How it works

Inside the governed gateway.

Every request your team makes — whether through chat or the API — passes through one accountable control plane. Here's exactly what that means in practice, and what happens to your data at each step.

Access

Two ways your people work.

Same governance, whichever they choose — nothing escapes the gateway.

Private chat

A secure, branded chat workspace — like a private ChatGPT for your whole organisation. Staff sign in with your identity provider and talk to any approved model. We route only to endpoints contracted not to train on or retain your data, and every message runs through the same controls as the API.

Direct API

A single, drop-in-compatible endpoint for your developers and applications. Point existing code at theaico and you inherit every guardrail, quota and log automatically — then switch the model behind it whenever you like, without changing a line of code.

The controls

What runs on every request.

Layers of governance applied automatically — on the way in and on the way out.

Data-loss prevention & redaction

Before a prompt ever leaves your environment, it's inspected for sensitive data — names, emails, phone numbers, credit-card and tax-file numbers, API keys, secrets and any custom patterns you define. Matches are redacted or blocked according to your policy, so confidential information never reaches a model provider.

  • PII, financial and secret/credential detection out of the box
  • Custom keyword and pattern rules per organisation
  • Redact, block or alert — your choice for each data type
  • Applied to model responses too, not just prompts

Guardrails & policy enforcement

Policy decides what's allowed before a request is ever fulfilled — which models, which users, and which kinds of content. Prompt-injection and unsafe-content checks run inline, and anything outside policy is stopped at the gateway, not discovered after the fact.

  • Allow or deny specific models per team or role
  • Content and safety filtering on input and output
  • Prompt-injection and jailbreak detection
  • Enforced server-side — users can't switch it off

Quotas, budgets & spend control

Every user and department gets a budget. Set hard or soft limits by cost, tokens or request volume over any period. When a limit is reached, theaico throttles or blocks automatically — so there are no surprise bills, and no single team can run away with spend.

  • Per-user and per-department limits
  • Cap by cost, tokens or request count
  • Daily, weekly or monthly windows
  • Enforced in real time — not a month-end shock

Logging & audit trail

Every request and response is logged — who asked, when, which model, what it cost, and whether any policy fired. It's a complete, attributable audit trail your security and compliance teams can search, export and retain to meet their obligations.

  • Full request/response capture, with redaction respected
  • Attribution by user, model and cost
  • Every DLP and policy event recorded
  • Exportable for SIEM, finance and audit

Reporting & insight

Those logs become answers. Dashboards and scheduled reports show usage and cost by person, team and model, where data was redacted, and where you could save by switching models — ready for finance, security and the board.

  • Cost and usage by user, department and model
  • Redaction and policy activity at a glance
  • Trend and forecast views
  • Scheduled exports to finance and security
The journey

What happens to a single request.

From keystroke to answer — and it all happens in milliseconds.

  1. Request made

    A user sends a message in private chat, or one of your applications calls the API with its theaico key.

  2. Identity & quota check

    We confirm who's asking and that their team is within budget. Over a limit? The request is throttled or stopped right here.

  3. Inspect & redact

    The prompt is scanned for sensitive data. Anything confidential is redacted or blocked before it goes any further.

  4. Apply guardrails

    Policy and safety checks run — approved model, approved content, no injection. Only compliant requests pass through.

  5. Route to the model

    The request goes to the chosen model under our enterprise agreement. Swap models whenever you like; nothing else changes.

  6. Filter the response

    The model's answer is checked and redacted the same way on its journey back to the user.

  7. Log & meter

    The whole exchange is logged and costed against the right user and department, ready for your reports.

See it running on your own data.

A short demo walks through chat, the API, and the controls above — set up for your environment.

Book a demo