The same policy for the traffic a browser never sees.
Apps, scripts and agents call AI through an OpenAI-compatible endpoint with keys you issue. The gateway applies your policy, redacts payloads before they reach a provider, and writes to the same evidence log.

Developer and API governance.
Policy for machine-to-model traffic.
The challenge
Internal tools, scripts and AI agents send prompts to model APIs directly. They carry the same customer data as a person's prompt, with no browser in the path.
Why existing controls miss it
Browser controls cannot see server-side API calls, and provider consoles offer no organisation-wide data policy.
How Deltawall enforces it
Route AI calls through the gateway on keys you issue. Each key carries a policy; payloads are redacted before the provider sees them, and non-EU providers can be blocked per department.
- OpenAI-compatible, so existing SDKs work
- Streaming responses supported
- Every call lands in the evidence log
EU first, by rule.
- Providers
- Mistral EUAzure OpenAI EU EUOpenAIAnthropicDeepSeekMistral and Azure OpenAI EU keep data in the EU. OpenAI, Anthropic and DeepSeek can be blocked per department.
- Per-key policy
- RedactBlockAllow-list of providers
- Protocol
- OpenAI-compatibleStreaming
- Evidence
- Same chain as the browser
See it stop real-looking data in a real browser.
A 30-minute technical walkthrough: a prompt redacted, a file stopped, the dashboard, and an evidence pack verified offline in front of you.
No slide deck. Synthetic data only.
