Gateway

Run your AI.
Prove every decision.

One governed API between your company and every AI model: routing, receipts, per-request residency selection, personal-data masking and cost control — applied per request, ready for the EU AI Act era.

ChatCopilotAgentAPIGatewayOpenAIAnthropicMistralGoogleOpen-weight
Receipts

A receipt for every answer.

Which model, why, what it cost, where the data went — logged to a named person, exportable as CSV or JSON. Certificates prove the platform; receipts prove your decision.

  • Allowed, redacted, denied, capped — every event on the record
  • Personal data can be masked before a provider sees it (rolling out)
Data protection

Sensitive data can be kept from providers.

Names, phone numbers and IDs can be detected and replaced with opaque tokens before a request leaves the Gateway — and put back in the answer before it reaches you, so the provider works on the masked text. This protection is rolling out.

  • Encrypted in transit and at rest; prompt content stored in EU Postgres
  • Every request tied to a named person and on the record
  • Provider credentials sealed per record; keys revocable one by one
Routing & cost control

Quality-first routing. Costs that stay within your caps.

Auto picks the best model your policy allows — never the cheapest — with automatic failover when a provider stumbles. Prepaid balance, per-project caps and rate limits mean requests pause at the cap instead of surprising you on an invoice.

  • One OpenAI-compatible endpoint in front of every model
  • Spend, requests and latency — visible, always
Territorial control

Residency applied when you select the tier.

Three residency tiers — EU-Strict, EU-Cloud, and an opt-in Global — applied on each request per the tier you choose, not promised in a policy PDF. Project-scoped API keys, created on demand and revocable one by one, keep integrations inside the same boundaries.

  • EU-owned infrastructure where rules require it
  • Keys identify systems; people are identified per request

Get the audit trail your DPO has been asking for.

Two-line integration. Governance from the first request.