Inspect inputs & files
Screen text and documents for prompt injection, secrets, personal data, obfuscation, and risky content before model access.
- Deterministic scanners
- Local semantic signals
Local-first AI security gateway
TrustLayer sits between enterprise applications, models, and tools. It inspects every boundary and enforces your policies before sensitive data or risky actions move forward.
Summarize the attached internal report, then send the result to an external workspace.
risk: external_write
Interactive control path
Explore how one request moves through TrustLayer. Choose a scenario, then select any node to inspect what the gateway evaluates at that boundary.
Swipe to explore the complete flow
The request asks a tool to write outside the trusted environment. TrustLayer holds execution until an authorized reviewer decides.
REQUIRE_REVIEWOne enforcement layer
AI applications create new paths between users, company data, models, and tools. TrustLayer gives engineering and security teams one place to inspect those paths and apply consistent controls.
Defense in depth
Screen text and documents for prompt injection, secrets, personal data, obfuscation, and risky content before model access.
Apply policy decisions to sensitive content with explicit outcomes that can allow, mask, block, or escalate the request.
Intercept tool calls before execution, enforce registries and role constraints, and route high-risk actions to a human reviewer.
Inspect model and tool results again before they leave the gateway to reduce sensitive-data leakage at the final boundary.
Deterministic enforcement
Semantic classifiers help identify ambiguous threats. TrustLayer keeps hard enforcement in a deterministic policy layer, so a model signal never gets the final word on its own.
0.87trueexternal_writeIF sensitive_data AND external_write
THEN require_human_review
Secure by changing one route
Point an existing OpenAI-style client to TrustLayer and keep security in the execution path. Every request can be inspected before the model, every tool call before action, and every response before it returns to the user.
from openai import OpenAI
client = OpenAI(
base_url="http://trustlayer.local/v1",
api_key="your-internal-key"
)
response = client.chat.completions.create(
model="your-model",
messages=[...]
)
Inspect prompts and documents for injection patterns, secrets, personal data, obfuscation, and file risk before an upstream model call is allowed.
Intercept tool calls, check registered capabilities and role constraints, then hold sensitive or irreversible operations for human review.
Recheck model and tool output, redact supported leaks, block unsafe responses, and retain decision evidence without logging raw secrets.
Current stage
TrustLayer is currently a working prototype under active evaluation. The focus is detection quality, false-positive analysis, policy behavior, and safe integration patterns. We do not make untested claims of production readiness.
Pilot conversations
We are speaking with engineering and security teams to validate the gateway against real workflows, policies, and threat models.
Discuss a pilot