PLATFORM

The enterprise AI gateway that runs on your infrastructure.

One governed, OpenAI-compatible API between your applications and every AI provider — self-hosted in the EU, so prompts and data never leave your network. The gateway is Xcellerate AIG, built by RMM Labs Ltd in Sofia and open-core under AGPL v3; TruCert delivers it under an EU contract and adds the evidence layer. Everything on this page is a shipped capability, not a roadmap promise — our roadmap, and exactly where our role ends, is on the Company page.

A control plane you actually own

Customer apps Internal copilots Agents / MCP tools TruCert gateway — YOUR estate one OpenAI-compatible API · virtual keys · budgets adaptive routing · semantic cache · rate limits guardrails · data-protection catalog · MCP tools request logs · audit log · OTel → your stack Docker · Kubernetes · appliance — HA, air-gappable Frontier providers EU endpoints Your self-hosted models Applications talk to the gateway; the gateway talks to your chosen providers. Nothing is routed through a vendor cloud.

Left: the AI your staff and software already use. Middle: the gateway, running on your servers, applying your rules. Right: the providers you approve — frontier names, EU endpoints, or your own models. Provider credentials, request logs and the audit trail all live in your infrastructure, not ours.

SELF-HOSTEDAir-gappable by design

Run the whole gateway inside your own network — even fully offline — on Docker, Kubernetes, or as a self-contained appliance answering on 443 from first boot.

NO EGRESSNo prompt leaves your network

Applications talk to the gateway, and the gateway talks to your chosen providers. Nothing is routed through a vendor cloud — ours least of all.

EUEU company and jurisdiction

The gateway is built by RMM Labs Ltd in the EU and delivered by TruCert B.V. in the Netherlands, so your deployment, contract and support stay under European law.

CUSTODYYour systems keep the records

Provider credentials, request logs and the audit trail all live in your own infrastructure. There is no copy on our side to subpoena, leak or lose.

Every provider, one catalog.

Connect the models you already use and manage them from one catalog, with pricing and capabilities in view. Switching provider is a configuration change, never a rebuild.

OpenAIAnthropicGoogle GeminiAzure OpenAIAWS BedrockMistralGroqOllamaOpenRouterYour self-hosted models+ any OpenAI-compatible endpoint

One gateway, complete control.

Sixteen modules — everything you need to put enterprise AI traffic under governance, from provider routing to data protection. All of it runs on your infrastructure.

One API for every model

OpenAI-compatible, provider-agnostic

Point your applications at a single OpenAI-compatible endpoint and reach every provider behind it. The same request shape works whether the model runs at OpenAI, Anthropic, in your own data centre or anywhere in between.

Self-hosted and air-gapped

Your infrastructure, your data, your rules

Run the entire gateway inside your own network — on Docker, Kubernetes or as a self-contained appliance. It can operate fully air-gapped, so prompts, responses and credentials never leave the perimeter you control.

Every provider, one catalog

Connect the models you already use

OpenAI, Anthropic, Google Gemini, Azure OpenAI, AWS Bedrock, Mistral, Groq, Ollama and OpenRouter — plus any OpenAI-compatible endpoint — managed from one catalog with pricing and capabilities in view.

Virtual keys and governance

Companies, teams and keys under control

Issue virtual keys under a companies-and-teams hierarchy instead of sharing raw provider secrets. Each key carries its own permissions, budgets and model access, and can be rotated or revoked without touching your provider accounts.

Built-in guardrails

Screen every prompt and response

Guardrails inspect traffic on the way in and the way out. Define them as plain topics, back them with a model asked to judge the content, or call an external service — and decide whether to block, redact or simply record.

Data protection in your own words

Guardrails your DPO can configure

A sensitive-data catalog written in business language, not regular expressions. Your data protection officer decides what counts as sensitive — national identifiers, IBANs, cards, health, salary, legal terms, internal codenames — and what should happen when it appears.

Adaptive routing

Send each request to the right model

Write routing rules an operator can read: send a slice of traffic to a canary, run an A/B test, prefer the lowest-latency provider, keep data in a region, or route on what the request is actually about.

Semantic response caching

Stop paying for the same answer twice

Cache responses and serve them again when an incoming request is close enough to one already answered — not just an exact match. You cut cost and latency on repetitive traffic, with full control over what is cached and for how long.

Operations dashboard

Traffic, spend and health at a glance

A live dashboard shows request volume, spend, latency, error rates and provider health across the whole gateway, so operators can see what is happening and where to look next.

Request logs

Every call, fully searchable

Every request through the gateway is logged with its model, tokens, cost, latency, key and tags. A searchable browser lets operators and auditors find any call and see exactly what happened.

