allclouds.pl
SAIE products / PROXY:AI

PROXY:AI

The central layer of control, security and corporate governance for AI. One gateway between users, applications and AI agents and over 100 models — cloud and local. It eliminates shadow AI, protects sensitive data and keeps costs under control — from cloud to on-premises and air-gap deployments

Book a demonstrationGet the PDF white paper
<50 msreal-time analysis
100+supported models
12scanning languages
6+ monthsaudit history on demand
PROBLEM

Shadow AI means three risks at once

Securitysensitive data reaches external models outside policy → AI Firewall masks data and blocks attacks on the model
Costsan agent stuck in a loop generates runaway bills (denial-of-wallet) → Cost Control: budgets and limits
Provider dependencyvendor lock-in → Zero-Code Switch: change models without rewriting applications
Regulatory pressureAI Act, GDPR, DORA, NIS2/Polish KSC, KRI, ISO/IEC 42001 → Governance: WORM records and evidence packs
One request lifecycle — the same for a person, application or agent
1 · Authentication · RBAC: roles, groups, keys · — no direct API keys · AI GATEWAY · 2 · Context assessment · ABAC: who, from where, which model, · and at what risk · AI GATEWAY · 3 · Input scanning · data masking, blocking · prompt injection and jailbreak · AI FIREWALL · 4 · Routing and budget · model selection based on scan · results and limit checks · COST CONTROL · 5 · Model invocation · or a response from the · semantic cache for · repeated questions · AI GATEWAY · 6 · Output scanning · model response analysis · AI FIREWALL · 7 · Human approval · high-risk operations · (human-in-the-loop) · GOVERNANCE · 8 · Audit record · immutable WORM register · GOVERNANCE · REQUEST: PERSON, APPLICATION OR AGENT · RESPONSE AND AUDIT TRAIL
Zero-Code Switch — manage access profiles, not models
User · sends a request · Application · sends a request · AI agent · sends a request · Assigned profile · access · instead of selecting a raw model · Decision · system · permissions · cost · data class · Local models · e.g. Bielik, Llama · Cloud models · selected by policy · WHO IS ASKING · PROFILE · DECISION · MODEL · over 100 models for policy-based selection
Platform modules

Nine modules across four pillars

A dedicated module implements each stage of the lifecycle. Changing a model or adding a policy or limit does not require rewriting applications

Modules around one gateway
Model Registry · model and access profile catalogue · ABAC Gateway · attribute-based request evaluation · RBAC and identity · roles, groups, keys; rotation without downtime · MCP Gateway · oversight of autonomous AI agents · AI Firewall · scanning in 12 languages, data masking · Guardrails · prompt injection and jailbreak filters · Prompt management · response policy repository · Immutable audit · WORM register, Prometheus and Grafana · FinOps and Anti-DoW · budgets, Twin:Coin, Basic / Advanced classes · PROXY:AI · gateway for services, rules and compliance · AI Gateway · AI Firewall · Governance · Cost Control · AI GATEWAY · AI FIREWALL · GOVERNANCE · COST CONTROL
Regulatory compliance and evidence

A record that cannot be denied

The WORM register stores every model invocation, its cost and decision context immutably and with cryptographic protection. Using data collected during normal operations, PROXY:AI prepares audit evidence packs with one click

Evidence supports demonstrating compliance — it does not replace legal advice or certification
2026-09-23 10:41:07 WORM user=a.nowak · profile=finance-confidential2026-09-23 10:41:07 firewall: national ID ×2 → masking · 38 ms2026-09-23 10:41:08 routing: model=local-bielik · cost=0.42 TC2026-09-23 10:41:09 hash=7f3a…c91e · signature ✓
Prepare an evidence pack
Documentation under AI Act Annex IV
DORA risk reports
NIS2 / Polish KSC materials
ISO/IEC 42001 audit packs
FEATURE CATALOGUE

54 PROXY:AI features

The complete gateway feature list: model access, policies and permissions, compliance and oversight, administration and the administrator panel

