Skip the build
Scrubbing, classification, policy, and audit are table stakes for any serious AI product - and slow to build well.
Most teams underestimate how much of this is edge cases: entropy tuning, false-positive rates, chain-of-custody for audit records.
Sell to regulated buyers sooner
Government and enterprise buyers ask about PII handling and audit trails on day one of procurement.
GaaS gives you a real, verifiable answer instead of a roadmap promise - it closes deals that would otherwise stall in security review.
Your rules, our engine
You and your customers configure the policy - risk tiers, thresholds, classification ceilings - the engine enforces it.
The policy and access-control layers are generic by design: they don't assume OBEL's own product shape, only yours.
Isolated by design
GaaS runs on its own API host, separate from OBEL's own product traffic, with separately scoped keys.
A key issued for GaaS can't reach OBEL's own developer/proxy surface, and vice versa - no shared blast radius.
B2B2B, not another vendor booth
We work with you directly to integrate GaaS into your platform - this isn't a self-serve add-on for your end users.
Usage-based pricing, sales-assisted onboarding, and a connector pattern built around how platforms actually integrate third-party APIs.
Audit-ready from day one
Every governed decision your platform makes through GaaS is hash-chained and independently verifiable.
When your customer's auditor asks 'can you prove this wasn't tampered with,' the answer is yes - and they can check it themselves.
What you get
The core governance engines, one API.
These four are the foundation. GaaS is now up to 11 governed endpoints in total - injection detection, agent tool-call classification, usage/cost governance, and compliance export included. See the full capability list.
Scrubbing & PII Detection
- One API call scrubs PII, credentials, and secrets out of any text your platform handles
- Same detection engine (ARGUS-i) that runs inside OBEL's own production traffic
- Configurable rule sets per calling org, tuned to your customers' data shapes
- Cleaned text and a structured hit list returned in one response
Classification & Access Control
- PSPF-aligned classification levels, from UNOFFICIAL to TOP SECRET, out of the box
- A hard ceiling per org caps what classification level can be read or retained
- Retention windows enforced at the API layer, not left to your own application code
- Gives platforms selling into government or regulated sectors a defensible control
Policy Engine
- Rules matched on event type, risk tier, and resource type - most specific match wins
- Effects: allow, warn, block, or require approval - enforced server-side, not advisory
- Falls back to a simple risk-tier threshold for orgs that haven't written custom rules
- Lets your platform ship governance controls your customers configure themselves
Tamper-Evident Audit Ledger
- Every governance decision is hash-chained, not just logged - verifiable, not just claimed
- Chain verification algorithm is published so you or your customers can independently check it
- Gives your platform an answer ready for the compliance question every enterprise buyer asks
- One less system you have to build, operate, and defend under audit