Your rules.
AI follows.
Turn policy and regulatory requirements into controls enforced across models, agents, and tools, with evidence for every governed decision.
One policy. Active across every AI project.
Your organisation sets the rules once. obstruo applies them to every project, agent and request, and keeps the evidence that it did.
Locked, recommended and optional policies, inherited by every project the moment it is created.
Redaction, model restrictions, guardrails, budgets and tool permissions act on the request itself, not on a report.
The policy version, the decision, the routing, the redactions and the tool call stay connected as one record.
Control what AI can see, use and do
Redact PII and secrets before they reach models, and again when they return through tools.
Control which providers and models are allowed, behind stable logical model names.
Apply policy by agent identity, and restrict which MCP tools and actions each one can reach.
Enforce budgets, rate limits, safety guardrails and fail-closed behaviour when a check cannot run.
Connect runtime decisions to projects, agents, vendors, incidents and approvals.
Data, models, agents, risk and evidence are governed from the same place, so a rule changes once and applies everywhere.
Compliance and engineering see the same reality
No reconciliation meeting. A single blocked request appears in both views, described in the language each team works in.
Three use cases that need governance first
Once an agent can place an order or issue a refund, tool permissions become the control that matters. Allow the reads, deny the writes, record the attempts.
Personal data and secrets reach models through prompts, retrieval and tool responses. Redaction runs in path, in both directions, and records what it removed.
Applications ask for a logical model name. Policy decides which approved provider and region answers, and refuses the ones your review has not cleared.
Fits the AI infrastructure you already operate
You do not have to replace your proxy or re-onboard every project to start governing AI.
Point your applications at obstruo and let it hold the provider connections, the policy and the evidence.
Keep the proxy you already run for traffic, and put obstruo in front of it for policy and evidence.
Start with the higher-risk projects and agents, then widen coverage as the policy proves itself.
What is live today, and what is not
Everything below is labelled honestly, so your security review does not have to guess.
Available to design partners. Ask us for access.
Built to the standards your auditors ask about
No. Use it directly or chain it in front of the proxy you already run. Either way, policy and evidence stay in one place.
EU-hosted by default, in EU regions only. Traffic can be pinned to in-jurisdiction endpoints per project.
You choose the behaviour per policy: fail closed and refuse the request, or fail open and let it through. Either way the outcome is recorded with the policy version that caused it.
Around 20ms p50 for the enforcement path. Redaction with entity detection adds more, and is measured per project.
No. Most teams start with two or three higher-risk projects, then inherit the same organisation policy as coverage widens.
Policy version, decision, routing, redaction counts, tool calls, incidents and approvals, exportable per project, agent or framework.
Your AI. Your data. Your control.
Start free on one project, then make the same policy executable across the organisation.