AI Security Gateway
OpenAI-compatible client API, scoped identities, quotas, controlled egress, DLP, LLM Guard, policy-based routing and inspected responses.
On-premise · Model-independent control layer
CyberPass sits between applications, employee agents and model providers. It inspects text, applies organization policy and selects an approved public or private route.
Providers and upstream model IDs are configuration. Client applications use stable aliases, so a model can change without customer-specific product forks.
OpenAI-compatible client API, scoped identities, quotas, controlled egress, DLP, LLM Guard, policy-based routing and inspected responses.
Deterministic text detectors, tenant dictionaries, constrained regex and allow/redact/block modes.
Explainable prompt-injection and jailbreak risk signals. No claim of perfect detection.
Metadata-only security events and CEF over Syslog UDP/TCP.
Gateway, control plane, policy store and security events run on customer-managed infrastructure. A CyberPass vendor cloud is not required.
Production readiness for a regulated environment is validated in the customer pilot; it is not implied by a website label.
| Capability | Status | Boundary |
|---|---|---|
| Gateway, DLP, Guard, Policy, Events | Available | Text, OpenAI-compatible traffic. |
| Windows and browser channel | Beta | Connector and DOM-based extension; not transparent TLS inspection. |
| OIDC/LDAP and customer PKI | Baseline | Reusable protocols; the selected IdP, directory schema and certificate lifecycle require pilot validation. |
| KMS/HSM and Kubernetes HA | Planned | Customer-specific infrastructure extensions after requirements are fixed. |
| Independent penetration test | External gate | Scope is prepared; report and remediation retest are not yet claimed. |
Select one application, one private or public endpoint and measurable pilot acceptance criteria.
hello@cyberpass.kz →