Resources

What is an AI / LLM gateway in your network?

An AI or LLM gateway is a control point you run in your own network that inspects agent and model traffic — prompts, tool calls, and completions — so unsafe actions can be blocked, logs can be kept, and spend can be attributed to agents rather than seats.

Teams add a gateway when agents start calling tools, MCP servers, and paid model APIs without a single inspectable path. UnitOne Gateway is that path: stop unsafe tool use, keep CRA-style logs, then cap spend. Gateway is self-serve. Finding → Fix Spec → PR remediation is a scoped POC.

What an in-network agent gateway does

  1. 1

    Sit on the agent path, not beside it

    If traffic can bypass the gateway, you cannot block a tool or attribute a dollar. Deploy Gateway in your network so agent workloads send tool calls and model requests through a path you control.

  2. 2

    Inspect and block unsafe tool use

    Agents fail when tools are poisoned, over-scoped, or invoked with attacker-controlled context. The gateway applies policy before the tool runs — not after a dashboard lights up.

  3. 3

    Keep logs you can export

    When Article 14-style duties ask what happened, you need the agent, tool, decision, and timestamp. That is operational evidence, not a legal determination of CRA scope.

  4. 4

    Attribute spend to agents, then set caps

    Seats are humans in the console. Agents are AI workloads that pass through Gateway. Caps only work if discovery experiments and published production agents are separate identities with their own event budgets.

  5. 5

    Start free, then pick a plan by agents and events

    Free includes Gateway in your network, 10 agents, 2 seats, and 25,000 gateway events per month. Team is $99/month for 100 agents and 500,000 events. Enterprise is talk to us. See How to start a Gateway trial.

Frequently asked questions

What is an AI / LLM gateway in your network?
An AI or LLM gateway is a reverse-proxy-style control point for model and agent traffic that you run in your environment. Requests, tool calls, and completions pass through it so you can inspect, allow, or block them and keep logs. UnitOne Gateway is that control point for agent traffic: security and CRA-style evidence first, then spend attribution.
How is an in-network gateway different from a public AI proxy?
A public proxy sends agent traffic through a vendor's shared path. An in-network gateway keeps that traffic in your environment. UnitOne Gateway in your network is included on Free, Team, and Enterprise. You do not have to send agent traffic through a shared public proxy as the default model.
How does Gateway control agent spend and security?
Security first: inspect tool calls and block poisoned tools, over-scoped access, and unsafe actions. Then keep exportable logs for vulnerability handling. Then attribute spend by agent, team, or project and set caps. Observation without a deny path is not control.
Is UnitOne Gateway a cost dashboard?
No. Cost dashboards show tokens. Gateway starts by stopping unsafe agent behavior and keeping logs you can export. Spend caps come after you can name the agent that spent the money.
Does Gateway replace an MCP scanner?
No. A scanner grades a server before you connect it. Gateway inspects tool calls at runtime. See Gateway vs MCP scanner.

Run Gateway in your network

Start free to inspect agent traffic where it already runs. See plans for Team and Enterprise limits. Talk to us for SSO, MSA/BAA/DPA, or CRA readiness help.