Administration and governance7
  1. A knowledge-accounting layer for monitoring and budgeting the use of AI resources
  2. Operational event registration, administrator analytics dashboards and provider-error monitoring
  3. Defining rules that allow AI actions, require approval or block tools
  4. A confidentiality mode for working with sensitive data
  5. An MCP gateway with multi-level tool-access control at user, role and team level
  6. Restricting and auditing access to tools, functions, code execution and terminals
  7. Configuring AI request and response transformations without code through simple administrative rules
Compliance and model oversight8
  1. Controlled AI use through audits, access policies, human oversight, decision logging and model-usage documentation
  2. Readiness for EU AI Act requirements, including visibility of models, policy decisions, events, risks and audit trails
  3. Managing personal-data exposure by detecting, masking, blocking or escalating requests
  4. Registers and operational evidence useful for AI management under ISO 42001
  5. Regulatory compliance templates for the EU AI Act
  6. An SBOM model and compliance reporting for Cyber Resilience Act requirements
  7. Human Oversight mechanisms including AI-content labeling, FRIA/ASIA export and approval gates for critical actions
  8. A compliance panel presenting policies, access decisions, events, risks and active models
Access to LLM models18
  1. A unified management point for communication with LLMs by applications, agents and users
  2. Support for multiple cloud, local and on-premises AI model providers
  3. Mapping errors from different providers to one format compatible with the OpenAI API
  4. Routing models according to configuration, availability, cost, policies and user permissions
  5. Visualization of a request's route through rules, models, providers and policy decisions
  6. Fallback-model configuration and automatic switching when the primary model is unavailable
  7. A model catalog with metadata including alias, provider, type, status and usage mode
  8. Per-tier SLA isolation with dedicated instances and hardware-level GPU isolation
  9. Declarative regional data residency in an EU-only per-tenant model
  10. Defining AI resources as Custom Resource Definitions in Kubernetes
  11. Protection against excessive spending by detecting unusual consumption patterns and terminating suspicious sessions
  12. A dry-run panel for testing ABAC security rules before production activation
  13. No-code AI request and response transformations
  14. IDE integration through a dedicated plugin with real-time cost and token visibility
  15. An LLM Playground for experiments, response comparison and parameter tuning
  16. A Python and WASM plugin framework extensible through a marketplace
  17. Model validation before launch in the AI environment
  18. An internal-currency model for accounting for AI use, including per-action costs, budgets and transfers
Access policies and permissions7
  1. Model-access decisions based on user, group, model, data-type and environment attributes
  2. Predefined security-policy profiles for regulated sectors including finance, healthcare, public administration and energy
  3. Real-time detection of abuse attempts including injection, jailbreak, prohibited content and token-consumption anomalies
  4. Measuring the cost of every request by user, team, project and model with hierarchical budgets
  5. A central versioned prompt registry
  6. Prompt-template support and request decoration with central gateway rules
  7. Caching recurring requests using semantic similarity with per-tenant key isolation
Administrator panel14
  1. A dashboard for database-integration status, outbox/reconciliation, cost and usage
  2. A conversational Knowledge Chat assistant supporting operators or administrators
  3. A model registry with test statuses, BYOK tests and routing projection
  4. AI operation logging and auditing with filters and CSV/JSON export
  5. Unified telemetry with replay of historical AI requests
  6. Virtual-key management covering creation, synchronization, masking, rotation and auditing
  7. ABAC rule administration with YAML import/export, dry-run mode and gateway publishing
  8. An ABAC decision dashboard, HITL queue, user logs and risk register
  9. AI security controls through guardrails, control policies, human review and evidence logs
  10. Operational schedules, Langflow agents and runnable agent lists
  11. Spending and token logs for cost reporting and configuration
  12. Docker log browsing with a time filter
  13. Orchestration of complex multi-step agent processes with state retained between steps
  14. Automatic or semi-automatic model evaluation and adaptive real-time A/B prompt tests
DEVELOPMENT ROADMAP

