A Sybersafe Product

The Private AI Gateway.
Use every model. Leak nothing.

ZDR-enforced routing across OpenAI, Anthropic, and Gemini — with an audit trail your board can read. Governance for the way your teams actually use AI.

No form? Book straight onto our calendar from the enterprise brief. Prefer early access instead? Join the waitlist.

Request Early Access

A short waitlist for security, compliance, and platform leaders. We'll create your Shield workspace and email a setup link.

Complete the human check above to continue.

SOC 2 alignedHIPAA alignedZero Data RetentionModel-agnosticEU AI Act ready

The gateway

Enterprise AI has an outbound problem. Shield fixes it at the wire.

Model governance, not model bans

One dispatcher, every provider. Route by policy, cost, latency, and residency — not by which URL someone bookmarked.

Zero Data Retention, enforced

Shield strips, grounds, and proxies every prompt so no provider learns from your data. ZDR is the default, not a checkbox.

An audit trail your board can read

Every prompt, model, and surface — logged, attributed, and mapped to HIPAA, SOC 2, ISO 27001, and the EU AI Act.

Who it's for

Four people usually own this problem. Shield answers all four.

CISO & security

Stop unsanctioned AI egress without a ban you cannot enforce. One inventory, one control point, one log.

Compliance & risk

Evidence per request, mapped to HIPAA, SOC 2, ISO 27001, and the EU AI Act — not a policy document nobody can prove.

General Counsel

Confidentiality and privilege preserved, with a defensible record of what left and under which terms.

CIO & platform

Every team on frontier models without per-team keys, duplicate spend, or a code change to switch providers.

How it works

Three steps, not a transformation programme

01

Connect the path

Point people and applications at one gateway endpoint bound to your corporate identity. No endpoint agents, no rewrite.

02

Set the policy

Choose approved models, residency, and what may leave. Sensitive content is minimized before dispatch, automatically.

03

Report the evidence

Every request is attributed and logged, mapped to the frameworks your auditors and board already ask about.

See the full request path

Why not direct access

Handing every team an API key is not a governance strategy

Direct model accessDsyfer Shield
Data protectionEach team's code and each provider's defaultsMinimization and Zero Data Retention enforced centrally
Audit evidenceScattered logs, rarely attributableOne attributable record per request
Model choiceHard-coded; switching means a code changePolicy-based routing across every provider
Shadow AIInvisible and growingSanctioned path is the easiest path
Read the full comparison

Compliance mapping

One log, four frameworks

HIPAA

Minimum necessary payloads, access and audit controls, transmission security

SOC 2

Logical access, change monitoring, and continuous evidence of controls

ISO 27001

Annex A access control, logging, and supplier management records

EU AI Act

System inventory, transparency records, and human oversight logs

Implementation

Thirty days, start to evidence

Days 1–5

Readiness review, AI surface inventory, and policy draft agreed.

Days 6–15

Gateway live for a first team, identity bound, models allow-listed.

Days 16–25

Applications migrated off direct keys; minimization rules tuned.

Days 26–30

Reporting handed to compliance; board-readable summary delivered.

Security questions, answered

Does Shield see our prompt content?

Only to apply your policy in flight. What is retained in the audit log is your choice, including minimized or metadata-only records.

Do providers train on what we send?

No. Shield dispatches only to models under enforced Zero Data Retention terms, so nothing you send is stored or trained on after inference.

Do we have to ban ChatGPT or Copilot?

No. Bans push usage onto personal devices where you have no visibility. Shield governs the path instead of policing the tool.

What evidence do auditors get?

Per-request records of the caller, the model, the terms in force, and the controls applied — mapped to HIPAA, SOC 2, ISO 27001, and the EU AI Act.

How fast can we be live?

A first governed team is usually running within days; a staged rollout across business units typically lands inside 30 to 60 days.

Can we keep our existing provider contracts?

Yes. Bring your own keys and negotiated rates, and route them through the gateway.

Start with a free AI Readiness Review

Twenty minutes, no obligation. You leave with a written summary of where AI data is going today and the controls a board would expect. Built for CISOs, CIOs, Compliance Officers, and General Counsel.