New Business Rules in the AI Agentic Age Get the free whitepaper
Platform · Gateway

Repoint one URL. Govern every call.

A transparent, OpenAI-compatible proxy. Point your agents at it and every model and tool call is checked against your rulebook before it runs. No app changes, your keys stay yours.

Prefer to enforce in your own code?Use the Verdict SDK →
Your agents
enforces here
TapPass
refund > €500 → holdexport PII → ask a human
Tools & models
An OpenAI-compatible endpoint. Repoint one base URL and every call is checked against your rulebook — passed, held for a person, or blocked.
EU-hostedBYOK — your model keysRedacted in transitNo app changes
What the Gateway does

Enforcement, observability and evidence — in one hop.

Transparent proxy

An OpenAI-compatible endpoint. Repoint your base URL and governance is live — no SDK, no rewrites.

OpenAI-compatibleno app changes

Policy on model calls

Whitelist-by-default guardrails and PII redaction applied in the request path, before the model sees a thing.

whitelist defaultPII redaction

Policy on tool calls

Per-tool permissioning and human-in-the-loop approvals on MCP traffic. Least privilege by default.

per-toolhuman-in-the-loop

Full observability

Every prompt, response and tool call visible in real time, per user and per team.

real-timeper user & team

Audit trails

Every interaction recorded and exportable to your SIEM as OpenTelemetry. Evidence is a query, not a project.

SIEM exportevidence is a query

BYOK & vault

You keep your own model keys. Credentials live in an encrypted vault, never on user devices.

BYOKencrypted vault
On the record

Nothing runs unseen.

Every decision the Gateway makes streams to the SIEM you already run, as OpenTelemetry. Sensitive content is redacted in transit; raw data is never persisted. When an auditor asks, the answer is a query.

How policies are written →
OpenTelemetry (OTLP)SIEM: Splunk · Sentinel · ElasticHash-chained recordsGDPR · EU data residency
Every call, on the recordSplunk
09:41:02allowbilling · refund €120
09:41:44holdbilling · refund €8,200
09:42:10blockresearch · export_all
09:42:31allowsupport · reply #4821
redacted in transit · evidence is a query
FAQ

The Gateway, in plain answers.

What is the Gateway, and what does it do?

A transparent, OpenAI-compatible proxy that sits between your agents and the models and tools they call. Every model call and every tool (MCP) call passes through it, is checked against your rulebook, and is then allowed, held for a person, or blocked — with every decision recorded.

Why put a checkpoint in front of every call?

An agent with your model key can reach any tool, any model, any time. The agent isn’t the villain — ungoverned access is. One checkpoint in the request path keeps eager agents useful and makes sure nothing runs that you didn’t allow.

How does it work?

Repoint one base URL — no SDK, no rewrites. Each request is then screened for sensitive data, evaluated against your rules, and either passed to the model on your behalf (using your own key) or returned for your code to run. If your rules can’t load, the request is blocked; nothing passes unchecked.

How does it integrate with my stack?

It works with the models you already use (bring your own keys), the MCP servers your agents already call, and the SIEM you already run — decisions stream out as OpenTelemetry to Splunk, Sentinel or Elastic, and human approvals route to Slack or email. No application changes.

Isn’t this just an API gateway (Kong, MuleSoft)?

An API gateway routes and rate-limits HTTP. It can’t tell an agent from a user, can’t permission individual MCP tools, and produces access logs — not agent-action evidence. TapPass adds the agent-aware policy and audit on top.

We already have guardrails in our code — why add this?

Guardrail libraries live inside one app and usually only see the model call. The Gateway governs the tool calls too — across every agent and model, from one place — with human-in-the-loop approvals and a record. One rulebook, not one per repo.

Can I enforce inside my own code instead of the proxy?

Yes. If you’d rather not route through a proxy, call the Verdict SDK before an agent acts — it returns allow, hold or block, and your code enforces the answer. Same rulebook, same record.

Won’t a proxy add latency or leak our keys?

The check adds a few milliseconds in the request path. Your model keys stay yours (BYOK) in an encrypted vault, never on user devices, and content is redacted in transit — raw data is never persisted.

Ready when you are

See TapPass on your own agents.

Watch first, enforce when you’re ready — live in your EU region in two weeks, on the stack you already run.

No credit card · EU-hosted · works with your MCP, models & gateway
Book a demo