ProxyAi
Open navigation
POLICY-AWARE AI PROXY

Govern enterprise AI before sensitive data reaches a provider.

ProxiAI authenticates users, enforces tenant policy, detects and masks sensitive data, streams approved AI responses, and records encrypted or metadata-only evidence according to organisation retention policy.

Open Admin DemoRead architectureSecure. Governed. Observable.
ProxiAI proxy

Designed and verified for security-conscious engineering teams

Tenant isolated
Policy enforced
Sensitive-data aware
Enterprise-oriented controls

THE PROBLEM

Enterprise AI needs a control plane, not another chat wrapper.

Uncontrolled AI access

Direct AI usage can bypass organisation policy and approval boundaries.

Sensitive-data egress

Prompts may contain credentials, personal data, or internal connection details.

Missing governance evidence

Security and operations teams need usage, decision, and audit evidence without storing plaintext prompts.

Security controls before provider access

Each decision is tenant-scoped, deterministic, and safe to observe.

Policy First

Enforce approved AI usage policies before any request reaches a provider.

Data Protection

Detect and mask sensitive data to reduce risk and protect confidentiality.

Full Visibility

Understand decisions, usage, and routing without exposing sensitive content.

Provider Control

Keep one governed interface while your approved provider strategy evolves.

BUILT FOR ENTERPRISES

How ProxiAI works

  1. User makes a request

    A user sends an AI request from their workspace.

  2. ProxiAI inspects risk

    Sensitive data is detected and risk is classified.

  3. Policy decides

    Organisation policy allows, masks, or blocks safely.

  4. Approved request is routed

    Only the approved prompt reaches the configured provider.

  5. Response returns safely

    The response streams back with safe decision metadata.

P
Summarize the security risks of shadow AI.
P
Policy checked ALLOW
Ask anything...

IMPLEMENTED ARCHITECTURE

Security, reliability, and accounting share one trusted request boundary.

The Express API remains authoritative. Next.js renders the product surface, MongoDB stores tenant records, Redis coordinates request safety, and dedicated BullMQ workers process durable side effects.

Identity and tenant boundary

Trusted organisation scope, current database permissions, Argon2id passwords, rotating refresh sessions, and exact-origin CORS.

Policy-aware request path

Deterministic PII detection, explainable risk scoring, and ALLOW, MASK, or BLOCK before provider execution.

Provider reliability

Provider adapters use bounded retry, circuit state, ordered pre-token fallback, and safe normalized failures.

Async accounting

Append-only usage records drive billing rollups; BullMQ workers reconcile billing, analytics, anomaly, health, and enqueue recovery.

Encryption and audit

AES-256-GCM encrypted message storage uses tenant/resource AAD; admin mutations append immutable audit events atomically.

Observability

Bounded Prometheus metrics, worker heartbeats, safe structured logs, and operational runbooks expose health without prompt labels.

AWS RELEASE SHAPE

Immutable ECR images deploy as separate frontend, API, and worker ECS/Fargate services behind one ALB. The low-traffic demo uses one task per service and snapshot-driven deep stop/start for cost control; it is not a multi-task high-availability claim.

Enterprise-oriented controls by design

ProxiAI is designed for organisations that need secure access, reliable policy enforcement, and bounded operational evidence without claiming formal certification or multi-region availability.

Tenant-scoped access
Stateless frontend architecture
Fail-closed policy and budget controls
Auditable policy decisions

VERIFIED RELEASE EVIDENCE

Security claims backed by deterministic tests.

Internal evidence from audit commit 789136c on 22 August 2026. It covers tenant isolation, Auth/RBAC, prompt egress, encryption, immutable audit, billing replay, pagination, Docker, and isolated MongoDB/Redis/BullMQ integration; it is not an external certification.

Review the source and release harness

78.24% lines

Backend coverage

77.62% lines

Frontend coverage

63 / 63 passed

Isolated integration

All approved ≥ 90%

Critical branch gates

RESTRICTED RECRUITER DEMO

Try the real governed chat path.

Explore the real read-only admin dashboard and governed chat path without receiving or entering an administrator password.

Demo backend may take 1–2 minutes to wake after inactivity.

Open Admin Demo

HONEST BOUNDARIES

What this release does not claim

  • Attachments are not implemented in the current MVP.
  • Prompt cache and safe response replay remain deferred.
  • Exact provider usage is never estimated when an interrupted stream omits usage.
  • The public demo is single-task, low-traffic infrastructure.
  • No external penetration-test or compliance certification is claimed.

Ready to secure your AI usage?

Join your organisation workspace to use ProxiAI safely.

Access is provisioned by your organisation administrator.

Log in to workspace