Skip to main content
SOC 2 Type II Observation In Progress • 11 Compliance Frameworks Mapped

Enterprise AI Security
At Scale, With Confidence

The AI Security Layer for enterprise: API security, MCP security, AI gateway, and verification engine — unified under one correlation ID with tamper-evident hash-chain audit, Patroni+etcd HA, blue-green deploys, and 11 compliance frameworks mapped. All 4 platforms from $2,999/mo (founder rate · floor · custom above).

SOC 2 Type II — In Progress (external audit engagement H2 2026)
HIPAA-Ready
PCI-DSS Ready
1-hour P1 response (Enterprise SLA)
Enterprise Dashboard
Live Status
All Systems Operational
99.99%
SLA Guaranteed Uptime
0
APIs Protected
0
Threats Blocked
0
Active Regions
0%
Compliance Score
Certifications
SOC 2 Type II
HIPAA
PCI DSS
ISO 27001
Support SLA
<4 hours
Critical Response Time24/7/365
Enterprise-Grade Security
11
compliance frameworks mapped
7-year
audit retention (84-month WORM)
SHA-256
hash-chain audit (CC7.2 / §164.312(b))
Patroni
+ etcd + HAProxy quorum HA
4-dim
Zero Trust composite risk score
Blue-green
zero-downtime deploys + auto-rollback
67
GitHub CI workflows (CodeQL, Trivy, ZAP)
99.9%
Enterprise SLA · 1-hr P1 response

Enterprise-Grade Security

Built for regulated industries with compliance, scale, and security at the core

Automated Compliance

Auto-generated SOC 2, HIPAA, and PCI evidence packages. Cross-framework sync means a SOC 2 control automatically contributes evidence toward GDPR, ISO 27001, and HIPAA where they overlap.

  • Quarterly compliance reports
  • Audit trail export (CSV, JSON)
  • Evidence logs for auditors

SSO & Multi-Tenancy

Full SSO/SAML with Auth0, Okta, Azure AD. Multi-tenant administration with organization-level isolation and SAML XML Signature Wrapping (XSW) defense.

  • OIDC/JWKS authentication
  • Role-based access control
  • Organization isolation

Custom Deployment

Cloud, on-premise, or air-gapped deployment. Multi-region with data residency. Dedicated VPC, private endpoints, and DNS failover across 5 routing strategies.

  • Private cloud deployment
  • Architecture supports air-gapped deployment
  • Multi-region failover

Complete AI Security Platform

Enterprise plans include unlimited access to all 4 pillars of the G8KEPR platform

API Security

Unlimited Requests
  • Unlimited API requests tracked
  • WAF (Web Application Firewall)
  • mTLS to upstream services
  • Advanced rate limiting & circuit breakers

MCP Security

Unlimited Tool Calls
  • Unlimited MCP tool calls
  • Enterprise permission framework
  • Custom security policies per agent
  • Multi-agent orchestration monitoring

AI Gateway

Unlimited LLM Providers
  • Unlimited LLM providers (BYOK)
  • Enterprise cost tracking & chargebacks
  • Custom routing strategies
  • Private model endpoints

Verification Engine

4 Validation Layers
  • Constraint enforcement (forbidden phrases, format, length, PII)
  • Source grounding (citation verification, hallucination detection)
  • Structural validation (JSON schema, regex, expected structure)
  • BLOCK-capable enforcement on selected critical paths

11 Compliance Frameworks, One Hash-Chain Audit Log

Every state-changing operation is appended to a SHA-256 hash-chained audit log. Cross-framework mapping means a SOC 2 control automatically contributes evidence toward GDPR, ISO 27001, and HIPAA where they overlap.

EU AI Act
Articles 9, 11, 12, 13, 14, 15
controls implemented
SOC 2 Type II
CC6.1 / CC6.6 / CC7.2 / A1 / C1
observation in progress
HIPAA
Security Rule §164 + 7-yr audit + BAA
-Ready (BAA available)
GDPR
Articles 5, 12, 17, 28, 32 + DPA
controls implemented
PCI DSS v4.0
300+ requirements mapped
-Ready
ISO 27001:2022
93 Annex A controls
aligned (not certified)
FedRAMP
84 controls · NIST 800-53 mapping · 3 baselines
AU-9 evidence available
CMMC 2.0
110+ practices · DoD-ready
evidence aggregation
NIST CSF 2.0
106 subcategories · function-level mapping
mapped
NIST 800-53 Rev 5
1,000+ controls
control implementation checks
GDPR DPA
Article 28 · subprocessor tracking
DPA generation workflow
Cross-Framework Sync
cross_framework_sync.py
eliminates duplicate evidence

"-Ready" / "aligned" / "controls implemented" reflect capability posture. SOC 2 Type II, HIPAA, ISO 27001 certifications pending external audit. Audit retention: 90 days hot (PostgreSQL monthly partitions), 7 years cold (S3 WORM Object Lock COMPLIANCE mode).

