Transparent proxy
An OpenAI-compatible endpoint. Repoint your base URL and governance is live — no SDK, no rewrites.
A transparent, OpenAI-compatible proxy. Point your agents at it and every model and tool call is checked against your rulebook before it runs. No app changes, your keys stay yours.







An OpenAI-compatible endpoint. Repoint your base URL and governance is live — no SDK, no rewrites.
Whitelist-by-default guardrails and PII redaction applied in the request path, before the model sees a thing.
Per-tool permissioning and human-in-the-loop approvals on MCP traffic. Least privilege by default.
Every prompt, response and tool call visible in real time, per user and per team.
Every interaction recorded and exportable to your SIEM as OpenTelemetry. Evidence is a query, not a project.
You keep your own model keys. Credentials live in an encrypted vault, never on user devices.
Every decision the Gateway makes streams to the SIEM you already run, as OpenTelemetry. Sensitive content is redacted in transit; raw data is never persisted. When an auditor asks, the answer is a query.
How policies are written →A transparent, OpenAI-compatible proxy that sits between your agents and the models and tools they call. Every model call and every tool (MCP) call passes through it, is checked against your rulebook, and is then allowed, held for a person, or blocked — with every decision recorded.
An agent with your model key can reach any tool, any model, any time. The agent isn’t the villain — ungoverned access is. One checkpoint in the request path keeps eager agents useful and makes sure nothing runs that you didn’t allow.
Repoint one base URL — no SDK, no rewrites. Each request is then screened for sensitive data, evaluated against your rules, and either passed to the model on your behalf (using your own key) or returned for your code to run. If your rules can’t load, the request is blocked; nothing passes unchecked.
It works with the models you already use (bring your own keys), the MCP servers your agents already call, and the SIEM you already run — decisions stream out as OpenTelemetry to Splunk, Sentinel or Elastic, and human approvals route to Slack or email. No application changes.
An API gateway routes and rate-limits HTTP. It can’t tell an agent from a user, can’t permission individual MCP tools, and produces access logs — not agent-action evidence. TapPass adds the agent-aware policy and audit on top.
Guardrail libraries live inside one app and usually only see the model call. The Gateway governs the tool calls too — across every agent and model, from one place — with human-in-the-loop approvals and a record. One rulebook, not one per repo.
Yes. If you’d rather not route through a proxy, call the Verdict SDK before an agent acts — it returns allow, hold or block, and your code enforces the answer. Same rulebook, same record.
The check adds a few milliseconds in the request path. Your model keys stay yours (BYOK) in an encrypted vault, never on user devices, and content is redacted in transit — raw data is never persisted.
A valid credential doesn't make a live action valid.
Least privilege for humans is well understood.
Dashboards and log aggregation were built for human-speed decisions.
Watch first, enforce when you’re ready — live in your EU region in two weeks, on the stack you already run.