PROXY:AI
The central layer of control, security and corporate governance for AI. One gateway between users, applications and AI agents and over 100 models — cloud and local. It eliminates shadow AI, protects sensitive data and keeps costs under control — from cloud to on-premises and air-gap deployments
Shadow AI means three risks at once
Nine modules across four pillars
A dedicated module implements each stage of the lifecycle. Changing a model or adding a policy or limit does not require rewriting applications
A record that cannot be denied
The WORM register stores every model invocation, its cost and decision context immutably and with cryptographic protection. Using data collected during normal operations, PROXY:AI prepares audit evidence packs with one click
54 PROXY:AI features
The complete gateway feature list: model access, policies and permissions, compliance and oversight, administration and the administrator panel
- A knowledge-accounting layer for monitoring and budgeting the use of AI resources
- Operational event registration, administrator analytics dashboards and provider-error monitoring
- Defining rules that allow AI actions, require approval or block tools
- A confidentiality mode for working with sensitive data
- An MCP gateway with multi-level tool-access control at user, role and team level
- Restricting and auditing access to tools, functions, code execution and terminals
- Configuring AI request and response transformations without code through simple administrative rules
- Controlled AI use through audits, access policies, human oversight, decision logging and model-usage documentation
- Readiness for EU AI Act requirements, including visibility of models, policy decisions, events, risks and audit trails
- Managing personal-data exposure by detecting, masking, blocking or escalating requests
- Registers and operational evidence useful for AI management under ISO 42001
- Regulatory compliance templates for the EU AI Act
- An SBOM model and compliance reporting for Cyber Resilience Act requirements
- Human Oversight mechanisms including AI-content labeling, FRIA/ASIA export and approval gates for critical actions
- A compliance panel presenting policies, access decisions, events, risks and active models
- A unified management point for communication with LLMs by applications, agents and users
- Support for multiple cloud, local and on-premises AI model providers
- Mapping errors from different providers to one format compatible with the OpenAI API
- Routing models according to configuration, availability, cost, policies and user permissions
- Visualization of a request's route through rules, models, providers and policy decisions
- Fallback-model configuration and automatic switching when the primary model is unavailable
- A model catalog with metadata including alias, provider, type, status and usage mode
- Per-tier SLA isolation with dedicated instances and hardware-level GPU isolation
- Declarative regional data residency in an EU-only per-tenant model
- Defining AI resources as Custom Resource Definitions in Kubernetes
- Protection against excessive spending by detecting unusual consumption patterns and terminating suspicious sessions
- A dry-run panel for testing ABAC security rules before production activation
- No-code AI request and response transformations
- IDE integration through a dedicated plugin with real-time cost and token visibility
- An LLM Playground for experiments, response comparison and parameter tuning
- A Python and WASM plugin framework extensible through a marketplace
- Model validation before launch in the AI environment
- An internal-currency model for accounting for AI use, including per-action costs, budgets and transfers
- Model-access decisions based on user, group, model, data-type and environment attributes
- Predefined security-policy profiles for regulated sectors including finance, healthcare, public administration and energy
- Real-time detection of abuse attempts including injection, jailbreak, prohibited content and token-consumption anomalies
- Measuring the cost of every request by user, team, project and model with hierarchical budgets
- A central versioned prompt registry
- Prompt-template support and request decoration with central gateway rules
- Caching recurring requests using semantic similarity with per-tenant key isolation
- A dashboard for database-integration status, outbox/reconciliation, cost and usage
- A conversational Knowledge Chat assistant supporting operators or administrators
- A model registry with test statuses, BYOK tests and routing projection
- AI operation logging and auditing with filters and CSV/JSON export
- Unified telemetry with replay of historical AI requests
- Virtual-key management covering creation, synchronization, masking, rotation and auditing
- ABAC rule administration with YAML import/export, dry-run mode and gateway publishing
- An ABAC decision dashboard, HITL queue, user logs and risk register
- AI security controls through guardrails, control policies, human review and evidence logs
- Operational schedules, Langflow agents and runnable agent lists
- Spending and token logs for cost reporting and configuration
- Docker log browsing with a time filter
- Orchestration of complex multi-step agent processes with state retained between steps
- Automatic or semi-automatic model evaluation and adaptive real-time A/B prompt tests
What is coming to PROXY:AI in the next quarters
35 roadmap items through Q3 2027. The full list for all layers is on a separate page
2026/Q3IN PROGRESS
PA-519AI Cost Forecast & OptimizerBefore launching a solution, it is difficult to forecast model costs and identify a configuration that delivers the required quality within budget
PA-523Executive AI DashboardExecutives need a concise view of AI costs, risks, quality, and usage without analyzing operational reports
PA-525Offline Model RegistryDisconnected environments need a controlled local catalog of model packages, versions, and compliance information
2026/Q4
PA-431Enterprise RAG GatewayAgents and applications built outside the core product need secure, consistent access to search across corporate knowledge
PA-432Priority OCR ServiceHigh volumes of scanned documents create queues where urgent files compete with lower-priority jobs and processing status is difficult to track
PA-433Session Intelligence LayerWithout recognizing the context of an individual session, it is difficult to apply the right limits, policies, and behavioral analysis to a specific conversation
PA-434Multi-Node Routing FabricIn a multi-node environment, requests must reach available resources while taking workload, location, and model requirements into account
PA-435AI Compliance EngineThe organization needs to enforce regulatory requirements automatically during model use instead of relying solely on manual compliance procedures
PA-436AI Policy ControlDifferent teams and use cases require consistent rules for access, permitted models, data, and response generation
PA-437AI Cluster ManagerDistributed AI infrastructure requires a single place to control nodes, capacity, availability, and workload allocation
Questions about PROXY:AI
12 answers
It is the central control layer — one router for different AI models. It addresses shadow AI and protects the organisation against sensitive data leaks and uncontrolled costs
FinOps and Anti-DoW mechanisms set tenant and user limits, including protection against denial-of-wallet attacks
PROXY:AI supports human-in-the-loop oversight: a critical process pauses until the appropriate person authorises it
The immutable WORM audit log records the complete operational history: model, configuration, invocation cost and data needed to reconstruct the decision
The MCP Gateway lets agents use only explicitly assigned tools, such as Jira, and records an audit trail of their actions
Yes. Model responses are scanned again for sensitive data and dangerous instructions
Yes. The dry-run panel allows ABAC rules to be tested on simulated traffic before production deployment
Yes. The AI Firewall analyses data in under 50 milliseconds and neutralises items such as Polish national ID and tax numbers and email addresses before they leave the organisation's network
Semantic caching serves repeated questions with similar meanings from the cache, without querying an expensive model again
Real-time guardrails filter requests and block attacks such as prompt injection and jailbreaks
Zero-Code Switch: change the primary model in PROXY:AI settings without rewriting business application code
It does not admit requests blindly. For every request, it evaluates who is asking, from which environment, using which data and at what risk — then allows, restricts or blocks the operation