Our engineers set up and run your first AI security scan. Get in touch

Runtime AI Gateway

A self-hosted agent that proxies LLM API calls, applies DLP rules on the wire, and enforces Ed25519-signed policy. Prompts never leave the customer VPC in this deployment mode.

Last reviewed September 2026

The gap a runtime gateway closes

Inline LLM guardrails inspect prompts at the edge of a managed vendor. Regulated buyers cannot accept the data-residency story: prompts contain customer PII, internal URLs, source code. The data must stay inside the trust boundary while still being filtered.

How Penaxtra runs the gateway inline

The Penaxtra Runtime AI Gateway is a single static binary (Linux x86-64) that customers self-host inside their VPC. It terminates the agent-to-LLM-provider request, runs a six-pass normalization pipeline, applies DLP and tool-allowlist rules, then forwards the redacted request. Policy bundles are Ed25519-signed at the control plane; the gateway verifies before applying. The free browser extension applies the same detection library in the browser, before a prompt leaves the user's machine.

Runtime AI Gateway capabilities

Forty-eight built-in DLP patterns; custom regex supported

Six-pass normalization: Unicode, leet, zero-width, base64, homoglyph, HTML entity

Turkish case-folding handled: lowercasing the dotted capital I does not yield a plain i, so keyword filters that skip this step are bypassed in published testing

Optional semantic classifier measured on an external Turkish set: 0.8 percent false positives on benign prompts, 7.5 percent missed injections (threshold 0.5)

Tool allowlist per asset; rejects unauthorised tool calls regardless of model output

Per-domain budgets + rate limits (daily and monthly)

Ed25519-signed policy bundles with version pinning

P99 filter overhead under 0.8 ms

Append-only block-event ledger forwarded to the control plane

Linux amd64 static binary, plus an optional build carrying the semantic classifier

Runtime AI Gateway compliance mapping

Maps to OWASP LLM02 (insecure output handling), LLM06 (sensitive disclosure), LLM07 (insecure plugin), LLM08 (excessive agency), MITRE ATLAS AML.T0048 (model evasion), NIST AI 600-1 MANAGE-2.4, and EU AI Act Article 15 (cybersecurity).