An AI security gateway. It sits between your systems and your AI providers, inspecting every outbound request in real time and blocking sensitive data before it leaves your organisation.
Traditional controls cover email and file transfers. They were not built for AI API calls. CattleGrid closes that specific gap — where existing controls go blind.
No. Prompts are inspected in memory, your rules are applied, and the content is discarded. Nothing is used for model training. Nothing is written to disc.
Audit metadata only: who made a request, when, which rules fired, and what action was taken. Not the prompt content itself.
On European infrastructure. No American cloud providers. No US CLOUD Act exposure. Your data stays under UK and EU jurisdiction by design.
CattleGrid is available today as a cloud-hosted SaaS. On-premises deployment is on our near-term roadmap. Contact us if infrastructure sovereignty is a hard requirement.
Yes. Built-in detectors cover standard PII and financial data. Custom rules let you define your own: client identifiers, deal codes, sector-specific data patterns.
Inspection takes milliseconds. Latency is negligible. Staff continue working normally. The only difference is that requests containing sensitive data are stopped before they leave.
The employee receives a clear explanation of what was detected and why. Administrators see the event in real time. A full audit log is maintained.
Structured for UK and EU organisations of 50 to 500 employees — not enterprise-scale budgets. Founding Access participants receive preferential terms. Contact hello@cattlegrid.uk for specifics.
Direct access to the team who built the product. No ticketing system between you and us. Founding Access participants receive priority onboarding support.
Revert your API configuration to point directly at your AI provider. CattleGrid holds no data on your behalf. There is no lock-in.
Yes. It is built for organisations that need governance controls, policy enforcement, and audit trails. Individual personal subscriptions are outside its scope.
CattleGrid protects traffic passing through your organisation’s API configuration. Personal mobile applications connecting directly to public AI services are outside that controlled path.
Not currently. Copilot is governed through Microsoft’s own admin controls, not an external API endpoint. CattleGrid protects direct API calls to LLM providers — a different layer.
The founding team has backgrounds in enterprise technology and healthcare data governance. Architecture is designed against ISO 27001, ISO 42001, and EU AI Act requirements. Technical documentation is available on request.
No. Under the US CLOUD Act, American federal agencies can compel disclosure of data held by US companies regardless of location. European infrastructure removes that exposure. For regulated UK organisations, that is a compliance decision, not a political one.
No. It is built for regulated UK and EU organisations in the 50 to 500 employee range — where serious AI governance is required but enterprise platforms are neither affordable nor appropriate.
AWS Bedrock, Azure OpenAI, Google Cloud, Mistral, and other direct LLM API connections. If your organisation uses an API-routed AI service, CattleGrid can protect that traffic.
No. Compliant requests pass through without interruption. Only requests containing data your policies flag as sensitive are blocked — and employees are told clearly why.
By preventing sensitive data from reaching external AI services, and by generating the audit trails that UK GDPR, ISO 42001, and EU AI Act documentation requirements all demand.
No. ISO 27001 and ISO 42001 certification requires executive commitment and time. CattleGrid is the tactical control that limits your exposure whilst that strategic work proceeds.
Any other questions we haven’t answered here please get in touch…