CattleGrid sits between your applications and AI providers. Every AI API request passes through it. Before anything reaches Anthropic, OpenAI, Mistral, or Google, CattleGrid inspects the content, enforces your rules, and either blocks the request, redacts the sensitive data, or lets it through – logged and audited. It retains none of your data. Inspect, redact, block, discard. That is the complete sequence.
CattleGrid does not inspect AI responses. What the AI generates travels directly back to your application with zero buffering and zero modification. CattleGrid does not store customer request content – it exists only during processing and is discarded when the request completes. There is no database of your prompts. There is no log of what your staff typed.
The only records retained are: usage metadata ( counts, latencies, status codes), violation summaries (rule triggered and action taken – not the content that triggered it), and configuration audit events.
This is not a policy position. It is an architectural constraint enforced at every layer.
CattleGrid inspects the content of every outbound request against your configured inspection rules. Rules can match regex patterns (e.g. UK National Insurance numbers, credit card numbers, postcodes) or keyword blocklists (e.g. internal project names, customer identifiers). When a rule triggers, CattleGrid can:
Developers and automated systems may inadvertently send sensitive data (National Insurance numbers, credit card numbers, API keys, internal credentials) to third-party AI providers.
Once sent, you cannot retrieve it.
The UK GDPR (Data Protection Act 2018) requires organisations to demonstrate data minimisation, purpose limitation, and appropriate safeguards when processing personal data – including when sending it to AI providers.
Most organisations have limited visibility into what data is being sent to AI providers, by whom, and how often.
Without a centralised gateway, every team implements (or forgets) its own safeguards.
Block the request entirely – nothing reaches the AI provider.
Redact the matched content – replace it with tokens and forward the sanitised request.
forward the request unchanged but add an warning header and log the violation.
Forward the request unchanged and silently record the violation
This programme admits a small number of UK and EU-based organisations into the first CattleGrid deployment cohort. Early participants help shape the product, receive preferential commercial terms and gain direct access to the product team. Places are limited, and we are accepting requests to join the waitlist.