-source, self-hosted components you can audit.
FIG. 01 — the sanctioned AI channel, logical view. Sensitive traffic never leaves your perimeter.
The problem
AI use in your organisation is already happening.
The question is whether it happens under your controls.
AI use is already happening
Your employees already use AI tools, with or without authorisation. Blocking fails quietly; blindness costs more.
Confidential data walks out
Contracts, client data, source code — any of it can end up in a public chatbot without anyone recording that it left.
No answer for the regulator
When a regulator asks who shared what data with which AI service, today there is no documented answer.
The control plane
Five checks. Every request. In order.
The gateway is a single supervised entry point — every request passes through each stage before it reaches any model.
-
Every request tied to a person
Identified users and teams, access keys per team. Only approved models are visible.
-
Sensitive data stopped at the door
PII masked. National ID and tax ID validated, not guessed. Prompt-injection attacks detected and blocked.
-
Sensitivity chooses the destination
Not the user, not habit, not convenience — the sensitivity of the request decides where it may go.
-
Budgets per team
Usage limits and spend caps per team. Spend is stopped before it becomes a surprise bill.
-
AI agents on a leash (phase 2)
Only allow-listed tools. Every action logged. A drift alarm fires if a tool changes behaviour.
Where questions can go
The sensitivity of the request chooses the destination.
Two permitted lanes, verified by policy. One route that no longer exists.
Non-sensitive lane
Approved cloud AI
A vetted commercial model under contract, in region. It receives only non-sensitive, already-masked traffic.
Sensitive lane
Sovereign AI — inside your organisation
An open-weights model on your own hardware with no internet connection. Nothing leaves the building. Sensitive questions end here, always.
Blocked
Public chatbots
Unreachable from the sanctioned channel — and no longer needed once every approved use has a supervised path.
Logical view — the design is location-independent. The gateway runs on a server, the sovereign model on your own hardware, and both can move fully on-premises without changes.
The evidence plane
Every request leaves a permanent trail.
Per-user activity review
Filter any interaction by person, team, or cost. The question "who asked what" has an answer.
Live dashboards
Spend per team, traffic per lane, blocked attempts — visible while it happens, not in next quarter's report.
Immutable audit log
Every interaction archived write-once and sealed by a hash chain. It cannot be altered afterwards.
Data residency
You decide where the records live.
Data-leak prevention filters sensitive information before it leaves your organisation, and you choose the jurisdiction where every record is processed and stored. What you can tell your regulator:
- “We know which AI services are used in the organisation, who uses them, and with what information.”
- “Sensitive data is filtered before it leaves; every attempt is recorded.”
- “We can hand over complete, verifiable evidence of every interaction, whenever it is requested.”
Questions
Common questions
What is an AI gateway?
A single supervised entry point between your teams and the AI services they use. Every request passes through identity checks, guardrails, policy-based routing, cost controls and — for AI agents — tool governance, and every request leaves a permanent audit record.
How does the gateway keep sensitive data inside our organisation?
Policy-based routing sends sensitive requests to a sovereign open-weights model running on your own hardware with no internet connection, so the data never leaves your perimeter. Non-sensitive, already-masked traffic may go to a vetted in-region commercial model under contract. Public chatbots are unreachable from the sanctioned channel.
What evidence can we show an auditor or regulator?
A per-user activity trail, live dashboards of spend and blocked attempts, and an immutable write-once audit log sealed by a hash chain — complete, verifiable evidence of every interaction, on request.
Where is the audit data stored?
You decide the jurisdiction in which records are processed and stored. The design is location-independent: the gateway runs on a server, the sovereign model on your own hardware, and both can move fully on-premises without changes.
Does the gateway cover AI agents as well as chat?
Yes — employees use a chat portal, internal applications call the gateway programmatically, and AI agents that use tools to take action are governed in phase 2 with allow-listed tools, per-action logging, and drift alarms.
More on the thinking behind supervised AI use: data residency, privacy, and auditable controls for organisational AI on the blog, and how it fits the DiaCero managed security platform.
Put AI use under your controls.
30-minute call with a senior engineer. We'll map where AI is already used in your organisation and what a sanctioned channel looks like.
Request a demonstration →