Secure AI use
SSO-authenticated requests, per-user model allowlists, and a deny-by-default egress gate. Data only reaches destinations you've authorized — CUI never leaves the boundary.
Built for defense & regulated industry
SecRouter is the secure API gateway between your teams and every model — authenticating every request, enforcing policy, controlling egress, and capping spend across the organization. One endpoint. Total control.
Self-hostedDeny-by-default egressAir-gap ready
The control plane for AI
Sit between your people and the models. Inspect every request, enforce every policy, and meter every dollar — without slowing teams down.
SSO-authenticated requests, per-user model allowlists, and a deny-by-default egress gate. Data only reaches destinations you've authorized — CUI never leaves the boundary.
Hard budgets and rate limits per group and user. Route each request to the cheapest capable model and cut off runaway usage before the invoice arrives.
Hash-chained, tamper-evident audit of every request, decision, and route — metadata only, never prompt content. RBAC and SSO, with exportable evidence for auditors and accreditation.
Drop-in architecture
Point your existing SDKs at SecRouter. Change the base URL — keep your code.
Your teams & apps
SecRouter control plane
Model providers
Security & deployment
Run SecRouter fully self-hosted, in GovCloud, or air-gapped. Nothing leaves your boundary unless policy says so — and you hold the keys.
Read the security brief →No outbound calls required — route only to in-boundary or GovCloud endpoints.
OIDC SSO with MFA; group and role policy mapped to your IdP.
Prompt and response content is never stored — only decisions, counts, and hashes.
Hash-chained audit trail, exportable for accreditation.
Cost control
Attribute spend down to the principal, set hard caps, and route to cheaper models automatically. Finance gets one bill; IT gets the controls.
OIDC, group-mapped policy
Approve models per group
Hard caps & auto-cutoff
Cheapest capable model
Deny-by-default allow-list
Hash-chained, metadata-only
Request & token rate limits
Air-gap & GovCloud
Map SecRouter to your environment and compliance posture — or clone it and bring up the secured test stack in one command.