AI Security Gateway
VerifiedAI Firewall & LLM Proxy — PII Redaction, Smart Routing, Budget Enforcement
Quick facts
- Best for
- AI security
- Pricing
- Freemium
- Editor rating
- 5 / 5
- Community saves
- 0

About AI Security Gateway
Socials: AI Security Gateway (AISG) is a vendor-neutral AI firewall and LLM proxy and AI Governance Gateway with DLP, SSO, RBAC, SIEM, and Hybrid VPC. Auto-redacts 30+ PII types from LLM prompts, routes across 600+ models and 8 providers, enforces per-project budgets, kills agent loops, and streams security events to your SIEM. Enterprise SSO (Okta, Azure AD, Google Workspace), 4-tier RBAC, and Hybrid VPC deployment where prompts never leave your network. OpenAI SDK compatible. Open-source core (Apache 2.0). It sits between your app and LLM providers (OpenAI, Anthropic, Google, Meta, Mistral, xAI, Groq, DeepInfra, TogetherAI and others) to enforce security policies before prompts reach any third party. Drop it in with a 2-line base URL change. Core capabilities: 🔒 PII Redaction: Auto-detects and redacts 28+ entity types (names, emails, SSNs, credit cards, etc.) from prompts before they leave your infrastructure 👁️ Vision DLP: OCR-based scanning of images for sensitive data before sending to vision models ⚡ Smart Routing: Automatically selects the most cost-efficient provider across 380+ models 💰 Budget Enforcement: Per-project spending caps with hard limits — requests blocked when budget is exhausted 🛡️ Project-Level DLP Policies: Versioned, per-project security policies with custom regex patterns 🚫 Prompt Injection Blocking: Heuristic detection of jailbreak and injection attempts ⚡ Recursive loop protection — auto-kills agent retry loops ($108/hr saved) 🛡️ HMAC-SHA256 webhook alerts — push to Slack, PagerDuty, or SIEM in real time 👁️ Hybrid VPC deployment — compiled Go proxy runs inside your infrastructure 🛡️ Docker Compose + Kubernetes — 3-container stack, deploy in minutes 🛡️ SAML SSO — Okta, Azure AD, Google Workspace with auto-provisioning 🛡️ 4-tier RBAC — Owner, Admin, Member, Viewer with 17 granular permissions 👁️ SIEM Connectors — stream events to Splunk HEC, Datadog Logs, or Microsoft Sentinel 🛡️ On-premises DLP — 30+ PII entity types redacted locally, sub-50ms ⚡ Cloud-managed policies — update rules from dashboard, synced every 30s 👁️ Zero data egress — only metadata (token counts, violation counts, latency) reaches cloud 🛡️ Fail-closed architecture — blocks requests if DLP unavailable, never fails open 🛡️ Private container registry — authenticated image pulls, deployment token provisioned during onboarding Compliance: • EU AI Act Article 12 compliant audit logging (enforcement: Aug 2, 2026) • Hash-chained tamper-evident records — SHA-256 fingerprints, no raw content • JSONL export + chain verification API • GDPR, HIPAA, PCI-DSS ready ✅️ Privacy by design: Stateless proxy architecture — prompts and responses exist only in volatile memory during processing. Zero retention. No training on your data. ✅️ Integration: • OpenAI SDK compatible — 2-line code change • Python SDK: pip install aisg • Streaming (SSE) fully supported • Open-source core: Apache 2.0 ✅️ Free: 1M credits, no credit card. Try the AI Leak Checker (no signup): aisecuritygateway.ai/ai-leak-checker 🔗 Open source: https://github.com/aisecuritygateway/aisecuritygateway Supported featuresAPIOpen sourceRun locallyCybersecurity Key FeaturesAi Prompt Leak ProtectionLlm Prompt Pii RedactionAi Security FirewallStateless Ai FirewallPii Redaction (28+ Entity Types)Prompt Injection DetectionVision Ocr Dlp (scans Images For Pii)Credit Card Detection With Luhn ValidationRecursive Loop ProtectionApi Key And Secret DetectionWorks With All Major Llm ProvidersEu Ai Act Compliance LoggingAccess To Llm ModelsOpenai Sdk Compatible ProxyWebhook NotificationsPrivate And Secure: Your Data Is Never Used For TrainingMulti-provider Support (anthropic/openai/gemini)Model Gateway: Use Built-in Provider Keys; One Billing Surface For ModelsMulti-provider Smart Routing200+ Llm Models SupportedBudget Enforcement Per ProjectCost Optimization Across ProvidersByok (bring Your Own Key) With 0% Markup2-line Code IntegrationZero Data RetentionPython SdkJsonl Audit ExportChain Verification Api1m Free Credits (no Credit Card)Openai, Anthropic, Groq, Gemini, Mistral, Llama, Xai SupportSaml Sso — Okta, Azure Ad, Google Workspace With Auto-provisioning4-tier Rbac — Owner, Admin, Member, Viewer With 17 Granular PermissionsSiem Connectors — Stream Events To Splunk Hec, Datadog Logs, Or Microsoft SentinelHybrid Vpc — Compiled Go Proxy In Your Network, Cloud Dashboard For PoliciesPer-project Budget Enforcement With Hard Spending Caps
Pros
- Professional security gateway
- Hardened, stateless firewall
- Supports 300+ models
- Total data sovereignty enforcement
- Real-time redaction of 28+ PII entities
- Image OCR for PII detection
- Autonomous cost-optimized routing
- Saves up to 90% vs GPT-4o
- Per-project budget governance
- Token quotas enforcement
- Audit-ready security logs
- Integration in 2 lines of code
Cons
- Wallet mode Pay as you got starts at $10Provider optimization not customizable
- Only 28+ PII entities detected
- No OCR scanning customizations
- Pro plan required for BYOK