Stop unsafe agent actions. Stay CRA-ready. Cap spend.
Gateway sits in your network. It blocks poisoned tools and over-scoped access, keeps logs you can export for Article 14-style duties, and attributes spend so you can set caps.
Run agents safely in your network. Gateway blocks unsafe tool use, keeps CRA-ready evidence, and attributes spend.
Security
Stop poisoned tools, over-scoped access, and unsafe agent actions at runtime.
Compliance (CRA)
Keep logs you can export for vulnerability handling and Article 14-style duties.
Cost
See spend by agent, team, or project — and set caps.
Deploy Gateway in your network on AWS, Azure, or GCP
Data plane stays with you. Policy, evidence, and spend views sync over outbound HTTPS.
Your AWS account — data plane
Prompts, virtual keys, spend · VPC · AWS · Azure · GCP
Load balancer
HTTPS into your VPC
UnitOne Gateway
Compute in private subnets
Database
Spend + keys
Secrets
Customer-managed
Model providers
Called through your egress
Agents & tools
Inspected in your account
Outbound HTTPS
Customer-controlled NAT
UnitOne — control plane
Tenant config, policy, inventory, evidence
API + console
Registration, spend views, policy, compliance
Tenant database
Inventory + evidence
Key vault
Control-plane secrets
Identity federation
Token exchanged at STS
Customer data plane on the left: agents and apps reach UnitOne Gateway in your VPC, then models and tools, with customer-controlled egress. UnitOne control plane on the right: API, console, policy, CRA evidence, and spend. Sync uses admin API, identity federation, and webhooks over outbound HTTPS only.
How multi-cloud deploy works? FAQ
Guides
CRA evidence, the agent gateway, discovery-to-publish spend, MCP controls, and Finding → Fix Spec → PR.
CRA Article 14 essentials checklist
A practical Cyber Resilience Act Article 14 checklist for products with digital elements and agentic software: reporting timelines, user notification, and fix-ready evidence.
Read the guide →What is an AI / LLM gateway in your network?
An AI gateway inspects agent and model traffic on a path you control. How UnitOne Gateway uses that path for security, CRA-style logs, then spend caps.
Read the guide →Agent discovery to publishing spend
Where agent cost leaks between discovery, experimentation, and publishing to production — and how Gateway attributes spend to agents, not seats.
Read the guide →Agent discovery: find every agent and MCP
Discover every AI agent and MCP server in your estate, map who can call which tools, and make agent spend and tool calls governable with UnitOne Gateway.
Read the guide →Cap AI agent spend without blocking teams
Cap AI agent spend by identity: attribute usage by agent/team, block unsafe tools, keep CRA-ready logs. Start free on UnitOne Gateway.
Read the guide →MCP server enterprise readiness checklist
Use this MCP server enterprise readiness checklist to inventory tools, owners, permissions, data access, and change risk before setting policy.
Read the guide →MCP server enterprise-ready security rubric
A security rubric for Model Context Protocol servers covering identity, tool scope, secrets, untrusted input, logging, and change control.
Read the guide →Finding to fix spec to PR
How intent-preserving remediation turns a security finding into a constrained fix spec and a reviewable pull request without breaking developer intent.
Read the guide →PE portfolio security remediation playbook
A practical playbook for PE operating teams to prioritize portfolio findings, increase fix capacity, and create repeatable remediation evidence.
Read the guide →Intent-preserving CVE remediation vs. naive auto-fix
Learn why naive CVE auto-fixes break application intent and how reviewable, context-aware remediation paths help teams fix vulnerabilities safely.
Read the guide →Common questions
How Gateway differs from a cost dashboard, in-network deploy on AWS, Azure, or GCP, CRA evidence, and how to start.
Talk to us
Enterprise Gateway, SSO, MSA/BAA/DPA, or CRA readiness help.