Observability

Metrics and traces for your stack

The gateway exposes Prometheus metrics and structured logs, and emits OpenTelemetry traces into your existing observability stack — so AI traffic sits alongside the rest of your systems.

Spend by tag & chargeback

Attribute every cost to its owner

Tag every request with whatever finance cares about — project, cost centre, customer — and the gateway turns that into a spend breakdown and the chargeback file finance actually asked for, with budgets that track a project rather than just a key.

MCP servers & tools

Govern the tools your agents call

Register MCP servers and expose their tools to conversations through the gateway, with the same governance as everything else — so the tools your agents call are catalogued, permissioned and accounted for.

Data connectors

Your databases as governed tools

Expose on-premise databases and file shares to AI as governed, read-only tools — behind the same virtual keys, guardrails and audit trail as everything else, even when the data sits on a network the gateway itself cannot see.

Tamper-evident audit log

Provable record of every change

A tamper-evident audit trail records who changed what and when, and signed outbound webhooks let downstream systems trust the events they receive. Alerting is written so a person can still read and act on it a year later.

SSO, SCIM & RBAC

Enterprise identity, built in

Sign in with your identity provider over OIDC, provision and de-provision users automatically with SCIM, and control exactly what each role can see and do with deep role-based access control, reveal gating and data scopes.

GOVERNANCE

Give every team AI access — on your terms.

Issue virtual keys under a companies-and-teams hierarchy, each with budgets, rate limits and model allow-lists, and attribute every euro of spend back to its owner.

KEYSVirtual keys, not raw credentials

Teams get a gateway key that maps to your provider accounts — real provider secrets never leave the vault, and revoking a key touches no provider account.

LIMITSBudgets and rate limits

Set spend caps and request limits per company, team or key, enforced by the cost engine in real time. When the budget is gone, the request stops.

FINANCESpend attributed by tag

Tag every request and hand finance a chargeback file that shows exactly what each project and team cost — not one undifferentiated provider invoice.

SCOPEModel allow-lists

Decide which providers and models each key may reach; anything else returns a clear, governed refusal rather than a silent success.

Where it runs

Residency is wherever you deploy it — that is the whole point of a self-hosted control plane.

On your servers

Docker or Kubernetes on your own infrastructure, with your own PostgreSQL, your identity provider over OIDC in front, traces and metrics into your existing observability stack, and outbound connections limited to the providers you approve.

As an appliance

A self-contained appliance answering on 443 from first boot — for teams who want a gateway running today rather than a platform project.

Fully air-gapped

The same product with zero calls to the outside internet: models inside your network, updates as verified offline bundles, guardrails running in-cluster.

In an EU sovereign cloud

The same pattern on European sovereign-cloud landing zones (Proximus, KPN/STACKIT, hyperscaler EU sovereign regions).

EU-NATIVE

Sovereign by design.

The gateway is built by RMM Labs Ltd in Bulgaria and runs entirely inside your own EU infrastructure — your data never leaves your jurisdiction. TruCert contracts from the Netherlands under Dutch law.

OWNERSHIPEuropean company and control

Designed, built and supported in the EU — no non-EU parent anywhere in the data path, and no non-EU entity in your contract chain.

RESIDENCYRuns on your infrastructure

Self-hosted on your own servers or appliance, so residency is wherever you deploy it — not wherever a vendor's region happens to be.

PROVABLECompliance-ready data protection

Business-language data protection and a tamper-evident audit log give compliance teams provable control — which is exactly what Assure turns into evidence.

DELIVERYUpdates that can't ambush you

Every release reaches you through the Quarantine Channel: verified, re-signed, SBOM included, licence compliance checked. Air-gapped estates get the same bundle offline. You are never the crash test.

Support, plainly

Your team runs the gateway around the clock — it's your infrastructure, and that's the point. We make that safe: hardened releases, tested runbooks, expert help in business hours (Mon–Fri 09:00–17:00 CET). Managed operations ("Operate") is on the roadmap — waitlist open.

SeverityWhat happenedWe respond within
S1The gateway is down, or all AI traffic is blocked — no workaround4 business hours
S2Major problem, but there is a workaround8 business hours
S3Minor defect2 business days
S4Question / how-to3 business days

These are response targets, not fix guarantees. We support the current and the previous quarantined release (N, N–1). The full SLA schedule is in the subscription agreement.

See it on your own stack.

Tell us which providers and applications you run today and we'll show you how to put them under one governed gateway: budget hard-stop, routing fallback, one-action revocation, and an evidence export from the demo's own traffic. Nothing faked.

✓ Request received. We'll reply within one business day with times that suit you.

Or run the readiness check first