VPC-native · 2 patents pending

An agent just acted on your production systems. Can you prove what it did, and why it was allowed?

Gateplex sits inline between your agents and your production systems. Every tool call is evaluated against your policy set before it executes, blocked server side when it violates, and written to a hash chained audit record your regulator can verify.

Decision path
No LLM
Verdict path
Evaluated before execution
Payload egress
Zero
gateplex control plane
enforcing
FIN-001Wire transfers over $5,000
BLOCK
PII-004PII egress sanitisation
Masked in the audit record
BLOCK
DAT-014SQL write restriction
BLOCK
OPS-022Output length ceiling
off
Last enforcement
wire_transfer $48,200 blocked
7f3a...e91c chain verified
Deployment
VPC-Native / Docker Edition
Data boundary
Zero Data Egress Guarantee
Integrity
SHA-256 Cryptographic Audit Trails
Regulatory
Built for EU AI Act, SOC 2, and HIPAA audit requirements
Financial services
Built for the oversight and audit trail expectations in Qatar Central Bank's AI Guideline and SAMA's Cyber Security Framework
01Board exposure

Your board will ask three questions.

Q1
What did the agent do
Full intercepted payload, tool name, and target system.
Q2
Why did it do it
The exact rule that matched, with the values that triggered it.
Q3
Who approved it
Reviewer identity derived server side from the authenticated session.

Gateplex produces the evidence that answers all three before your auditor asks. Start with a fixed-fee, 30-day Shadow Compliance Audit. No code changes required.

02Data topology

One hop. Inside your perimeter.

The proxy runs where your workloads run. Agent payloads are evaluated in memory against your rule set and are never forwarded to Gateplex infrastructure. In the air-gapped edition there are no outbound connections at all.

request path · inline proxy topology zero data egress
01 / LLM tool call

Autonomous Agent

  • OpenAI / Anthropic / Bedrock
  • LangChain · CrewAI · MCP
intercept
02 / Deterministic engine

Gateplex Inline VPC Proxy

  • Rule match. No model inference.
  • Server-side evaluation
Runs inside your VPC
Air-gapped edition available
Payloads never leave the perimeter
forward
03 / Core banking · CRM · SQL

Target Enterprise API

  • Reached only on ALLOW
  • Blocked calls never egress
ALLOW
Forwarded unchanged. Logged and hash chained.
BLOCK
Dropped at the proxy. Target API never sees the call.
HOLD
Escalated to a named human reviewer before execution.
03Failure modes

Your AI agents are executing actions. Are you governing them?

risk-01Ungoverned

Agentic Drift

Scope creep, at machine speed

A procurement agent approves a $24,000 vendor contract. Nobody scoped it to sign anything. It reasoned its way there, one plausible step at a time, and every step looked reasonable in isolation.

risk-02Ungoverned

PII Exposure

Customer data does not leak in one dramatic breach. It leaks in fragments: an SSN echoed into a third-party ticketing API, a home address quoted back in a summary, a card number passed to a tool that logs everything it receives.

Each fragment is small. The disclosure obligation is not.

risk-03Ungoverned

Financial Risk

Refunds issued. Terms negotiated. Payments released. Most of it correct, some of it duplicated, and none of it reviewed by a person before the money moved.

The question is not whether the agent was wrong. It is whether you can show who authorized it.

04Rule testing sandbox

Toggle a policy. Watch the verdict change.

This is the same evaluation order the engine uses in production: rules are matched in sequence, the strictest verdict wins, and an audit record is written before the caller receives a response.

policy set · acme-bank / treasury3 of 3 active
Inbound tool call
Agent
treasury-ops-01
Tool
wire_transfer
Amount
$48,200 USD
Beneficiary
ACC-9931-XT
Memo
Vendor payout, contact ssn 401-55-8812
live audit terminal

Awaiting call. Toggle policies on the left, then run the simulation.

05Two buyers, one control plane

Built for the people who sign off and the people who ship.

Evidence a regulator will accept, produced automatically.

Enforcement is deterministic. A rule either matched or it did not. There is no model in the decision path to explain away in an audit.

Request a Shadow Audit
Signed compliance exports
Period reports covering policy triggers, per-agent risk, and hash chain verification status.
Deterministic enforcement
Rule evaluation is code, not inference. The same input always yields the same verdict.
Audit questionnaire relief
Answer control questions with a generated report instead of an engineering interview.
Regulatory alignment
EU AI Act Article 12 logging and Annex III oversight, mapped to SOC 2 and HIPAA control language.
Named human oversight
Reviewer identity is derived server side from the session, never supplied by the client.
06Deployment

Runs where your compliance boundary already is.

Gateplex Cloud

Available now

Live in minutes. We handle infrastructure and updates. EU, US, and GCC/MENA residency options.

VPC / Docker Edition

Enterprise

Runs entirely inside your AWS, Azure, or GCP account. Agent payloads never cross your perimeter.

Air-Gapped On-Prem

Enterprise

Fully self-hosted with no outbound connections. Built for banks and government-adjacent entities.

Article 50: In effect Aug 2, 2026 · Annex III: Dec 2, 2027

Article 50 is already in effect. Annex III is next.

Article 50 transparency obligations took effect August 2, 2026. Any AI agent interacting with users must now disclose it is AI. Annex III high-risk system obligations follow December 2, 2027. Enterprise procurement cycles run 6 to 12 months, which means the window to be ready opens now, not later. Gateplex delivers tamper-evident audit trails, transparency reporting, and human oversight out of the box.

See compliance map
07Where Gateplex fits

Category, not scorecard.

The agent tooling market splits into distinct categories. We describe those categories rather than publish capability scorecards for other vendors, because their products change faster than any comparison table can stay honest.

Agent and prompt security
Zenity, Lakera Guard (Check Point), Prompt Security (SentinelOne)

Threat centric. Detecting and blocking prompt injection, jailbreaks, and data exfiltration attempts against AI applications.

ML and LLM observability
Galileo, Arthur

Quality centric. Evaluating model output, tracing LLM applications, and monitoring drift and performance over time.

Governance and enforcement
Gateplex

Evidence centric. Intercepting each agent action before execution, enforcing business rules, and producing the audit record a regulator or auditor will ask for.

Pre-execution enforcement. Blocked actions never reach the downstream tool.
Hash-chained audit log with server-side SHA-256 chaining and verification.
Human-in-the-loop approval queue with server-derived reviewer identity.
Compliance report export covering policy triggers, per-agent risk, and chain status.
MCP server card published for MCP registry discovery.
Cloud, VPC, and on-premise deployment, including EU, US, and GCC/MENA residency.

Category descriptions are our own summary of how these products position themselves publicly. They are not capability claims. Verify any vendor against their current documentation before making a buying decision.

Shadow compliance audit · 30 daysNo code changes

See what Gateplex would catch in your environment.

A 30-day Shadow Compliance Audit runs against your actual agent traffic with no code changes required. You get the same evidence a regulator would ask for, before they ask for it.

Prefer to explore the API first? Read the docs →