What CattleGrid Does

CattleGrid sits between your applications and AI providers. Every AI API request passes through it. Before anything reaches Anthropic, OpenAI, Mistral, or Google, CattleGrid inspects the content, enforces your rules, and either blocks the request, redacts the sensitive data, or lets it through – logged and audited. It retains none of your data. Inspect, redact, block, discard. That is the complete sequence.

What it never does

CattleGrid does not inspect AI responses. What the AI generates travels directly back to your application with zero buffering and zero modification. CattleGrid does not store customer request content – it exists only during processing and is discarded when the request completes. There is no database of your prompts. There is no log of what your staff typed.

The only records retained are: usage metadata ( counts, latencies, status codes), violation summaries (rule triggered and action taken – not the content that triggered it), and configuration audit events.

This is not a policy position. It is an architectural constraint enforced at every layer.

Prevent sensitive data leakage

CattleGrid inspects the content of every outbound request against your configured inspection rules. Rules can match regex patterns (e.g. UK National Insurance numbers, credit card numbers, postcodes) or keyword blocklists (e.g. internal project names, customer identifiers). When a rule triggers, CattleGrid can:

Data leakage risk

Developers and automated systems may inadvertently send sensitive data (National Insurance numbers, credit card numbers, API keys, internal credentials) to third-party AI providers.

Once sent, you cannot retrieve it.

Regulatory compliance

The UK GDPR (Data Protection Act 2018) requires organisations to demonstrate data minimisation, purpose limitation, and appropriate safeguards when processing personal data – including when sending it to AI providers.

Visibility gap

Most organisations have limited visibility into what data is being sent to AI providers, by whom, and how often.

Inconsistent controls

Without a centralised gateway, every team implements (or forgets) its own safeguards.

Block

Block the request entirely – nothing reaches the AI provider.

Redact 

Redact the matched content – replace it with tokens and forward the sanitised request.

Warn

forward the request unchanged but add an warning header and log the violation.

Log

Forward the request unchanged and silently record the violation

Signup to CattleGrid Early Access Programme

Signup to CattleGrid
Early Access Programme.

This programme admits a small number of UK and EU-based organisations into the first CattleGrid deployment cohort. Early participants help shape the product, receive preferential commercial terms and gain direct access to the product team. Places are limited, and we are accepting requests to join the waitlist.