TruCert builds one control plane with three jobs: carry every AI request your company makes, enforce every rule you set — and turn that live traffic into proof your auditor, your board and your customers can check themselves. Gateway and certificate. One product, one contract, one vendor.
The AI gateway category is mature, and its capabilities are public knowledge: one API in front of every model, budgets, keys, routing, guardrails, caching, observability. We ship the whole checklist — self-hosted on your servers, air-gapped if you need. This is the entry ticket, not the product.
One OpenAI-compatible API in front of OpenAI, Anthropic, Google Gemini, Azure OpenAI, AWS Bedrock, Mistral, Groq, Ollama and OpenRouter — plus any OpenAI-compatible endpoint and your own self-hosted models. Switch providers by configuration, never by rebuilding software.
Spend caps and rate limits per company, team and key, enforced by the cost engine in real time. Spend attributed by tag, granular enough for a chargeback file. Virtual keys issued, scoped, rotated and revoked centrally, with model allow-lists.
Canary slices, A/B tests, lowest-latency preference, region pinning, content-based routing — and fall-through when a provider fails. Semantic response caching stops you paying twice for the same answer. Streaming, tool-calls and long agent runs stay intact.
Guardrails inspect traffic in both directions — plain topics, a model asked to judge, or your own service — and block, redact or record. A sensitive-data catalog your DPO writes in business language, not regular expressions.
OIDC single sign-on, SCIM provisioning and de-provisioning, deep role-based access control with reveal gating and data scopes. MCP servers and their tools are registered, permissioned and accounted for like everything else.
A live operations dashboard, fully searchable request logs, Prometheus metrics and OpenTelemetry traces into your own stack, and a tamper-evident audit log with signed outbound webhooks.
This page is our contract with ourselves: the whole map, published, so you can hold us to it.
Four things no feature checklist gives you — each buildable, each sellable, and together the reason TruCert is a category, not a copy.
Others keep logs and promise you can audit later. TruCert writes signed, tamper-evident evidence the moment a control fires: the refused overspend, the routing fallback, the redacted record. Not logs you turn into evidence later — evidence from the start.
Turn on the EU AI Act disclosure list, the DORA provider register, NIS2 access control. The control plane compiles each obligation into budgets, keys and routing rules — and the evidence writes itself while your teams just work. A regulation stops being a quarter of panic.
Every AI agent gets its own virtual key, budget and expiry — and every MCP tool it calls is catalogued and attested. Your agents become the first workers you can revoke in one action, whose whole history fits in one signed export. Governance for the workforce that has no badge.
A live TruCert your customers and auditors verify themselves — current, or visibly expired. Procurement turns from a stack of questionnaires into one link. Compliance becomes something you can sell, not only something you pay for.
You're buying certainty, so we build the way certainty is earned: your servers, your rules, your evidence — and every role stated in the open, on this website rather than in a data room.
The gateway underneath TruCert is Xcellerate AIG, the enterprise AI gateway built by RMM Labs Ltd in Sofia, Bulgaria — open-core under AGPL v3. We say so on every page rather than pretending we wrote a control plane from scratch. TruCert B.V. delivers it under an EU contract, hardens each release, and adds the evidence layer.
Your team operates the gateway around the clock on your own infrastructure. We harden every release, keep the runbooks tested and give you expert escalation in business hours. Managed operations ("Operate") is coming — publicly on the roadmap.
Our assurance today is full transparency: security statement, SBOM sample, insurance and licensing documents — ready for your vendor assessment. ISO 27001 follows when our scale justifies an audit worth the paper.
We generate the operating evidence; the compliance judgment stays with you and your auditors. That separation is exactly what makes the evidence trustworthy.
TruCert certifies against OpenAISF — an open AI safety & security framework: public, vendor-neutral, free for anyone to read, and mapped control by control to the standards your auditors already speak: ISO 42001, ISO/IEC 23894 (AI risk management), NIST AI RMF, the EU AI Act and more. We build on it because open standards can't bluff — every control is falsifiable, every tier published, every claim checkable. Its core idea powers Assure: proof should come from your live traffic, and expire when it stops. The details live at openaisf.org.
TruCert B.V., Netherlands. EU-owned, EU jurisdiction, EU contracts. Gateway engine: RMM Labs Ltd, Sofia, Bulgaria — also EU.
No SDRs, no discovery-call scripts. A message here reaches the people who build the product — not a pipeline.