TruCert puts one governed, OpenAI-compatible API between your applications and every AI provider — running on your own infrastructure, so prompts and data never leave your network. Then it turns that live traffic into evidence your auditor can check.
If any of this is your company, you're normal. You're also exposed.
Every team buys its own AI subscriptions. Finance sees a pile of invoices, not a picture.
If an AI tool misbehaves today, how long until someone cuts its access everywhere? Hours? Days?
Your AI policy is a PDF. A PDF proves what you intended — not what happened last month.
KPMG / University of Melbourne, 2025. You cannot govern what you cannot see.
Every request is proxied inside your own network. Your applications talk to the gateway; the gateway talks to the providers you approve. You get provider choice, guardrails and full auditing without sending a single prompt to a third-party cloud. The gateway is Xcellerate AIG, built in the EU by RMM Labs Ltd; the evidence layer on top is ours.
Docker, Kubernetes, or a self-contained appliance answering on 443 from first boot. Fully air-gappable. Your building or your cloud — never ours.
Virtual keys under a companies-and-teams hierarchy, each with its own budget, rate limit and model allow-list. Guardrails your DPO configures in business language, not regular expressions.
Every refused overspend, every routing fallback, every redacted record becomes audit evidence automatically — signed, chained and mapped to the regime it satisfies.
From provider routing to data protection — sixteen modules, all self-hosted. Your teams keep the models they want; you finally get the control point. All sixteen, in detail →
Point your applications at one OpenAI-compatible endpoint and reach every provider behind it. The same request shape works whether the model runs at OpenAI, Anthropic, in your own data centre or anywhere in between.
Set spend caps and rate limits per company, team or key — enforced by the cost engine in real time. When the budget is gone, the request stops. Tag every call and hand finance the chargeback file it actually asked for.
Routing rules an operator can read: prefer the lowest-latency provider, keep data in a region, send a slice to a canary, run an A/B test, or route on what the request is actually about — and fall through when a provider fails.
Teams get a gateway key that maps to your provider accounts — the real provider secrets never leave the vault. Rotate or revoke any key without touching a provider account. Someone leaves, one action, gone everywhere.
A sensitive-data catalog written in business language: national identifiers, IBANs, cards, health, salary, legal terms, internal codenames — and what should happen when each appears. Block, redact, or simply record.
Guardrails inspect traffic on the way in and the way out — as plain topics, backed by a model asked to judge the content, or by an external service you call.
Who changed what, and when — chained so it cannot be quietly rewritten. Signed outbound webhooks let downstream systems trust the events they receive.
A normal certificate says your controls worked on audit day. A TruCert is rebuilt every 29 days from what actually happened in the gateway's own request logs, audit trail and routing records — and it lapses the moment good behaviour stops. Your auditor sees living proof or an honest gap, never a stale yes. How Assure works →
Five yes/no questions, one at a time. Your score appears immediately — we only ask for email to send the full report.
Tell us which providers and applications you run today and we'll show you how to put them under one governed gateway — and what the evidence looks like when it comes out the other side.
Talk to us How we work — in the open