Self-hosted AI gatewayCustomer-managed · your infrastructure

Govern every model request.

Agent Access Manager is the control layer between your AI applications and your model providers. Replace shared vendor keys with scoped virtual access, enforce policy at runtime, and keep a searchable record of everything your agents do.

RuntimePolicy enforcement
ProtectedProvider credentials
SearchableActivity records
Agent Access Manager — console
The Agent Access Manager console overview: seven-day spend, request volume, and flagged and blocked counts, a spend trend chart, indexed security events, spend by model, pending SOAR actions, recent control-plane changes, and virtual key totals.

Console overview from a demonstration deployment carrying synthetic traffic.

The console

Administration, investigation, and evidence in one dashboard.

Manage keys, providers, budgets, and guardrail policy, then search the governed activity behind every decision — without leaving your own network.

Agent Access Manager — console

Recorded against a demonstration deployment with synthetic traffic.

Operate

Issue and revoke virtual keys, register providers and model aliases, rotate vendor credentials, and set routing.

Govern

Define guardrail categories, detectors, and per-direction policy; set budgets and rate limits at any scope.

Investigate

Search the audit trail, review guardrail findings and detections, and inspect the decision behind any call.

Report

Track spend by model and over time, read request-density heatmaps, and export scheduled usage and security reports.

The control plane

One governed layer between agents and model providers.

Applications authenticate with scoped, revocable virtual keys while provider credentials stay encrypted inside your environment. No reusable vendor secret needs to live in agent code.

Every model request is evaluated against identity, team, model, budget, rate, and guardrail policy before it is forwarded to a configured provider.

Security and platform teams get one operational record across model requests, guardrail decisions, usage, configured cost, and outcomes.

Agents & applications

Coding agents and assistants
Internal AI applications
SDKs and orchestration frameworks
Teams, projects, and environments

Agent Access Manager

Authenticate with scoped virtual keys
Authorize model requests by scope
Route to configured providers
Enforce request and response guardrails
Apply budgets and rate limits
Record decisions, usage, and outcomes

Model providers

Cloud-hosted LLMs
OpenAI-compatible endpoints
Anthropic deployments
Gemini and Vertex AI
Self-hosted model servers
Product capabilities

Access, policy, routing, and evidence in one platform.

Agent Access Manager brings identity context, credential protection, routing, guardrails, cost control, and security records into the same request path.

Scoped virtual keys

Issue revocable, expiring virtual keys for applications, agents, teams, and projects without distributing provider credentials.

Credential isolation

Keep provider credentials AES-256-GCM encrypted inside the gateway and inject them only when forwarding a governed request.

Routing and failover

Map model aliases to several deployments, then load-balance with health-aware routing and automatic fallback across vendors.

Runtime guardrails

Inspect requests and responses for PII, secrets, and patterns with allow, flag, redact, or block actions — streaming included.

Budgets and rate limits

Apply spend and token budgets plus RPM/TPM limits across organizations, teams, projects, and individual keys.

Cost-aware spillover

Cap an expensive vendor per deployment and let a governed alias fail over to a cheaper backend instead of failing the call.

Security analytics

Search model-call and guardrail events, run Sigma detections and behavioral analytics, and apply reversible containment.

Searchable audit trail

Investigate governed activity with the applicable identity, provider, model, token usage, configured cost, and outcome.

Explore the platform
Integrations

Bring providers and agent frameworks behind one governed endpoint.

Connect supported cloud and self-hosted models, then point compatible SDKs, frameworks, coding agents, and internal applications at Agent Access Manager.

Model providers

Route through customer-managed provider connections.

Centralize provider configuration and model aliases while applications use scoped virtual keys instead of reusable vendor credentials.

OpenAIAnthropicAzure OpenAIAWS BedrockGoogle GeminiVertex AICohereMistral AIGroqOllamaMeta LlamaIBM watsonxNVIDIADatabricksDeepSeek

Additional providers connect through any supported OpenAI-compatible endpoint.

SDKs and frameworks

Keep the development tools your teams already use.

In most integrations, an application changes the base URL and swaps the provider key for an Agent Access Manager virtual key.

LangChainLangGraphLlamaIndexDSPyVercel AI SDKLiteLLMSemantic KernelOpenAI SDKCrewAIAutoGen

Guides are available for OpenAI, Anthropic, Gemini, Vertex AI, LangChain, and supported self-hosted models.

Questions

Common questions about governing AI access.

How Agent Access Manager governs application and agent access to models in customer-managed environments.

What is Agent Access Manager?

Agent Access Manager is a self-hosted AI gateway and governance layer that sits between your applications and your LLM vendors. Applications get a single OpenAI-compatible endpoint and revocable virtual keys; the platform routes each call to the configured provider, enforces budgets, rate limits, and guardrails at runtime, and records governed activity in a searchable audit trail. It deploys in your own environment with Docker Compose or Kubernetes.

How do AI agents access models without seeing our provider API keys?

Provider credentials are registered once by administrators and kept AES-256-GCM encrypted inside the gateway; they are never returned to clients. Each application, team, or agent instead receives a scoped virtual key that is revocable, can expire, and carries its own budgets, rate limits, and guardrail policy. Revoking a virtual key cuts off that consumer without rotating the underlying provider credential.

Which LLM providers and SDKs does the gateway support?

The gateway exposes OpenAI-compatible chat, embeddings, responses, messages, and models APIs, with provider adapters for OpenAI-compatible services, Anthropic, Gemini, and Vertex AI, plus self-hosted backends such as Ollama, vLLM, and LiteLLM. Existing applications built on the OpenAI SDK, Anthropic SDK, LangChain, or coding agents like Claude Code and Codex connect by changing the base URL and key — no application rewrite.

Can Agent Access Manager run fully on-premises or air-gapped?

Yes. Agent Access Manager is customer-managed software deployed in your own environment — single-host Docker Compose or multi-replica Kubernetes with Helm — and supports offline installation. Prompts, responses, credentials, and audit data stay inside your infrastructure, and provider usage runs through your own vendor accounts.

How does Agent Access Manager handle model-generated tool calls?

The current gateway preserves or translates supported tool and function-call fields and provides tool-call argument screening through configured response guardrails using flag or block actions. It does not currently provide an MCP server registry or per-tool execution permissions. Tool execution must be authorized and audited by the agent runtime, tool service, or a separate tool gateway.

How does it help with SOC 2 or ISO 27001 audit evidence?

Every governed request is recorded with the applicable identity, policy decision, provider, model, token usage, cost, and outcome. Audit trails are searchable, and scheduled usage and security reports export in PDF, CSV, JSON, and HTML. Built-in SIEM search, Sigma detections, behavioral analytics, and SOAR containment support security operations on the same event stream.

See your first governed model call in under an hour.

Talk to the engineers who build Agent Access Manager. We will map your providers, agents, deployment environment, and governance requirements to a practical control architecture.

We typically respond within one business day.