COMPANY

Certainty, as a company.

TruCert builds one control plane with three jobs: carry every AI request your company makes, enforce every rule you set — and turn that live traffic into proof your auditor, your board and your customers can check themselves. Gateway and certificate. One product, one contract, one vendor.

01 — THE FULL CONTROL PLANE

Everything a gateway should do. All of it.

The AI gateway category is mature, and its capabilities are public knowledge: one API in front of every model, budgets, keys, routing, guardrails, caching, observability. We ship the whole checklist — self-hosted on your servers, air-gapped if you need. This is the entry ticket, not the product.

ONE DOORTen providers, one endpoint

One OpenAI-compatible API in front of OpenAI, Anthropic, Google Gemini, Azure OpenAI, AWS Bedrock, Mistral, Groq, Ollama and OpenRouter — plus any OpenAI-compatible endpoint and your own self-hosted models. Switch providers by configuration, never by rebuilding software.

THE PURSEBudgets to the single request

Spend caps and rate limits per company, team and key, enforced by the cost engine in real time. Spend attributed by tag, granular enough for a chargeback file. Virtual keys issued, scoped, rotated and revoked centrally, with model allow-lists.

THE SAFETY NETRouting you can read

Canary slices, A/B tests, lowest-latency preference, region pinning, content-based routing — and fall-through when a provider fails. Semantic response caching stops you paying twice for the same answer. Streaming, tool-calls and long agent runs stay intact.

GUARDRAILSRules on every request

Guardrails inspect traffic in both directions — plain topics, a model asked to judge, or your own service — and block, redact or record. A sensitive-data catalog your DPO writes in business language, not regular expressions.

PEOPLE & AGENTSIdentity for humans and software

OIDC single sign-on, SCIM provisioning and de-provisioning, deep role-based access control with reveal gating and data scopes. MCP servers and their tools are registered, permissioned and accounted for like everything else.

THE RECORDEverything visible, nothing deniable

A live operations dashboard, fully searchable request logs, Prometheus metrics and OpenTelemetry traces into your own stack, and a tamper-evident audit log with signed outbound webhooks.

This page is our contract with ourselves: the whole map, published, so you can hold us to it.

02 — WHAT ONLY TRUCERT SHIPS

The gateway market moves AI traffic. We make it testify.

Four things no feature checklist gives you — each buildable, each sellable, and together the reason TruCert is a category, not a copy.

Evidence-native

Proof is born with every request

Others keep logs and promise you can audit later. TruCert writes signed, tamper-evident evidence the moment a control fires: the refused overspend, the routing fallback, the redacted record. Not logs you turn into evidence later — evidence from the start.

Regulation as configuration

Switch on a regulation, not a project

Turn on the EU AI Act disclosure list, the DORA provider register, NIS2 access control. The control plane compiles each obligation into budgets, keys and routing rules — and the evidence writes itself while your teams just work. A regulation stops being a quarter of panic.

Non-human workers

Agents on a leash you can prove

Every AI agent gets its own virtual key, budget and expiry — and every MCP tool it calls is catalogued and attested. Your agents become the first workers you can revoke in one action, whose whole history fits in one signed export. Governance for the workforce that has no badge.

Proof as an asset

Show it, don't questionnaire it

A live TruCert your customers and auditors verify themselves — current, or visibly expired. Procurement turns from a stack of questionnaires into one link. Compliance becomes something you can sell, not only something you pay for.

03 — HOW WE WORK

You stay in control.

You're buying certainty, so we build the way certainty is earned: your servers, your rules, your evidence — and every role stated in the open, on this website rather than in a data room.

THE ENGINEPowered by Xcellerate AIG

The gateway underneath TruCert is Xcellerate AIG, the enterprise AI gateway built by RMM Labs Ltd in Sofia, Bulgaria — open-core under AGPL v3. We say so on every page rather than pretending we wrote a control plane from scratch. TruCert B.V. delivers it under an EU contract, hardens each release, and adds the evidence layer.

YOUR OPERATIONYou run it, we back you up

Your team operates the gateway around the clock on your own infrastructure. We harden every release, keep the runbooks tested and give you expert escalation in business hours. Managed operations ("Operate") is coming — publicly on the roadmap.

TRUST, EARNEDTransparency today, ISO 27001 next

Our assurance today is full transparency: security statement, SBOM sample, insurance and licensing documents — ready for your vendor assessment. ISO 27001 follows when our scale justifies an audit worth the paper.

BY DESIGNYour auditor stays the judge

We generate the operating evidence; the compliance judgment stays with you and your auditors. That separation is exactly what makes the evidence trustworthy.

04 — THE OPEN STANDARD

Certified against something everyone can read.

TruCert certifies against OpenAISF — an open AI safety & security framework: public, vendor-neutral, free for anyone to read, and mapped control by control to the standards your auditors already speak: ISO 42001, ISO/IEC 23894 (AI risk management), NIST AI RMF, the EU AI Act and more. We build on it because open standards can't bluff — every control is falsifiable, every tier published, every claim checkable. Its core idea powers Assure: proof should come from your live traffic, and expire when it stops. The details live at openaisf.org.

TruCert B.V., Netherlands. EU-owned, EU jurisdiction, EU contracts. Gateway engine: RMM Labs Ltd, Sofia, Bulgaria — also EU.

Transparency, standing

EngineGateway powered by Xcellerate AIG (RMM Labs Ltd, Sofia) — open-core, AGPL v3. Named on every page, credited in every release.
Security[email protected] · coordinated disclosure policy · security statement available for vendor assessments.
LicensingOpen-source notices shipped in every release; licensing transparency page lists all components and licenses.
PrivacyYour prompts, logs and spend data never transit TruCert systems. Telemetry off by default. Privacy policy applies to our website and support only — because that's all we touch.
ClaimsEvery statement on this site must survive the question: "which document proves this?" If one doesn't, tell us — we'll fix the site.

Talk to the people who built this.

No SDRs, no discovery-call scripts. A message here reaches the people who build the product — not a pipeline.

✓ Message sent. We reply personally, usually within one business day.