Every frontier AI model. The security layer your clients expect.
OBEL™ is a secure AI gateway — PII scrubbed, content classified against sovereign frameworks, and every interaction committed to an immutable audit trail before a single token reaches any model. Use Claude, GPT-4o, Gemini, and more with the confidence your professional obligations demand.
The AI governance gap is structural — and widening
It's not a capability problem. Frontier models are extraordinarily capable. The barrier is governance — and it compounds with every agentic deployment. Every organisation with a compliance function faces it. Most have no answer.
35%+ CAGRenterprise AI adoption growth
Agentic Security
Agent tool calls are the new attack surface
An autonomous agent may execute dozens of LLM sub-steps, access file systems, query databases, and call external APIs — all without human review. Each tool call is a potential data egress event, a sovereignty violation, and an audit gap.
Zero trustapplied to every tool invocation
Autonomic Discovery
Static rule sets can't keep up with dynamic threats
Any fixed pattern library is a snapshot of yesterday's threat landscape. OBEL™'s Autonomic Discovery Engine closes this gap continuously — the security perimeter grows with each organisation's interaction patterns, not when a vendor ships a patch.
PII redacted before inferenceSovereign FAIL-SHUT gateAES-256-GCM encrypted vaultTamper-evident audit vaultRow-level data isolationNo data used for model trainingSIEM-ready event streamHITL gate on every agent actionGoverned RAG — ARGUS-i™ at retrieval, not just ingest
Type any message and see how OBEL classifies it before it reaches any AI model.
ARGUS-i™ Live Demo
Sovereign PII Scrubber & Classification Engine
Presets
Raw Input215 / 2000
Sovereign Scrutiny
Output appears here…
Audit Vault · Live Stream
Awaiting scan…
Defensive Intelligence
Gateway Architecture
Every request follows this path — no exceptions.
Scrubbing and classification run at $0.00. Inference only starts if the gate passes. A blocked request costs nothing — the model never sees it.
01
Receive
Raw prompt enters the gateway. OBEL intercepts before any AI model sees the text.
$0.00
02
Scrub
PII, API keys, and injection patterns stripped. The cleaned text advances — the original never leaves.
$0.00
03
Classify & Gate
ARGUS-i™ applies sovereign schema. PROTECTED+ content is hard-blocked here — the model is never called.
blocked = $0.00
04
Inference
Only gate-cleared, scrubbed prompts reach the model. You're billed on the cleaned input — never the raw text.
← billed here
05
Audit
Every interaction committed to the immutable vault before this step completes. No audit write, no inference proceeds.
$0.00
Other AI gateway providers may offer PII scrubbing — but only on paid tiers, without sovereign classification and without a pre-inference audit write. OBEL™ runs this pipeline on every request, on every plan, with no bypass.
Platform capabilities
Everything your team needs. Nothing that shouldn't be there.
PII Scrubbing
Every prompt is scanned and redacted before it reaches any model — names, emails, phone numbers, tax file numbers, financial identifiers, and credentials stripped at the gateway.
Enforced before every inference call
Audit event written per matched value
Block mode or audit mode per organisation
Sovereign Classification
ARGUS-i™ classifies every message in real time against PSPF, ISM, NZISM, UK NCSC, NIST, and NATO schemas. PROTECTED+ content is hard-blocked before inference — no bypass possible.
FAIL-SHUT gate — never FAIL-OPEN
Immutable sovereign schema per release
Configurable block threshold per tier
Tamper-Evident Audit Trail
Every AI interaction is committed to an immutable audit vault before the model is called. If the write fails, inference does not proceed. The commit identifier changes if any record is altered.
Pre-LLM blocking write — no audit, no inference
Append-only — no silent deletion
Cryptographic record per session
Cost Governance
Per-user and per-org spend limits enforced at the gateway before inference runs. No charge on blocked requests. Prepay credit and real-time usage visible to every admin.
Budget check before every LLM call
Prepay credit — impossible to overspend
Department-level sub-allocations
AES-256-GCM Credential Vault
API keys and secrets encrypted at rest with per-record nonces — reusing a nonce is cryptographically impossible. Decryption occurs server-side only. Keys never leave in plaintext.
