On-premise · Model-independent control layer

One secure route to approved LLMs

CyberPass sits between applications, employee agents and model providers. It inspects text, applies organization policy and selects an approved public or private route.

Gateway availableEndpoint beta
DeploymentInside customer infrastructure
ProtocolOpenAI-compatible
DecisionsAllow · Redact · Block · Route
OperationsEvents · Audit · SIEM
01 / PLATFORM

A gateway, not
another model.

Providers and upstream model IDs are configuration. Client applications use stable aliases, so a model can change without customer-specific product forks.

Available

AI Security Gateway

OpenAI-compatible client API, scoped identities, quotas, controlled egress, DLP, LLM Guard, policy-based routing and inspected responses.

Available

Data protection

Deterministic text detectors, tenant dictionaries, constrained regex and allow/redact/block modes.

Available

LLM Guard

Explainable prompt-injection and jailbreak risk signals. No claim of perfect detection.

Available

Events & SIEM

Metadata-only security events and CEF over Syslog UDP/TCP.

02 / DEPLOYMENT

The decision stays
inside your perimeter.

Gateway, control plane, policy store and security events run on customer-managed infrastructure. A CyberPass vendor cloud is not required.

CUSTOMER SECURITY BOUNDARY
01AApplicationscentral API route
01BEmployee devicesWindows Connector beta
02CyberPass Gatewayinspect · decide · route
03APrivate LLMlocal inference
03BPublic LLMapproved egress
03 / DELIVERY STATUS

Clear capability
boundaries.

Production readiness for a regulated environment is validated in the customer pilot; it is not implied by a website label.

CapabilityStatusBoundary
Gateway, DLP, Guard, Policy, EventsAvailableText, OpenAI-compatible traffic.
Windows and browser channelBetaConnector and DOM-based extension; not transparent TLS inspection.
OIDC/LDAP and customer PKIBaselineReusable protocols; the selected IdP, directory schema and certificate lifecycle require pilot validation.
KMS/HSM and Kubernetes HAPlannedCustomer-specific infrastructure extensions after requirements are fixed.
Independent penetration testExternal gateScope is prepared; report and remediation retest are not yet claimed.

Start with one controlled AI route.

Select one application, one private or public endpoint and measurable pilot acceptance criteria.

hello@cyberpass.kz →