FAQ

Enterprise AI governance, answered

The questions security, compliance, and legal leaders ask us most — about how a private AI gateway works, what Zero Data Retention actually guarantees, what evidence auditors accept, how long a rollout takes, and what it costs.

Basics

What is a private AI gateway?

A single organization-controlled entry point for every AI request, which applies data-protection rules, routes to approved models, enforces Zero Data Retention, and logs every call in an attributable audit record.

What is Dsyfer Shield?

Shield is a private AI gateway for enterprises. It sits between your people and applications and the model providers, so teams can use OpenAI, Anthropic, and Gemini under one governed, audited path.

Does Shield replace ChatGPT or Copilot?

No. Shield governs access to models rather than replacing the interfaces people like. Teams keep working the way they prefer while traffic flows through a controlled route.

Is Shield model-agnostic?

Yes. Any approved provider can be routed to, and routing policy can change without touching application code.

Data protection

What does Zero Data Retention mean?

The provider does not store your prompt or response after inference and does not use either for training, evaluation, or human review.

Do providers train on our prompts?

Not under enterprise zero-retention terms — but those terms are per contract and per endpoint. Shield only dispatches to models whose current terms satisfy your policy.

Is sensitive data removed before it leaves?

Yes. Payloads are classified and minimized — stripped, tokenized, or replaced with grounded references — before dispatch, so a mistake is contained rather than catastrophic.

Where is our data processed?

Routing is residency-aware, so requests only reach models hosted in the regions you approve.

Do you store our prompts?

Shield retains the audit record you configure. Content retention is your decision, including minimized or metadata-only logging.

Compliance and audit

Which frameworks does Shield map to?

Logs and controls are mapped to HIPAA, SOC 2, ISO 27001, and the transparency and record-keeping expectations of the EU AI Act.

Can we use AI on protected health information?

Yes, when processing is covered by a business associate agreement, payloads are limited to the minimum necessary, and access is attributable and logged. Shield enforces all three.

What evidence do we get for an audit?

Per-request records showing the caller's identity, the model and terms in force, the controls applied, and the outcome — exportable for assessors.

Does Shield help with EU AI Act obligations?

It supplies the inventory, logging, and human-oversight records those obligations assume you can produce. It does not classify your systems for you.

Can we prove nobody sent data to an unapproved model?

Yes — unapproved models are unreachable through the gateway, and the log shows the complete set of dispatches.

Deployment and operations

How long does a rollout take?

A first governed team is typically live within days. A full rollout across applications and business units is usually staged over 30 to 60 days.

Does Shield need agents on endpoints?

No. It operates at the request path, not the device.

How does authentication work?

Requests are bound to corporate identity, so entitlements and offboarding follow your existing directory.

What happens if a provider has an outage?

Traffic reroutes to an approved alternative model within policy, rather than breaking the application.

What is the latency impact?

Routing overhead is milliseconds against inference measured in hundreds of milliseconds. Choosing the fastest compliant model often nets an improvement.

Can we bring our own provider keys?

Yes. Existing enterprise agreements and negotiated rates can be used through the gateway.

Cost and commercial

Does a gateway increase our AI spend?

Usually it lowers it. Routing sends routine work to cheaper models, reserves frontier models for work that needs them, and removes duplicate seat purchases across teams.

Is there a free option?

Yes. Dsyfer Shield Free lets a team start on a governed path immediately, with paid tiers adding enterprise controls and reporting.

How do we start without a procurement cycle?

Begin with a free AI Readiness Review. It produces a written summary of current exposure that most risk committees accept as the basis for a scoped pilot.

Request an AI Readiness Review — free

A 20-minute review of how your teams use AI today, which models are in play, and the controls a board would expect. No obligation.