AI Gateway

Every AI request through one door, supervised.

See and control how your organisation uses AI. A single point of control between your teams and the AI services they use — built from open-source, self-hosted components you can audit.

FIG. 01 — the sanctioned AI channel, logical view. Sensitive traffic never leaves your perimeter.

The problem

AI use in your organisation is already happening.

The question is whether it happens under your controls.

AI use is already happening

Your employees already use AI tools, with or without authorisation. Blocking fails quietly; blindness costs more.

Confidential data walks out

Contracts, client data, source code — any of it can end up in a public chatbot without anyone recording that it left.

No answer for the regulator

When a regulator asks who shared what data with which AI service, today there is no documented answer.

The control plane

Five checks. Every request. In order.

The gateway is a single supervised entry point — every request passes through each stage before it reaches any model.

  1. Identity & access

    Every request tied to a person

    Identified users and teams, access keys per team. Only approved models are visible.

  2. Guardrails

    Sensitive data stopped at the door

    PII masked. National ID and tax ID validated, not guessed. Prompt-injection attacks detected and blocked.

  3. Policy-based routing

    Sensitivity chooses the destination

    Not the user, not habit, not convenience — the sensitivity of the request decides where it may go.

  4. Cost control

    Budgets per team

    Usage limits and spend caps per team. Spend is stopped before it becomes a surprise bill.

  5. Tool governance

    AI agents on a leash (phase 2)

    Only allow-listed tools. Every action logged. A drift alarm fires if a tool changes behaviour.

Where questions can go

The sensitivity of the request chooses the destination.

Two permitted lanes, verified by policy. One route that no longer exists.

Non-sensitive lane

Approved cloud AI

A vetted commercial model under contract, in region. It receives only non-sensitive, already-masked traffic.

Blocked

Public chatbots

Unreachable from the sanctioned channel — and no longer needed once every approved use has a supervised path.

Logical view — the design is location-independent. The gateway runs on a server, the sovereign model on your own hardware, and both can move fully on-premises without changes.

The evidence plane

Every request leaves a permanent trail.

Per-user activity review

Filter any interaction by person, team, or cost. The question "who asked what" has an answer.

Live dashboards

Spend per team, traffic per lane, blocked attempts — visible while it happens, not in next quarter's report.

Immutable audit log

Every interaction archived write-once and sealed by a hash chain. It cannot be altered afterwards.

Data residency

You decide where the records live.

Data-leak prevention filters sensitive information before it leaves your organisation, and you choose the jurisdiction where every record is processed and stored. What you can tell your regulator:

  • “We know which AI services are used in the organisation, who uses them, and with what information.”
  • “Sensitive data is filtered before it leaves; every attempt is recorded.”
  • “We can hand over complete, verifiable evidence of every interaction, whenever it is requested.”

Questions

Common questions

What is an AI gateway?

A single supervised entry point between your teams and the AI services they use. Every request passes through identity checks, guardrails, policy-based routing, cost controls and — for AI agents — tool governance, and every request leaves a permanent audit record.

How does the gateway keep sensitive data inside our organisation?

Policy-based routing sends sensitive requests to a sovereign open-weights model running on your own hardware with no internet connection, so the data never leaves your perimeter. Non-sensitive, already-masked traffic may go to a vetted in-region commercial model under contract. Public chatbots are unreachable from the sanctioned channel.

What evidence can we show an auditor or regulator?

A per-user activity trail, live dashboards of spend and blocked attempts, and an immutable write-once audit log sealed by a hash chain — complete, verifiable evidence of every interaction, on request.

Where is the audit data stored?

You decide the jurisdiction in which records are processed and stored. The design is location-independent: the gateway runs on a server, the sovereign model on your own hardware, and both can move fully on-premises without changes.

Does the gateway cover AI agents as well as chat?

Yes — employees use a chat portal, internal applications call the gateway programmatically, and AI agents that use tools to take action are governed in phase 2 with allow-listed tools, per-action logging, and drift alarms.

More on the thinking behind supervised AI use: data residency, privacy, and auditable controls for organisational AI on the blog, and how it fits the DiaCero managed security platform.

Put AI use under your controls.

30-minute call with a senior engineer. We'll map where AI is already used in your organisation and what a sanctioned channel looks like.

Request a demonstration →