Stop unsafe agent actions. Stay CRA-ready. Cap spend.

Gateway sits in your network. It blocks poisoned tools and over-scoped access, keeps logs you can export for Article 14-style duties, and attributes spend so you can set caps.

See plans · Talk to us

Run agents safely in your network. Gateway blocks unsafe tool use, keeps CRA-ready evidence, and attributes spend.

Security

Stop poisoned tools, over-scoped access, and unsafe agent actions at runtime.

Compliance (CRA)

Keep logs you can export for vulnerability handling and Article 14-style duties.

Cost

See spend by agent, team, or project — and set caps.

Deploy Gateway in your network on AWS, Azure, or GCP

Data plane stays with you. Policy, evidence, and spend views sync over outbound HTTPS.

Agents / apps
Gatewayin your VPC
Models & tools
Control planepolicy · CRA evidence · spend

Your AWS account — data plane

Prompts, virtual keys, spend · VPC · AWS · Azure · GCP

Load balancer

HTTPS into your VPC

UnitOne Gateway

Compute in private subnets

Database

Spend + keys

Secrets

Customer-managed

Model providers

Called through your egress

Agents & tools

Inspected in your account

Outbound HTTPS

Customer-controlled NAT

UnitOne — control plane

Tenant config, policy, inventory, evidence

API + console

Registration, spend views, policy, compliance

Tenant database

Inventory + evidence

Key vault

Control-plane secrets

Identity federation

Token exchanged at STS

Trust boundary — outbound HTTPS only

Customer data plane on the left: agents and apps reach UnitOne Gateway in your VPC, then models and tools, with customer-controlled egress. UnitOne control plane on the right: API, console, policy, CRA evidence, and spend. Sync uses admin API, identity federation, and webhooks over outbound HTTPS only.

How multi-cloud deploy works? FAQ

Guides

CRA evidence, the agent gateway, discovery-to-publish spend, MCP controls, and Finding → Fix Spec → PR.

CRA Article 14 essentials checklist

A practical Cyber Resilience Act Article 14 checklist for products with digital elements and agentic software: reporting timelines, user notification, and fix-ready evidence.

Read the guide →

What is an AI / LLM gateway in your network?

An AI gateway inspects agent and model traffic on a path you control. How UnitOne Gateway uses that path for security, CRA-style logs, then spend caps.

Read the guide →

Agent discovery to publishing spend

Where agent cost leaks between discovery, experimentation, and publishing to production — and how Gateway attributes spend to agents, not seats.

Read the guide →

Agent discovery: find every agent and MCP

Discover every AI agent and MCP server in your estate, map who can call which tools, and make agent spend and tool calls governable with UnitOne Gateway.

Read the guide →

Cap AI agent spend without blocking teams

Cap AI agent spend by identity: attribute usage by agent/team, block unsafe tools, keep CRA-ready logs. Start free on UnitOne Gateway.

Read the guide →

MCP server enterprise readiness checklist

Use this MCP server enterprise readiness checklist to inventory tools, owners, permissions, data access, and change risk before setting policy.

Read the guide →

MCP server enterprise-ready security rubric

A security rubric for Model Context Protocol servers covering identity, tool scope, secrets, untrusted input, logging, and change control.

Read the guide →

Finding to fix spec to PR

How intent-preserving remediation turns a security finding into a constrained fix spec and a reviewable pull request without breaking developer intent.

Read the guide →

PE portfolio security remediation playbook

A practical playbook for PE operating teams to prioritize portfolio findings, increase fix capacity, and create repeatable remediation evidence.

Read the guide →

Intent-preserving CVE remediation vs. naive auto-fix

Learn why naive CVE auto-fixes break application intent and how reviewable, context-aware remediation paths help teams fix vulnerabilities safely.

Read the guide →

Common questions

How Gateway differs from a cost dashboard, in-network deploy on AWS, Azure, or GCP, CRA evidence, and how to start.

Architecture · Multi-cloud deploy · FAQ →

Talk to us

Enterprise Gateway, SSO, MSA/BAA/DPA, or CRA readiness help.