Local-first AI security gateway

Control what your AI can see and do.

TrustLayer sits between enterprise applications, models, and tools. It inspects every boundary and enforces your policies before sensitive data or risky actions move forward.

Local-firstPolicy-drivenOpenAI-compatible
TRUSTLAYER / LIVE POLICY TRACE
REQUEST 01INSPECTING

Summarize the attached internal report, then send the result to an external workspace.

01INPUTPASSED
02DOCUMENTPII FOUND
03MODEL OUTPUTREDACTED
04TOOL ACTIONREVIEW
✓
POLICY DECISIONHuman approval required
risk: external_write

Interactive control path

See every decision in the AI workflow.

Explore how one request moves through TrustLayer. Choose a scenario, then select any node to inspect what the gateway evaluates at that boundary.

TRUSTLAYER / REQUEST WORKFLOW

Swipe to explore the complete flow

TOOL GATE / 04

Human review before external action

The request asks a tool to write outside the trusted environment. TrustLayer holds execution until an authorized reviewer decides.

REQUIRE_REVIEW

One enforcement layer

Secure every AI boundary.

AI applications create new paths between users, company data, models, and tools. TrustLayer gives engineering and security teams one place to inspect those paths and apply consistent controls.

YOUR ENVIRONMENTApps & agentsInputs · Files · Requests
inspect
TrustLayer GatewayLOCAL
ScanClassifyDecideAudit
YOUR POLICIES ALLOW · REDACT · BLOCK · REVIEW
enforce
AI EXECUTIONModels & toolsOutputs · Calls · Actions

Defense in depth

Controls that follow the full request lifecycle.

01
⌁

Inspect inputs & files

Screen text and documents for prompt injection, secrets, personal data, obfuscation, and risky content before model access.

  • Deterministic scanners
  • Local semantic signals
02
⌾

Limit data exposure

Apply policy decisions to sensitive content with explicit outcomes that can allow, mask, block, or escalate the request.

  • PII and secret detection
  • Content redaction
03
⌘

Govern tool actions

Intercept tool calls before execution, enforce registries and role constraints, and route high-risk actions to a human reviewer.

  • Pre-execution checks
  • Human-in-the-loop
04
◎

Check every output

Inspect model and tool results again before they leave the gateway to reduce sensitive-data leakage at the final boundary.

  • Output leakage checks
  • Safe audit metadata

Deterministic enforcement

Models signal risk. Policies make the decision.

Semantic classifiers help identify ambiguous threats. TrustLayer keeps hard enforcement in a deterministic policy layer, so a model signal never gets the final word on its own.

01Fail with intentExplicit handling for model or control failures.
02Keep evidence usefulAudit trails retain decisions without logging raw secrets.
03Escalate uncertaintyRoute sensitive actions to a human instead of guessing.
POLICY ENGINEENFORCING
prompt_injection_score0.87
sensitive_datatrue
action_scopeexternal_write
MATCHED RULE

IF sensitive_data AND external_write
THEN require_human_review

ALLOWREDACTBLOCKREVIEW

Secure by changing one route

Change the route.
Keep the application.

Point an existing OpenAI-style client to TrustLayer and keep security in the execution path. Every request can be inspected before the model, every tool call before action, and every response before it returns to the user.

01Keep familiar client patternsPreserve the chat-completions request shape your application already uses.
02Centralize enforcementApply the same policy boundary across model access, agent actions, and tool execution.
03Retain provider flexibilityPlace one control layer in front of cloud or local OpenAI-compatible providers.
Python
from openai import OpenAI

client = OpenAI(
  base_url="http://trustlayer.local/v1",
  api_key="your-internal-key"
)

response = client.chat.completions.create(
  model="your-model",
  messages=[...]
)
✓ Request evaluated by TrustLayer policy
BEFORE THE MODELINGRESS

Stop unsafe context early.

Inspect prompts and documents for injection patterns, secrets, personal data, obfuscation, and file risk before an upstream model call is allowed.

BEFORE THE ACTIONTOOL GATE

Turn agent intent into governed action.

Intercept tool calls, check registered capabilities and role constraints, then hold sensitive or irreversible operations for human review.

BEFORE THE RESPONSEEGRESS

Keep sensitive output inside the boundary.

Recheck model and tool output, redact supported leaks, block unsafe responses, and retain decision evidence without logging raw secrets.

Current stage

Built to be measured before it is trusted.

TrustLayer is currently a working prototype under active evaluation. The focus is detection quality, false-positive analysis, policy behavior, and safe integration patterns. We do not make untested claims of production readiness.

Prototype Evaluation Pilot discovery

Pilot conversations

Deploying an internal AI assistant?

We are speaking with engineering and security teams to validate the gateway against real workflows, policies, and threat models.

Discuss a pilot