The SecRouter suite — documentation¶
The SecRouter suite is a self-hostable set of components for running AI securely inside a closed or regulated network: a governed gateway in front of every model, the identity/inference/ collaboration pieces around it, and one orchestrator that pins a tested version of the whole stack and deploys it — air-gap friendly. Every piece is open source (Apache 2.0) and independent: run the ones you need, drop the ones you already have.
This hub covers all of it. SecRouter, the governed AI gateway at the center, keeps its own four-page section; every other component gets a short overview page here linking out to its repo and its own in-depth docs.
Identity & trust¶
Optional — provide these when you have nothing, drop them when you already run an IdP/CA/DNS.
SecCert — internal ACME (RFC 8555) certificate authority; issues the suite’s TLS certs on closed or air-gapped networks.
SecSSO — single sign-on (Authentik), pre-wired OIDC blueprints and suite branding. Drop it the moment you have Okta, Entra, or Keycloak.
secdns — zero-dependency authoritative DNS; resolves the suite’s internal
*.internalnames when you run no DNS of your own.
Gateway¶
SecRouter — the governed AI gateway: authenticate every request, enforce model/tool/budget policy, gate egress, route (including A/B and escalation experiments), fail over dead providers, and log every decision. See the SecRouter (gateway) section in the sidebar for deploy, usage, configuration, and control-validation guides.
Inference¶
SecLLM — a friendly control plane for vLLM: curated model catalog, load/unload/reload, health management, and an OpenAI-compatible endpoint. SecRouter routes to it as a local, in-boundary provider.
Agents & collaboration¶
SecAgent — the agentic harness (pi + an affordance engine) behind MR review, static analysis, and docs/test generation. Every model call it makes is governed through SecRouter.
SecChat — auditable team chat and agentic chat in one app: SSO via SecSSO, tamper-evident hash-chained audit, owner-gated coding agents, and native voice & video calling.
SecRecorder — self-hosted Whisper transcription with optional speaker diarization; meeting audio and transcripts never leave the boundary.
Edge¶
Optional infrastructure.
SecProxy — edge reverse proxy; one HTTPS front door (
:443) for the suite’s web and API services, FIPS-clean on hardened hosts.
Orchestration¶
SecDeploy — release train and deploy orchestration: one pinned, tested suite version per target, from a macOS eval box to a FIPS-ready Fedora host.