Skip to content
Early access · accepting requests, onboarding begins shortly

Ship AI features without the compliance drag.

Sombrero™ is the runtime gateway that enforces and proves AI compliance. PII guardrails, audit-ready evidence, and cost controls — one control plane between your app and every model provider. Built for SOC 2 and the EU AI Act.

Built for SOC 2 · EU AI Act on the roadmap · design-partner access, not yet GA

POST /v1/chat · your app → control plane → provider
1 · Guardrails

PII redacted · injection check · policy applied

2 · Route

provider selected · cost + rate checked · fallback ready

3 · Evidence

decision logged · control-mapped · exportable

The problem

AI shipped fast. Compliance didn't.

The teams moving fastest on AI carry the most compliance risk — and it lands on two desks at once. GRC owns the audit and the regulation. Engineering owns the traffic. Neither has a control plane between the app and the model, so the drag compounds on both.

01

Your data surface just grew

Every AI feature sends prompts — often with customer PII — to third-party models you do not control. Each new call is a new question your security review has to answer.

02

Evidence lives in screenshots

When the auditor asks how AI decisions are governed, there is no system of record. GRC chases engineers for logs; engineers stop shipping to assemble them.

03

The deadlines are already dated

The EU AI Act's transparency obligations begin to arrive as early as August 2, 2026; more frameworks are landing behind them. “We'll handle compliance later” has a date on it now.

How it works

One control plane. Three jobs.

A runtime gateway for AI traffic: it routes every request, enforces your policy in-line, and turns each decision into audit-ready evidence.

  1. 1

    Route

    Point your AI traffic at the gateway.

    Send requests through one endpoint instead of calling each provider directly. The control plane sits inline between your app and every model and tool — no rewrite of your product, one place to see and govern all AI traffic.

  2. 2

    Enforce

    Guardrails apply in real time.

    PII detection and redaction, prompt-injection and output checks, policy rules, and cost + rate controls run on every request. Each call is allowed, redacted, or blocked according to the policy you set — before data ever reaches a provider.

  3. 3

    Prove

    Every decision becomes evidence.

    The control plane records what was checked, what was enforced, and why — as control-mapped, exportable evidence. Compliance stops being a quarterly scramble and becomes a byproduct of running in production.

What it does

Three pillars, one gateway

Compliance is the outcome. The gateway is how: guardrails at the edge, evidence as a byproduct, and cost and agent controls in the same path.

Privacy & guardrails

Keep sensitive data from leaving your boundary

  • PII detection and redaction before prompts reach a provider
  • Prompt-injection and jailbreak defenses on inputs
  • Output guardrails for unsafe or non-compliant responses
  • Policies you set once and enforce on every request
GRC evidence

Turn every AI request into audit-ready proof

  • A system of record for what was checked and enforced
  • Evidence mapped to framework controls, not raw logs
  • Exportable evidence packs for your auditor
  • Designed to sync into your existing GRC platform
Cost + MCP gateway

Control spend and govern agent traffic

  • Cost and rate controls across providers, in one place
  • Provider fallback and routing when a model fails
  • An MCP gateway to govern tool and agent calls the same way
  • One view of every model and tool your product touches

Frameworks

Map evidence to the frameworks that bind you

The frameworks below are where we're focused first. We map what the control plane enforces to specific controls, so the evidence lands in the shape your auditor and your regulator expect.

SOC 2

Built for

The control plane is designed to produce control-mapped evidence for the AI portion of a SOC 2 audit — access, monitoring, and change controls over how AI requests are handled. It generates the evidence; your auditor still runs the attestation.

EU AI Act

On the roadmap

Transparency obligations under the Act begin to arrive as early as August 2, 2026, with high-risk requirements phasing in later. We're building logging and technical-documentation support to help you meet them — shipping alongside the deadlines, not after.

Also on the roadmap. Additional frameworks as design partners bring them.

  • NIST AI RMF
  • ISO 42001
  • HIPAA
  • GDPR

Sombrero™ is in early access. Framework support described here is in active development and does not constitute a certification, legal advice, or a guarantee of compliance. Regulatory dates are provided for context and may change.

Who it's for

Built for both sides of the AI compliance deal

The person who owns the audit and the person who owns the traffic need the same control plane — for different reasons. It speaks to both.

Compliance · GRC · Security · Legal

If you own SOC 2 / EU AI Act risk

  • A system of record for AI decisions — no more chasing screenshots
  • Evidence mapped to controls and exportable for your auditor
  • Guardrails you can point to when the questionnaire arrives
  • Visibility into every model and provider your product uses
Engineering · Platform · ML

If you route the AI traffic

  • A drop-in gateway — one endpoint, no product rewrite
  • Provider fallback and cost controls without gluing them yourself
  • PII redaction and injection defense you do not have to build
  • Compliance handled in the path, so you can keep shipping

FAQ

Straight answers

Is Sombrero™ generally available?

No — it's in early access. We're accepting requests now and will onboard a limited group of design partners shortly, building alongside them. Request access and we'll talk about fit.

Are you SOC 2 certified?

We don't claim a certification. The product is built to generate control-mapped evidence for the AI portion of a SOC 2 audit; the attestation is still performed by your auditor. If SOC 2 status is a gating question for you, ask us directly and we'll be precise about where things stand.

How does it install?

It runs as a gateway in front of your AI traffic — you route requests through one endpoint instead of calling providers directly, with no rewrite of your application. Exact integration steps are part of what we work through with design partners.

Which model providers and tools does it support?

It's designed to be multi-provider — a single control plane in front of the models and tools your product already uses, including an MCP gateway for agent and tool traffic. Ask us about specific providers on your stack.

Does our PII leave our environment?

Yes — today, requests route through the Sombrero™ data plane, where PII is designed to be detected and redacted before anything reaches a model provider. So it is governed before it reaches a third party, but it does transit our infrastructure. Running the data plane inside your own environment is on the roadmap; it is not available today.

What is an MCP gateway?

MCP (Model Context Protocol) is how AI applications connect to tools and data. An MCP gateway puts those tool and agent calls through the same control plane as your model traffic — so guardrails, cost controls, and evidence cover agents too, not just chat completions.

What does it cost?

During early access we work out pricing with design partners based on scope. Request access and we can walk through it.

Request early access

Ship AI. Prove it's compliant.

We're accepting requests from a small group of design partners shipping AI under SOC 2 and the EU AI Act, and will begin onboarding shortly. Tell us what you're building and we'll be in touch.

  • Direct access to the team building it
  • Shape the roadmap around your frameworks
  • Design-partner terms during early access

We'll only use your details to talk to you about early access to Sombrero™. No lists, no spam.