Our engineers set up and run your first chatbot / LLM security scan. Get in touch

Enterprise AI-SPM Architecture: Runtime Gateway, Control Plane and Evidence Loop

Split control plane and in-VPC gateway.

The gateway runs inside your VPC while the control plane holds state. Runtime decisions feed posture back to the control plane, and a block can be promoted into a signed rule.

Penaxtra is an enterprise AI Security Posture Management (AI-SPM) platform split into a customer-side self-hosted runtime gateway and a hosted control plane. Prompt content never leaves the customer network; only allow or block decisions and redacted finding records flow upstream. The agent loads Ed25519-signed rule blobs and refuses anything that fails signature verification.

<1ms
Gateway overhead

per request, P95 on commodity hardware.

Ed25519
Signed rule blob

customer verifies signature offline before activation.

0
Prompt bytes upstream

only redacted decisions + finding evidence leave the VPC.

How policy and requests flow between the four nodes

Your agent sends prompts to the gateway, which forwards a redacted call to the LLM provider. The control plane signs policy down to the gateway and reads redacted evidence back. Hover the diagram to speed up the nearest beam.

From adversarial probe to signed rule

The same three stages that power scheduled scans also feed the runtime gateway's signed rule blob.

01

Probe

Adversarial prompts drawn from a library covering OWASP LLM Top 10, MITRE ATLAS, and bespoke probes you author. Probes carry the framework references they exercise.

02

Three-judge consensus

Each adversarial response is scored by three third-party LLMs (Anthropic, OpenAI, Google) in parallel. A meta-judge resolves disagreement and flags low-confidence cases for human review.

03

Evidence

Findings are stamped with framework control IDs, severity rationale, and timestamps. The same probe-and-judge pipeline feeds the runtime gateway's signed rule blob.

Every framework cited links back to its publisher.

Auditors verify our control mapping against the same documents we read. Each item below points to the canonical publication.

Last reviewed:

Want the deployment guide?

Threat model, rule-blob format, gateway deployment guide, and a sample scan report, in one PDF.

One email. No drip, no sales follow-up unless you ask.