Security
Work confidently with production-grade controls.
Governance, auditability, and access control sit in front of every provider — so teams move fast without bypassing risk controls.
- Organization workspaces with owner / admin / member roles
- SSO-ready org settings via WorkOS
- Scoped keys with model allowlists and spend caps
Sign in once. Enforce roles after.
Workspaces use WorkOS-ready SSO and role-based membership. API keys stay scoped to models, RPM/TPM, and spend caps — separate from the human login.
Features for teams that ship AI
These are product controls in the gateway and dashboard — not borrowed certification logos.
Security you can inspect
As a gateway, we sit on the request path. That is why controls are enforced in code — not promised as a future SOC badge.
- Auth and policy before every provider hop
- Choose UK or EU residency on the org
- Trust Center for approvals, policies, and violations
SSO
WorkOS
Residency
UK / EU routing
Audit
Immutable logs
Spend
Caps on every key
Trust center in the product
Policies, approvals, violations, and compliance views live under Dashboard → Trust Center once you are signed in.
Read how we handle data
Account, usage, and prompt handling are spelled out in the privacy policy.