One neutral layer in front of every call
Apps and agents hold one obstruo key. Every request passes through the control plane, redacted, routed, enforced, and logged, before it reaches any provider or MCP server.


Active control, not only observability
Because every call already passes through the control plane, obstruo can act on it in path. No queue, no agent to wake, no redeploy. Three kinds of control, one plane.
Strip or stop what must not pass: PII, secrets, jailbreaks, prompt injection, before it reaches the model.
Require what policy says must be present: context, disclaimers, allowed tools, on the way through.
When policy says a human must decide, hold the action, escalate with context, and emit a signed Article 14 record.
One console for the whole AI surface
From keys and the MCP proxy to the governance registries your agents will need. What the control plane enforces on each call, redaction, guardrails, limits and budgets, now lives on runtime controls. Some surfaces are live today, others are in preview, with the governance model already wired into the control plane.
Every call, with the evidence to prove it
One audit trail across every provider and agent: the full call chain, the routing decision, and the redaction state preserved exactly as it was at request time. Query it, export it, and retain it for years.
- Auditor view and CSV export
- Retention up to 2,555 days
- Filter by key, model, status, or PII state
Put every MCP server behind a governed proxy
Register your customer MCP servers as upstreams, then expose them to agents through obstruo MCP endpoints. It is many-to-many: one server can back many endpoints, one endpoint can compose many servers, and you allow or deny each tool per proxy.
- Per-tool allow and deny on every endpoint
- Destructive write and delete tools flagged before an agent connects
- Trust, transport, and auth posture on every server
One key. One endpoint.
Point your existing SDK at obstruo and change nothing else. Provider keys live in the vault, redaction and routing apply in path, and the audit record is written before a single token leaves your network.
Built for control, not lock-in
Route across models, providers, and regions by policy and cost. Failover when one degrades. No governance locked into a single vendor ecosystem.
EU-resident by default, in EU regions only. Pin traffic to in-jurisdiction endpoints and keep processing where your regulators expect it.
Policy is enforced in path on every call, not reported on after the fact. Redact, route, hold, or block, and emit signed evidence as it happens.
Agents, MCP servers, and skills in one place: owners, risk, data sources, and per-tool permissions, discovered from real live traffic.