Every AI call your company makes,
metered, filtered, and logged.
A zero-trust reverse proxy for your LLM traffic. Point your SDK at Vgil to enforce policies, mask PII, and record every token.
Vgil in one sentence
Vgilkeepswatch.Everyrequestyoursoftwaresendsamodel,everyanswerthatcomesback,andwhoeversetitinmotion—seenwhenithappens,andrememberedafter.NohiddenAPIwaste,nounvettedpromptleakingpastyourdefenses,andnountracedAIcalls.Completecontrolovereverytoken,fromdayone.
What it costs. What it leaks. Who did it.
Three questions nobody can answer yet.
All three happen in the same place: the moment your software calls the model. That is the one place to put a control — and it is where Vgil sits.
Four things it does
from that one position.
Type anything at the page. Watch all six stages think.
Not pass or fail — the whole pipeline on one screen, every stage showing its own verdict and the reason it reached it.
Validates workspace key & HMAC signature
Pick a payload or write your own, then send it. Watch which gates it clears.
In-browser simulation — same stages, same order. Nothing you type leaves this page.
One line changes in your code.
Everything else is a setting in Vgil.
What each control does, where it lives, and what happens when it fires.
01Reverse proxy & multi-model router
Point your existing OpenAI or Anthropic SDK at api.vgilai.com. Your provider keys stay in Vgil, encrypted at rest and attached upstream — they never ship inside your application.
curl https://api.vgilai.com/openai/v1/chat/completions \
-H "X-Vgil-Key: vgl_live_09x" \
-H "Content-Type: application/json" \
-d '{"model": "gpt-4o", "messages": [{"role": "user", "content": "Analyse risk"}]}'Your request carries a Vgil key only. The provider credential is decrypted and attached server-side, on the way out.
Enforcement is half of it. The other half is what you learn afterwards.
One conversation, not forty requests
An agent run is dozens of calls. Read them one row at a time and the shape of it never appears. Vgil puts them back together as the run they belong to — what it cost, how long it took, how many calls it made, and whether anything was flagged along the way.
| Session | Reqs | Cost | Duration | Issues |
|---|---|---|---|---|
| refund-triage-agent | 14 | $0.42 | 3m 12s | — |
| support-summariser | 9 | $0.18 | 1m 40s | 1 |
| onboarding-assistant | 31 | $1.07 | 7m 55s | — |
Risk with a number on it
Most governance tools hand you a red, an amber or a green. Vgil puts a dollar figure on each exposure instead. They rank by money rather than by colour, each carrying its loss type and the steps that would close it.
- 1Unredacted PII reaching a third-party modelLegal / regulatory$71.4k
- 2Unmetered agent spendDirect operational$38.9k
- 3No transparency notice publishedLegal / regulatory$23.8k
It tells you what to fix first
The advisor looks across everything Vgil has seen and writes back a ranked list of what to do about it — each with an estimated saving and a deadline, each markable as applied once it is done.
- HIGHRequires immediate action
Three API keys have no monthly cap set.
Estimated saving $2,400 / mo
- MEDIUMAddress within 2 weeks
A large share of calls could route to a cheaper model.
Estimated saving $1,150 / mo
- LOWPlan for next sprint
Session tracing is off for two workspaces.
Unmanaged API Calls
vs. Vgil Gateway.
What changes when every call goes through Vgil. One unified zero-trust proxy layer replacing key sprawl, raw data leakage, and blind upstream billing.
The Leaky Perimeter
Every service reaches model providers on its own, with its own credentials copied across teams, repos, and environments.
Zero-Trust AI Ingress
Change one base URL and Vgil sits in front of every request. Credentials stay in Vgil, in-flight PII is masked, and an immutable SHA-256 digest is sealed.
Regulatory Frameworks & Audit Readiness
How each framework maps to cryptographic evidence recorded by Vgil
Transparency obligations and record-keeping for generative AI systems (Articles 50 & 52).
Be first
through the gate.
Join the waitlist. When your seat opens, you get early-access pricing, automated key provisioning, and a dedicated onboarding architect. No credit card needed.