Per-record nonces — no IV reuse
Key hint stored for rotation verification
Vault key never in the database
Multi-Tenant Workspaces
Row-level security isolates every organisation at the database layer. Every query is scoped to the authenticated user's organisation. Zero cross-tenant data access — ever.
Row-level security on every table
Admin role + department management
Service role never exposed to browser
Multi-Provider Model Routing
Access frontier models from OpenAI, Anthropic, Google, Meta, Azure, and more — all through one governed interface. Switch providers without changing your workflow or losing governance posture.
OpenAI · Anthropic · Google · Meta · Azure
Consistent governance across all providers
Model selection without API key exposure
Governed Image Generation
FLUX.1 and GPT Image 2 with ARGUS-i™ applied to every generation request — classification, PII scrubbing, NSFW pre-flight filtering, and C2PA provenance metadata stamped on every file.
Full ARGUS-i™ pipeline on every prompt
NSFW block before generation API called
C2PA provenance — attribution persists across platforms
SIEM Integration
Forward every governance event to your existing SIEM in real time — scrubber hits, classification decisions, blocked requests, audit writes, agent tool calls, and HITL actions. Configurable per organisation, with optional content inclusion under admin control.
Splunk · Microsoft Sentinel · Elastic · any webhook SIEM
Agent run events and tool call outcomes included
Optional content payload — off by default, admin-gated
Integrations & Skills Hub
Connect your enterprise stack — Notion, Jira, Salesforce, HubSpot, Slack, GitHub, Google Workspace, Zendesk, Asana, Linear, Workday, Outlook, and more. Each connection unlocks a governed set of skills your agents can invoke.
15+ enterprise apps via MCP
Per-app token vault — AES-256-GCM encrypted
Skills gated through ARGUS-i™ on every invocation
Agentic Foundry
Deploy governed autonomous agents that connect to your real systems. Mention @AgentName in chat to dispatch a task. Every tool call is inspected, every action can require human approval before it executes.
@mention dispatch — route tasks to agents in chat
HITL gate — approve or reject each tool call
Blueprint builder — configure authority and connectors without code
Governed Knowledge Bases
Retrieval-Augmented Generation (RAG) with OBEL's full governance stack. Upload your documents and chat with them — without leaking a single sensitive token. ARGUS-i™ classifies, scrubs, and re-scrubs every retrieved chunk before it reaches the model. Your data never trains an external model.
PII scrubbed from chunks at ingest and at retrieval
PROTECTED+ chunks quarantined — never stored or returned
Source citations alongside every answer
Document Studio
Governed AI document generation — every output through the same security gateway.
Draft contracts, reports, code, and diagrams with frontier AI — then export, audit, and reuse them. Every generation request passes through ARGUS-i™ before a word is drafted.
Template Intelligence
A governed document library — seeded and ready.
Every org gets a pre-built library of NDAs, employment contracts, service agreements, statements of work, consulting agreements, and more — each with required fields, formatting rules, and placeholder validation. Define your own types for custom workflows.
10+document types seeded per org
Secure AI Generation
No AI-generated document skips the security layer.
ARGUS-i™ runs on every generation request — classifying intent, scrubbing PII, and blocking sovereign violations before a word is drafted. Documents, code, diagrams, reports, and workflow outputs are all treated as governed artifacts, not free text.
Zero bypassARGUS-i™ on every generation call
Artifact Vault & Export
Every output saved, attributed, and exportable.
Generated artifacts are stored in your org vault — version-controlled and tied to the audit session that produced them. Export any document as a branded PDF. Every export is attributable to a user, a session, and a complete governance record.
Full chainprompt → draft → export → audit
Agentic Foundry
Governed agents that connect to your real systems.
Deploy autonomous agents against Notion, Jira, Salesforce, Slack, and 10+ other enterprise apps. Mention @AgentName in chat to dispatch a task instantly. Every tool call is inspected by ARGUS-i™ and can require a human sign-off before it executes.
