Secure AI use
SSO-authenticated requests, per-user allowlists for models and the MCP tools your agents call, and a deny-by-default egress gate. Data only reaches destinations you've authorized — CUI never leaves the boundary.
Open source · Apache 2.0 · Built for defense & regulated industry
Govern AI use. Contain AI spend.
SecRouter is the secure API gateway between your teams and every model — authenticating every request, enforcing policy, controlling egress, and capping spend across the organization. Open source and self-hosted: deploy it yourself, or bring us in for deployment support.
Apache 2.0Self-hostedDeny-by-default egressAir-gap ready
The control plane for AI
Sit between your people and the models. Inspect every request, enforce every policy, and meter every dollar — without slowing teams down.
SSO-authenticated requests, per-user allowlists for models and the MCP tools your agents call, and a deny-by-default egress gate. Data only reaches destinations you've authorized — CUI never leaves the boundary.
Hard budgets and rate limits per group and user. Route each request to the cheapest capable model and cut off runaway usage before the invoice arrives.
Hash-chained, tamper-evident audit of every request, decision, and route — metadata only, never prompt content. RBAC and SSO, with exportable evidence for auditors and accreditation.
Drop-in architecture
Point your existing SDKs at SecRouter. Change the base URL — keep your code.
Your teams & apps
SecRouter control plane
Models & tool servers
Open source · Apache 2.0 · Self-hosted
SecRouter governs the AI traffic — but standing that up in a closed or regulated network takes identity, inference, collaboration, and the plumbing to tie them together. Each piece is self-hostable and air-gap ready. Run the ones you need; drop the ones you already have.
Single sign-on (Authentik) — pre-wired OIDC blueprints and suite branding. Drop it the moment you have Okta, Entra, or Keycloak.
Internal ACME (RFC 8555) certificate authority — issues the suite's TLS certs on closed or air-gapped networks.
Zero-dependency authoritative DNS — resolves the suite's internal *.internal names when you run no DNS of your own.
A friendly control plane for vLLM — curated model catalog, load/unload, health management, and an OpenAI-compatible endpoint. SecRouter routes to it.
The governed AI gateway at the center — authenticate every request, enforce model/tool/budget policy, gate egress, fail over providers, and log every decision.
Agentic harness (pi) — merge-request review, static analysis, docs and test generation over an affordance engine. Every call governed through the gateway.
Auditable team chat and agentic chat in one app — SSO via SecSSO, tamper-evident hash-chained audit, CUI marking and local DLP, and owner-gated coding agents driven right from a channel. Every model call governed through SecRouter, per person.
Self-hosted Whisper transcription with optional speaker diarization — meeting audio and transcripts never leave the boundary.
Edge reverse proxy — one HTTPS front door (:443) for the suite's web and API services, FIPS-clean on hardened hosts.
Release train and deploy orchestration — one pinned, tested suite version per target, from a macOS eval box to a FIPS-ready Fedora host.
Every component ships as one pinned, tested set through SecDeploy — and SecAgent and its pi CLI ship with LeanCTX context compression wired in, hardened and on by default.
Security & deployment
Run SecRouter fully self-hosted, in GovCloud, or air-gapped. Nothing leaves your boundary unless policy says so — and you hold the keys.
Read the security brief →No outbound calls required — route only to in-boundary or GovCloud endpoints.
OIDC SSO with MFA; group and role policy mapped to your IdP.
Prompt and response content is never stored — only decisions, counts, and hashes.
Hash-chained audit trail, exportable for accreditation.
Cost control
Attribute spend down to the principal, set hard caps, and route to cheaper models automatically. Finance gets one bill; IT gets the controls.
OIDC, group-mapped policy
Approve models per group
Deny-by-default agentic tools
RAG through the control plane
Hard caps & auto-cutoff
Request & token rate limits
Cheapest capable model
Deny-by-default allow-list
Circuit breaker on dead upstreams
Ops & SIEM observability
Hash-chained, metadata-only
Air-gap & GovCloud
Suite spotlight · open source
A self-hosted, OpenAI-compatible speech-to-text server (Whisper) with optional speaker diarization — for meeting notes and recordings. Runs on your own Apple Silicon or NVIDIA hardware, so audio and transcripts stay inside the accreditation boundary. Air-gap capable.
MLX (Apple) or faster-whisper (CUDA/CPU)
Per-word labels + voiceprints (opt-in)
Drop-in /v1/audio/transcriptions
Weights load once — no outbound calls
SecRouter and SecRecorder are open source (Apache 2.0) — clone them and run the secured stack in your boundary. When you need it done fast and accreditation-ready, we provide deployment, hardening, and CMMC/CUI support.