What is coming to PROXY:AI in the next quarters

35 roadmap items through Q3 2027. The full list for all layers is on a separate page

Full SAIE development roadmap

2026/Q3IN PROGRESS

PA-519AI Cost Forecast & Optimizer

Before launching a solution, it is difficult to forecast model costs and identify a configuration that delivers the required quality within budget

PA-523Executive AI Dashboard

Executives need a concise view of AI costs, risks, quality, and usage without analyzing operational reports

PA-525Offline Model Registry

Disconnected environments need a controlled local catalog of model packages, versions, and compliance information

2026/Q4

PA-431Enterprise RAG Gateway

Agents and applications built outside the core product need secure, consistent access to search across corporate knowledge

PA-432Priority OCR Service

High volumes of scanned documents create queues where urgent files compete with lower-priority jobs and processing status is difficult to track

PA-433Session Intelligence Layer

Without recognizing the context of an individual session, it is difficult to apply the right limits, policies, and behavioral analysis to a specific conversation

PA-434Multi-Node Routing Fabric

In a multi-node environment, requests must reach available resources while taking workload, location, and model requirements into account

PA-435AI Compliance Engine

The organization needs to enforce regulatory requirements automatically during model use instead of relying solely on manual compliance procedures

PA-436AI Policy Control

Different teams and use cases require consistent rules for access, permitted models, data, and response generation

PA-437AI Cluster Manager

Distributed AI infrastructure requires a single place to control nodes, capacity, availability, and workload allocation

FAQ

Questions about PROXY:AI

12 answers

What is PROXY:AI, and why should IT deploy it?

It is the central control layer — one router for different AI models. It addresses shadow AI and protects the organisation against sensitive data leaks and uncontrolled costs

How does PROXY:AI protect budgets against deliberate cost inflation?

FinOps and Anti-DoW mechanisms set tenant and user limits, including protection against denial-of-wallet attacks

What about high-risk operations?

PROXY:AI supports human-in-the-loop oversight: a critical process pauses until the appropriate person authorises it

How can we show an auditor why the system used a particular model?

The immutable WORM audit log records the complete operational history: model, configuration, invocation cost and data needed to reconstruct the decision

How does PROXY:AI control AI agents' permissions?

The MCP Gateway lets agents use only explicitly assigned tools, such as Jira, and records an audit trail of their actions

Does PROXY:AI also check what models generate?

Yes. Model responses are scanned again for sensitive data and dangerous instructions

Can new security rules be tested without risk?

Yes. The dry-run panel allows ABAC rules to be tested on simulated traffic before production deployment

Will the system block personal data from being sent to the cloud?

Yes. The AI Firewall analyses data in under 50 milliseconds and neutralises items such as Polish national ID and tax numbers and email addresses before they leave the organisation's network

How does PROXY:AI reduce query costs?

Semantic caching serves repeated questions with similar meanings from the cache, without querying an expensive model again

How does PROXY:AI protect models against user attacks?

Real-time guardrails filter requests and block attacks such as prompt injection and jailbreaks

What if we want to move to a newer model?

Zero-Code Switch: change the primary model in PROXY:AI settings without rewriting business application code

How does the ABAC Gateway differ from ordinary API access?

It does not admit requests blindly. For every request, it evaluates who is asking, from which environment, using which data and at what risk — then allows, restricts or blocks the operation

NEXT

What else to explore

You are here:SAIETWIN:DESKPROXY:AICDF methodologyDeployment and securityDevelopment roadmap
PROXY:AICDF methodology
Next step
CDF methodology

AI deployment step by step: initial assessment, phases F0–F6, oversight and CogOps

Explore CDF methodology
SAIEThree layers, one AI workspace — the problem, the solution and who it is for
TWIN:DESKAn AI workspace: domain assistants, company knowledge, agents and 48 features
Deployment and securitySaaS, On-Premises, Air-Gap, platform architecture and seven ISO standards
Development roadmap110 roadmap items across five quarters, with the option to submit your own needs