@ Mention Dispatch
Route tasks to agents directly from chat.
Type @AgentName followed by a task in any conversation and OBEL™ dispatches it to the correct agent — no context switch, no separate interface. The agent's tool calls, reasoning steps, and final response stream back inline.
@mentionagent dispatch from chat
HITL Governance
Every tool call can require human approval.
Configure agents at any authority level. At Level 1, agents observe and report. At Level 2, agents can act — but high-risk tool calls pause the run, surface a proposed action to an administrator, and wait for approval or rejection before proceeding. The SSE stream stays live throughout.
Zero blind executionHITL gate on every action
Blueprint Builder
Connect apps, set authority, deploy — no code.
The Blueprint builder lets you configure an agent's identity, connected apps, and read/write permissions in a single view. Authority level is automatically derived from the permissions you grant — read-only agents can never write, regardless of what an LLM requests.
Authority-lockedpermission derived from connector config
ARGUS-i™ Detection Packs
Jurisdiction-aware PII rules, shipped and ready.
ARGUS-i™ ships with certified detection packs covering every major regulatory jurisdiction. Each pack is a portable bundle of regex rules, replacement tokens, and severity classifications — applied to every message before it reaches inference. And if your jurisdiction isn't covered yet, you can add it.
🌐Certified
Global
Universal patterns
🇦🇺Certified
Five Eyes
FVEY intelligence frameworks
🇪🇺Certified
European Union
GDPR · ePrivacy Directive
🌍Certified
MENA
UAE · KSA · Egypt
🌏Certified
Asia-Pacific
SGP PDPA · AUS Privacy Act
🤝Open
Community
Submit for your jurisdiction
Rule Anatomy
Every rule is a regex with a purpose.
Each detection rule carries a pattern, a jurisdiction-scoped replacement token, a severity level (low / medium / high / critical), and a PII event type. ARGUS-i™ evaluates every active rule against every message — before a single token reaches the model.
[REDACTED:VE_CEDULA]replacement convention — zero raw PII to inference
Built-in Coverage
Five certified packs ship with every account.
Global covers universal patterns (emails, phone numbers, API keys). Regional packs add jurisdiction-specific IDs: UK National Insurance, EU VAT numbers, Australian TFNs, UAE Emirates IDs, Singapore NRICs, and more. Every built-in rule is reviewed and certified by ninthLABS.
40+ rulesacross 5 certified packs, active from day one
Community Packs
Your jurisdiction. Your rules. Reviewed and published.
Write a pack.json, validate it against the open schema, and submit it through the OBEL™ governance panel. ninthLABS reviews each pack for schema validity and safety before approving it — once live, it's available to every organisation on the platform.
Any countryVenezuela, Brazil, South Africa — if there's a regulation, it can have a pack
Retrieval-Augmented Generation
RAG your compliance team can actually approve.
Standard RAG retrieves documents and hands them straight to the model. OBEL™ runs every retrieved chunk through ARGUS-i™ classification and PII scrubbing before a single token reaches inference — at retrieval time, not just at upload.
Double Scrub
PII removed at ingest — and again at retrieval.
Most RAG pipelines scrub once at upload and trust the result forever. OBEL™ re-runs the PII scrubber and ARGUS-i™ classifier on every chunk at the moment of retrieval, so updated classification rules apply retroactively — without re-indexing.
2× scrubat ingest and at every retrieval
Source Citations
Every answer is traceable to its source document.
OBEL™ surfaces which chunks grounded each response so your team knows exactly where an answer came from. Every retrieval event is written to the immutable security event log — auditable, exportable, and SIEM-ready.
Full traceabilityevery retrieved chunk cited and logged
Zero Training Risk
Your documents never leave your organisation.
Chunks are stored in your own Supabase instance under pgvector, never sent to a shared embedding service, and never used to fine-tune an external model. Your organisation's row-level isolation boundary holds — even during retrieval.
Zero egressyour data stays in your infrastructure
Start free. Scale when you're ready.
Start with a 14-day free trial — full Individual Pro access, no credit card required. Upgrade to a team plan when you need multi-member workspaces and full governance.