Service Level Commitments

Aligned with the Starter / Pro / Enterprise tiers on our pricing page. Contractual SLA ships with the Master Service Agreement.

Starter
Best effort
availability target
Community support
Monthly downtime budget: No SLA guarantee
★ Recommended
Pro
99.9%
availability target
Priority email support
Monthly downtime budget: ~43 min/mo
Enterprise
Custom
availability target
Dedicated support
Monthly downtime budget: Per MSA

Production-Grade Operations Out of the Box

Patroni HA. Blue-green deploys. 67 CI workflows. Kubernetes-native. No DIY required.

High Availability

PostgreSQL with Patroni + etcd + HAProxy quorum-based failover. Redis Cluster + Sentinel. Backend uvicorn workers (2×vCPU+1) with process-level isolation. Nginx upstream health checks.

Blue-Green Deployments

Zero-downtime updates with canary traffic shifting. Automatic rollback on error rate SLO breach. Graceful request draining on shutdown. One-line operational commands: deploy / verify slot / instant rollback.

67 CI Workflows

CodeQL (fail-on-error, enforced), Trivy container scanning, Bandit Python linting, pip-audit + npm audit, OWASP ZAP, Gitleaks secret detection, Semgrep SAST, Lighthouse perf, threat-detection regression gate.

Zero Trust Risk Scoring

4-dimension composite score (device 25% / location 25% / behavior 30% / time 20%). Thresholds drive access decisions: 0–30 allow, 31–60 monitor, 61–80 step-up MFA, 81–100 deny. Impossible-travel detection via Haversine.

Helm + Kubernetes

Six Helm manifests: Deployment with rolling updates, HorizontalPodAutoscaler, PodDisruptionBudget, NetworkPolicy, ExternalSecrets, PrometheusRule. SHA-pinned images, non-root containers, defined HEALTHCHECK.

Tamper-Evident Audit

SHA-256 hash chain with all-zeros genesis block. Three verification levels (full / single / last-N). Monthly-partitioned PostgreSQL with 84-month retention. WORM Object Lock COMPLIANCE mode for cold storage.

White-Glove Enterprise Support

Your success is our priority. Get dedicated support from security experts.

Dedicated Support Engineer

Your own engineer who knows your infrastructure inside and out. Available via Slack, email, or phone.

1-Hour P1 (24/7/365)

Pro tier ships a 99.9% availability target with a ~43 minute monthly downtime budget. Enterprise tier negotiates a custom SLA per Master Service Agreement.

Direct Founder Access

Quarterly security reviews with our founding team. Direct Slack channel for strategic guidance and roadmap input.

Enterprise Pricing

Simple, transparent pricing for enterprise teams

Enterprise Plan

$4,999/moFounder rate · through Dec 31, 2026
from $2,999/month

Floor pricing for the Enterprise tier. Custom pricing above for larger deployments. Founder rate locked for the lifetime of your subscription.

Unlimited API requests
Full MCP security suite
All LLM providers supported
SOC 2, HIPAA, PCI compliance
SSO/SAML + Multi-tenancy
1-hour P1 SLA (24/7/365)

Enterprise Use Cases

Built for regulated industries worldwide

Financial Services

Banks, payment processors, and fintechs securing payment APIs, fraud detection AI agents, and transaction processing systems.

Compliance: PCI DSS, SOX, GDPR

Healthcare

Hospitals, health tech, and pharma companies protecting patient data APIs, medical AI assistants, and HIPAA-compliant systems.

Compliance: HIPAA, HITRUST, FDA 21 CFR

Government

Federal agencies and contractors securing classified systems, citizen services APIs, and government AI applications.

Compliance: FedRAMP, FISMA, NIST 800-53

Ready to Secure Your Enterprise?

Schedule a demo with our team to discuss your security requirements, compliance needs, and custom deployment options.

SOC 2 Type II — In Progress (H2 2026)
99.9% uptime target
1-hour P1 SLA (Enterprise tier)