An API proxy. Not an agent.
The distinction matters.

CattleGrid operates as a governance layer at the network boundary – between your organisation’s applications and the AI services your staff are using. It does not sit on endpoints, does not require agent installation, and does not modify application behaviour. Every outbound AI API request passes through it. Most pass through in under 50 milliseconds. The ones that shouldn’t, don’t.

How it Works

The architecture is deliberately straightforward. Applications — internal tools, third-party software, or direct browser interactions — route AI API traffic through CattleGrid before it reaches the provider. No changes are required to those applications. No software is installed on user machines. The intervention happens at the network layer, not the endpoint.

01 Intercept

Request received

Every outbound AI API call is routed through the CattleGrid gateway before reaching any external provider.

02 Inspect

Policy applied

Content is scanned in memory against your data classification rules — PII, financial data, trade secrets, custom-defined terms.

03a Pass

Clean request proceeds

Compliant requests pass through with negligible latency. The user experience is unchanged.

03b Block

Sensitive data stopped

The request is blocked. The employee is notified. Administrators are alerted. The incident is logged.

The inspection step adds under 50 milliseconds to request latency in typical operation. For context, the network round-trip to a major LLM provider from a UK datacentre is typically 80–200ms. CattleGrid’s contribution is not perceptible in practice.

Technical Specification

Gateway latency

< 50ms

Inspection overhead per request under typical operating conditions.

Architecture type

API proxy gateway. Network-level interception. No endpoint agents. No application modification required.

Data retention

Zero

Inspected content exists in memory only. Nothing is written to disc. Sensitive fragments from blocked requests are never stored.

Deployment model

SaaS or on-premises. Cloud-hosted on European infrastructure, or deployed within your own environment. Identical functionality either way.

Jurisdiction

UK company. European infrastructure. Not subject to the US CLOUD Act. Data never touches US jurisdiction.

Tenant isolation

Complete. Each organisation’s configuration, rules, and audit data are fully isolated. No shared data plane between customers.

Audit trail
Every request is logged: who sent it, when, which rules were evaluated, and what action was taken. Sensitive content is never stored in full — the log captures the event, not the data. Exportable for ISO 42001 and EU AI Act compliance evidence. Real-time dashboards and alert integrations — email, Slack, and existing SIEM infrastructure — available out of the box.

Deployment

The integration touchpoints are intentionally limited. CattleGrid connects to your existing AI provider API credentials and becomes the routing endpoint for your applications. Nothing changes downstream. No existing applications need to be rebuilt or reconfigured beyond pointing their API calls to the gateway.

SaaS / Cloud-hosted

Hosted on European infrastructure

Fastest path to deployment. CattleGrid operates on European cloud infrastructure with no US provider dependency. Appropriate for most UK enterprise deployments.

  1. Connect your AI provider API credentials to CattleGrid.
  2. Enable pre-built detection rules or define your own.
  3. Point your applications to the CattleGrid gateway endpoint.
  4. Verify via the test interface. Go live.

On-premises

Within your own infrastructure

For organisations with air-gap requirements, data residency obligations, or security architecture that requires internal deployment. Full feature parity with the SaaS model.

  1. Deploy within your existing network boundary.
  2. Configure against your internal security policies.
  3. Integrate with existing SIEM and alerting infrastructure.
  4. No outbound data. Audit logs remain on-premises.

Provider Compatibility

CattleGrid is not tied to a single AI provider. It operates across the platforms where UK enterprise AI workloads actually run. If your organisation is running multiple models across multiple platforms, a single CattleGrid deployment covers the entire surface.
AWS Bedrock
Claude, Llama, Mistral, Cohere. The dominant enterprise gateway for organisations already on AWS infrastructure.
Azure OpenAI
GPT-4o and associated models. The incumbent platform in NHS, public sector, and Microsoft-aligned enterprise environments.
Anthropic (direct)
Claude API. Direct integration for organisations not routing through hyperscaler gateways.
Google Vertex AI
Gemini and associated models on Google infrastructure.
Mistral AI
Direct API. European-domiciled provider of particular relevance for EU data sovereignty requirements.
OpenAI (direct)
Direct API access for organisations not routing through Azure. Consumer and enterprise tiers.

Data Handling

Inspected content exists in memory only, processed in milliseconds, then gone. Nothing is written to disc. Sensitive fragments from blocked requests are never stored in full. The audit log records the event — who, when, which rule, what action — without preserving the data that triggered it.

Credentials, encrypted at rest

API credentials connecting to AI providers are stored encrypted using current industry standards. They are never exposed in logs or audit exports.

Tenant isolation, complete

Each organisation’s data — configuration, rules, audit logs — is fully isolated. There is no shared data plane between customers.

No US jurisdiction

CattleGrid is a UK company operating on European infrastructure. Not subject to the US CLOUD Act. For regulated sectors with client data obligations, this is not a minor detail.

Audit exports, compliance-ready

Logs are exportable in formats suitable for ISO 42001 audits and EU AI Act compliance evidence. Pre-built templates for common regulatory frameworks are included.

Access Model

CattleGrid is role-based. The people who need visibility get it; the people who need to act can act; and the people who just need to use AI tools encounter nothing different at all.

End users

Nothing, ordinarily. AI tools continue to function as normal. When a request is blocked, the user receives a clear notification explaining why. No software to install. No training required beyond awareness of the policy.

Administrators

Configure detection rules via the visual dashboard. Define what categories of data are governed and how. Manage team access and permissions. All administrative actions are logged.

Security teams

Real-time dashboard visibility across the organisation’s AI usage. Immediate alerts on policy violations — via dashboard notification, email, or Slack. Integration with existing SIEM infrastructure. Full audit trail for incident investigation.

Compliance officers

Exportable reports for regulatory audits. Demonstration of data protection controls in operation. Pre-built compliance templates for GDPR, ISO 42001, and EU AI Act requirements. Configurable data retention policies.

A technical conversation, before a commercial one.

If you would like to discuss the architecture in more detail — your specific integration environment, compliance requirements, or deployment constraints — we are happy to have that conversation first.