Tool & Runtime Security

AI Gateway

Authorise every model call.

Put any model provider behind the Authorisation Layer. The AI Gateway runs model calls through the same enforcement as any other action, so what an agent asks a model to do is authorised, not just logged.

Any provider, one boundary

Point your agents at the gateway and their model calls are evaluated against your Charter, whichever provider they use.

  • Provider and model agnostic
  • One enforcement path for all calls
  • Adopted by changing the base URL

What gets enforced

The gateway applies identity, delegation, context and charter to model calls, and can pause high-impact calls for a human.

  • Identity and charter on each call
  • Pause for human where it matters
  • Sealed to the vault

Observe or enforce

Run in observe mode to see what would be caught, then switch to enforce when you are ready.

More in Tool & Runtime Security.

Related capabilities on the same authorisation layer. Every one is enforced before an action runs and sealed to the Provenance Vault.

1.0MCP & Tool Security

Decide which agent may call which tool.

Learn more
2.0Runtime Containment

Contain or kill any agent, instantly.

Learn more
3.0Breakglass

Emergency access without invisible exceptions.

Learn more
4.0Temporal Windows

Authority that only exists when it should.

Learn more

See AI Gateway in your workflow.

Put one workflow behind Xybern and watch every agent action authorised, and sealed to the vault.