Open source · Apache 2.0 · Built for defense & regulated industry

Govern AI use. Contain AI spend.

SecRouter is the secure API gateway between your teams and every model — authenticating every request, enforcing policy, controlling egress, and capping spend across the organization. Open source and self-hosted: deploy it yourself, or bring us in for deployment support.

Apache 2.0Self-hostedDeny-by-default egressAir-gap ready

Open source · Apache 2.0/NIST SP 800-171 R2/CMMC L3 control mapping/FIPS-aware/ OIDC SSO + MFA/Deny-by-default egress/Self-hosted or GovCloud

The control plane for AI

Shadow AI is a security incident and a budget leak. SecRouter closes both.

Sit between your people and the models. Inspect every request, enforce every policy, and meter every dollar — without slowing teams down.

Secure AI use

SSO-authenticated requests, per-user allowlists for models and the MCP tools your agents call, and a deny-by-default egress gate. Data only reaches destinations you've authorized — CUI never leaves the boundary.

Contain IT spend

Hard budgets and rate limits per group and user. Route each request to the cheapest capable model and cut off runaway usage before the invoice arrives.

Prove governance

Hash-chained, tamper-evident audit of every request, decision, and route — metadata only, never prompt content. RBAC and SSO, with exportable evidence for auditors and accreditation.

Drop-in architecture

One endpoint in front of every model

Point your existing SDKs at SecRouter. Change the base URL — keep your code.

Your teams & apps

Analyst tooling
Internal copilots
Batch pipelines

SecRouter control plane

AuthenticateEnforce policy Gate egressMeter spend Route to best / cheapest model Govern model, embedding & tool calls Log every decision

Models & tool servers

Commercial & GovCloud APIs
Self-hosted / open models
MCP tool servers

Open source · Apache 2.0 · Self-hosted

One gateway is the start. The suite is the whole boundary.

SecRouter governs the AI traffic — but standing that up in a closed or regulated network takes identity, inference, collaboration, and the plumbing to tie them together. Each piece is self-hostable and air-gap ready. Run the ones you need; drop the ones you already have.

Identity & trustoptional · drop when you have your own
SECSSO

Single sign-on (Authentik) — pre-wired OIDC blueprints and suite branding. Drop it the moment you have Okta, Entra, or Keycloak.

SECCERT

Internal ACME (RFC 8555) certificate authority — issues the suite's TLS certs on closed or air-gapped networks.

SECDNS

Zero-dependency authoritative DNS — resolves the suite's internal *.internal names when you run no DNS of your own.

Inference
SECLLM

A friendly control plane for vLLM — curated model catalog, load/unload, health management, and an OpenAI-compatible endpoint. SecRouter routes to it.

Gateway
SECROUTER

The governed AI gateway at the center — authenticate every request, enforce model/tool/budget policy, gate egress, fail over providers, and log every decision.

Agents & collaboration
SECAGENT

Agentic harness (pi) — merge-request review, static analysis, docs and test generation over an affordance engine. Every call governed through the gateway.

SECCHAT

Auditable team chat and agentic chat in one app — SSO via SecSSO, tamper-evident hash-chained audit, CUI marking and local DLP, and owner-gated coding agents driven right from a channel. Every model call governed through SecRouter, per person.

SECRECORDER

Self-hosted Whisper transcription with optional speaker diarization — meeting audio and transcripts never leave the boundary.

Edgeoptional infra
SECPROXY

Edge reverse proxy — one HTTPS front door (:443) for the suite's web and API services, FIPS-clean on hardened hosts.

Orchestration
SECDEPLOY

Release train and deploy orchestration — one pinned, tested suite version per target, from a macOS eval box to a FIPS-ready Fedora host.

Every component ships as one pinned, tested set through SecDeploy — and SecAgent and its pi CLI ship with LeanCTX context compression wired in, hardened and on by default.

Security & deployment

Deployed where your data is allowed to live

Run SecRouter fully self-hosted, in GovCloud, or air-gapped. Nothing leaves your boundary unless policy says so — and you hold the keys.

Read the security brief →

Air-gapped install

No outbound calls required — route only to in-boundary or GovCloud endpoints.

RBAC & SSO

OIDC SSO with MFA; group and role policy mapped to your IdP.

Metadata-only logs

Prompt and response content is never stored — only decisions, counts, and hashes.

Tamper-evident logs

Hash-chained audit trail, exportable for accreditation.

Cost control

Every token has an owner and a ceiling

Attribute spend down to the principal, set hard caps, and route to cheaper models automatically. Finance gets one bill; IT gets the controls.

  1. 01 Per-group and per-user budgets with rate limits and hard auto-cutoff
  2. 02 Smart routing trims spend by sending easy calls to small models
  3. 03 Per-user, per-model, per-day usage you can export for chargeback

Everything IT needs to say yes to AI

SSO & MFA

OIDC, group-mapped policy

Model allowlists

Approve models per group

MCP tool gateway

Deny-by-default agentic tools

Governed embeddings

RAG through the control plane

Budget caps

Hard caps & auto-cutoff

Per-user quotas

Request & token rate limits

Smart routing

Cheapest capable model

Egress control

Deny-by-default allow-list

Provider failover

Circuit breaker on dead upstreams

Prometheus metrics

Ops & SIEM observability

Audit logging

Hash-chained, metadata-only

Self-hosted

Air-gap & GovCloud

Suite spotlight · open source

SecRecorder — transcription that never leaves your boundary

A self-hosted, OpenAI-compatible speech-to-text server (Whisper) with optional speaker diarization — for meeting notes and recordings. Runs on your own Apple Silicon or NVIDIA hardware, so audio and transcripts stay inside the accreditation boundary. Air-gap capable.

Self-hosted Whisper

MLX (Apple) or faster-whisper (CUDA/CPU)

Speaker diarization

Per-word labels + voiceprints (opt-in)

OpenAI-compatible

Drop-in /v1/audio/transcriptions

Air-gap ready

Weights load once — no outbound calls

SecRecorder on GitHub

Deploy it yourself —
or bring us in.

SecRouter and SecRecorder are open source (Apache 2.0) — clone them and run the secured stack in your boundary. When you need it done fast and accreditation-ready, we provide deployment, hardening, and CMMC/CUI support.