The product

Policy runs before the action does.

Gateplex sits inline between your agents and the systems they touch. Every action is evaluated against your rules first, resolved to a verdict, and written to a tamper-evident record.

Intercept feedProduction environment
TimeAgentAttempted actionRule evaluatedVerdict
14:02:44.812payments-reconciliationInitiate wire transfer, 148,200.00 GBPSpend Limit, 100k GBPBLOCK
14:02:41.304mortgage-draftingGenerate customer offer letterKeyword Flag, disclosure setALLOW
14:02:39.118kyc-reviewRead customer record, national ID fieldPII ShieldPENDING_APPROVAL
14:02:35.550collections-outreachSend message to customer segment 4Output Length LimitFLAG
14:02:31.207treasury-sweepExternal call, unlisted vendor domainAPI Scope ControlBLOCK
Record hash 8b2f91a4c1dePrevious 4d07ce22ba90Chain verified
Figure 2.1/The live intercept feed. Each row is a single agent action and the rule that decided it.

Deterministic by design.

There is no language model in the decision path. The same action, evaluated against the same rules, returns the same verdict every time.

Evaluated inline, before execution
The action is intercepted at the boundary. A blocked action never reaches the downstream system at all.
The server decides
The client cannot override the verdict returned by Gateplex. Enforcement is not advisory.
Explainable outcomes
Every verdict cites the rule that produced it, so a reviewer reads a decision rather than inferring one.

Four verdicts. No ambiguity.

VerdictEffect on the actionRecord
ALLOWProceeds.Logged with the evaluation result.
BLOCKStopped at the boundary.Logged with the rule that stopped it.
FLAGProceeds, and is marked for review.Surfaced in the live feed.
PENDING_APPROVALHeld. The agent waits for a decision.Queued to a named reviewer, decision recorded against their identity.

Ten rule types, configured per project.

RuleWhat it governs
Spend LimitCaps the monetary value an agent can move in a single action or window.
PII ShieldDetects personal data in an agent's input or output before it moves.
Keyword BlockStops actions containing prohibited terms.
Keyword FlagRecords actions containing sensitive terms without stopping them.
Rate LimiterConstrains how frequently an agent can act.
RuleWhat it governs
API Scope ControlRestricts which external endpoints and domains an agent may reach.
Regex Pattern MatchMatches structured identifiers such as account or card formats.
Output Length LimitBounds the size of generated output.
Prompt Injection DetectorIdentifies attempts to override the agent's instructions.
Repetition DetectorCatches looping or repeated agent behaviour.
Guardrail configurationFinancial Services Pack
  • FIN-001Spend LimitTransfers above 100k GBPBLOCK
  • PII-004PII ShieldNational ID, IBAN, card numberPENDING_APPROVAL
  • API-011API Scope ControlAllow-listed vendor domainsBLOCK
  • SEC-022Prompt Injection DetectorInbound instruction payloadsPENDING_APPROVAL
  • OPS-030Rate Limiter60 actions per agent per minuteFLAG
Figure 2.2/Guardrail configuration for a Financial Services deployment.

Compliance packs.

Preconfigured rule sets for the regimes our customers are held to, editable once applied.

EU AI Act Article 12 Pack
Logging and traceability configuration aligned to the record-keeping obligations in Article 12, with exports formatted for regulatory review.
HIPAA Safety Pack
Protected health information controls, with PII Shield and regex matching configured for clinical identifiers.
Financial Services Pack
Spend limits, scope controls, and customer data protections tuned for payments, lending, and treasury agents.

Human approval, on the record.

Rules configured to require approval return PENDING_APPROVAL. The action is held until a named reviewer approves or rejects it, and their identity is derived server side, not supplied by the client.

Approval queue2 awaiting a named reviewer
kyc-reviewPENDING_APPROVAL

Read customer record, national ID field

PII Shield · raised 14:02:39 · execution held

ApproveRejectDecision recorded against reviewer identity
credit-underwritingPENDING_APPROVAL

Approve facility above delegated authority

Spend Limit, 250k GBP · raised 13:58:04 · execution held

ApproveRejectDecision recorded against reviewer identity
Figure 2.3/The approval queue, with held actions awaiting review.

Integration is one endpoint.

REST API

A single intercept endpoint. Send the action, receive the verdict, act on it.

Python SDK

The gateplex-python package on PyPI, including drop-in patches for the OpenAI and Anthropic clients.

MCP server

Published on Smithery, Glama, and MCP.so for agents that speak the Model Context Protocol.

See it against your own agents.