New Sign up free, 10 calls on us. Up to $1, no card needed.

Control the spend.Protect the data.Keep the proof.

Budgets, allowances and approvals control the spend. Guardrails and data classification protect the data. A tamper-evident audit log of every console change keeps the proof. It runs as a managed dedicated instance or inside your own network.

Approvals Three requests are waiting on you. Team budget $300.00 a day.
  • Emily Carter Daily allowance $20.00 → $50.00 · quarterly contract extraction Asked twice before, both approved · the team has $248.00 of $300.00 left
    Escalates in 4h Decline Approve
  • Jason Miller Access to claude-opus-5 · 30 days First time asking · spent $4.10 yesterday against a $20.00 allowance
    Decline Approve
  • Sarah Brooks Daily allowance $20.00 → $400.00 Above the team's $300.00 a day, so approving sends this to an admin
    Goes to an admin Decline Approve

Know what your company uses AI for

The gateway classifies every call by intent: coding, analysis, writing, lookup, leisure or other. Nobody fills out a form. Spend is shown by team and by intent at list price, so Finance and Engineering see the same number.

  • Logs: one row per call. Open it for the routing decision, the guardrail hits and the cost.
  • Where bodies are retained, nobody reads a prompt without a time-limited review grant, and every read lands in the audit log.
  • Exports send every request record to S3 or an OTLP collector.
Teams × intents This month, at list price
Team Intent mix Spent / budget
R&D Coding 72% $4,812 / $8,000
Sales Writing 46% $3,960 / $4,500
Support Writing 38% $3,120 / $6,000

See it

Spend by team, model and key, split by intent, with the month-end forecast and what caching saved.

Set policy on it

Leisure over 2% notifies the team head. The top tier over 30% needs approval. A used-up budget blocks.

Route by it

With model=auto a lookup goes to a cheaper tier and a long analysis to a larger model. Every decision records why.

What else the Enterprise edition does.

Five more parts of the same gateway.

One base URL in front of every model

People change only their base URL and key. Behind it sit the models in our catalogue, the providers on your own keys and the models inside your network. The gateway watches the health of each upstream and fails over to another.

  • The catalogue lists what each model costs and what each upstream does with your data: no retention, may retain or stays inside.
  • Model access by team: allowed, needs approval, or blocked. The first matching rule wins.
  • Switch a team to no-retention and upstreams that may retain data are turned off for that team. The private model stays available.
  • BYOK is included, and personal provider keys can be allowed or turned off for the whole instance.
Teams × models Cells come from the rules; change the rules, not the cells
Team claude-opus-5gpt-5.4deepseek-v4.1
Support BlockedAllowedAllowed
R&D Needs approvalAllowedAllowed
Sales Needs approvalAllowedAllowed

Budgets that act before the invoice

The organization gets a cap, teams get a total, intents get a share and people get a daily allowance. When one is exceeded, the gateway reports it and acts on it.

  • Alert lines at 50, 80 and 95% of the cap. When it runs out, new requests are refused with a 402, or served and flagged: your choice.
  • Policies per intent: notify the team head, require approval, route to a cheaper tier, or block.
  • A temporary increase reverts on its own. A request for a higher limit goes to the team head, then to an admin if 24 hours pass without a decision. A person decides each one.
  • Cost centers and a monthly statement to Finance, with unallocated spend listed by key.
Intent policies Checked on every request, before it is forwarded
  • Leisure share over 2% · all teams Notify head
  • Analysis top tier over 30% · R&D Needs approval
  • Lookup share over 10% · Support Cheaper tier
  • Any intent budget used up · all teams Block

Guardrails with a judge model and a tool registry

Rule packs check requests and responses: prompt injection, personal data, secrets and keys, denied topics, your own word list. Start in detect-only, see what it would have done, then enforce.

  • Four actions: block, mask, guide or detect. Guide tells the person what to do instead, without changing what the model receives.
  • A judge model reviews each hit above a confidence threshold, with the text redacted first. If the judge is slow or down, that request passes, is recorded and raises a high-severity alert.
  • Data classification: four levels and your own rules. Each level says which models it may reach.
  • MCP servers and skills are registered; an unregistered one is recorded or blocked. Alerts go to Slack, email, Feishu or PagerDuty, and before you disable a key you see what it would break.
Rule packs Last 7 days · enforce
Pack Direction Action Hits
Prompt injection In block 286
Personal data In · Out mask 912
Secrets and keys In block 248
Denied topics In detect 6

With model=auto, the gateway picks the model

With model=auto the gateway reads the request, picks a tier and a model and records why. The base URL, the SDK and the list price stay the same, so a routing policy can change without a code change.

  • Detects the intent from keywords, structure, length and tools. Local rules decide inside the instance and nothing leaves it, or you can point it at your own intent endpoint.
  • Maps the intent to a tier. Long or tool-using requests get a higher one.
  • Picks the first model available right now. Within a conversation the tier only moves up.
  • The routing page shows what auto saved against sending everything to the top tier.
# Drop-in. One line changes.
base_url="https://api.openai.com/v1"
base_url="https://synthorai.io/v1"
# model="auto"

Identity from your IdP, and an audit log you can verify

People sign in with SSO and are provisioned over SCIM, and roles come from IdP groups. Every change made in the console lands in a hash-chained audit log.

  • Accounts bind to the IdP subject, never the email: a look-alike address cannot inherit someone's allowance or keys.
  • Keys stop within five minutes of deactivation in the IdP, in-flight requests included.
  • The audit log records each console change field by field and each read of a prompt, never request bodies. Export it as JSONL or stream it to your SIEM. It is kept permanently.
  • Request logs and bodies have their own retention: off, redacted, or full for debugging.
Audit log Chain intact · verified 3 min ago
  • Emily Carter · Admin Changed upstream weight Azure eastus 100 → 50
  • SCIM Offboarded, keys revoked Mark Davis · 3 keys
  • Jason Miller · Team head Approved an increase Sarah Brooks · $10 → $15 a day
  • System Judge failed over Judge → local rules

Where the data goes.

Managed dedicated instance

Your own instance, run by us. Zero retention by default, or the retention policy you set. Region pinning in the US, EU or APAC.

Private deployment

The whole product, gateway and console, in your VPC or data center. Requests leave only for the providers you allow.

You choose the endpoints for the routing classifier, the judge model and the prompt tagger. The gateway accepts only HTTPS or a private address for them, so a prompt is not sent across the public internet unencrypted.

What it supports.

Asked for Provided by
EU AI Act, Article 26: deployers of high-risk AI systems keep automatically generated logs for at least six months and assign human oversight to people with the authority for it Audit events are kept permanently, and request logs for the retention you set; approvals and guardrail rules put a person or a rule on the request itself
ISO/IEC 42001: an AI management system with an inventory, roles and continual monitoring Application registry, teams and roles, per-request records with intent tags
NIST AI RMF: govern, map, measure, manage Policy rules, data classification, usage analytics by team and intent, approvals

These are the controls each framework asks for and the feature that provides each one. They support your assessment and are not a certification.

Talk to sales.

Tell us your team size, the providers you use and where it has to run. The DPA is available on request.

Talk to sales