Skip to main content
Shield · LLM Security Gateway & Platform

Anonymising outbound.
Rehydrate inbound.

Shield sits in front of every AI tool your team uses and replaces the secrets and PII its filter packs match with placeholders, outbound, before they leave your company, then rehydrated inbound so your developers never notice.

AI Coding Tool Security · Secret Leak Prevention · Audit-Ready by Design

Building security infrastructure for AI-native teams.

The App

One binary. One config. Every tool covered.

Shield runs on your machine, not ours. The gateway, the CLI, the dashboard, the audit log: all one binary. No hosted service. No data pipeline.

One install, every tool
One local gateway. Plugins auto-install for the LLM CLIs your team already uses, Claude Code, Codex, Cursor, DeepSeek, Ollama.
Transparent redaction
Secrets and PII your packs match become placeholders outbound, then rehydrate inbound. The provider never sees the real value; the developer never notices.
Belt and suspenders
The plugin catches obvious leaks at the agent-loop boundary; the gateway scrubs the wire. If one layer misses, the other catches.
Desktop coverage
Claude Desktop, Cursor, VS Code Copilot, Zed, Continue, routed through the gateway with backup, restore, and health checks per app.
What the model saw
[REDACTED:AWS_KEY_001]
[REDACTED:PHI_NAME_001]
[REDACTED:JWT_001]
...sanitized payload

Redacted tokens. Sanitized payloads. Matched PHI never sent in the clear.

What your developer saw
AKIA2X9...REAL_KEY
Sarah Johnson
eyJhbGci...full_token
...full response

Real values. Full responses. Nothing hidden from the developer.

Pricing

Two ways to run Shield

Own the source outright, or subscribe to the app. Same binary either way.

Flat, scoped engagements. Deployed on your infrastructure, source delivered at handoff. No license server, no subscription, no kill switch.

🚦
Foundation
Scoped pricing

The gateway on your infrastructure, with the source.

Shield deployed where your team works, tuned to the data you actually handle. Source delivered at handoff.

Gateway on your infrastructure, local or remote
Plugins for the LLM tools your team already uses
Filter packs tuned to your domain
Local, tamper-evident audit trail
Full source delivery
Most Popular
📋
Compliance
Scoped pricing

Foundation, plus the evidence your auditors ask for.

Every redaction becomes reviewable evidence: who triggered it, from what tool, what category was caught. Never the raw values.

Everything in Foundation
Audit sidecar and dashboard
Evidence export for SOC 2 and HIPAA programs
Extensible through Go interfaces
🏗️
Custom
Scoped pricing

Scoped to your environment.

The full platform, shaped around your requirements. We work out what you need on a call.

Everything in Compliance
Semantic detection beyond pattern matching
Federated, org-wide visibility
Filter authoring and CI integration
Platform Capabilities

Built the way you'd build it.

Go interfaces, not registries. Compile-time safety, not runtime plugins. The platform extends the app. It doesn't replace it.

Plugin system
Go interfaces as extension points: FilterHook, DashboardHook, ProxyHook, TelemetryHook, SettingsHook. Compile-time safety, no registry, no init().
Supervisor + circuit breaker
One lifecycle: StartAll, StopAll, Reload. Fail-open degrade with exponential backoff; three failures open the circuit. Dashboard shows green / yellow / red.
Federated dashboard
S3 federation. Every host ships events to your bucket, your keys. Org-wide view, drill by host, user, team. Local-only or federated, your call.
Audit system
Hash-chained, encrypted JSONL. Every redaction becomes tamper-evident evidence. SOC 2 and HIPAA exports, one command.
GPU orchestration
Provision defense models on your cloud (Linode today, more to come). Semantic scoring that catches what regex can't, with zero data leaving your network.
RemoteFilter + EntityTable
Custom-tier semantic layer. Multilingual named-entity recognition and linkage: a codebook, not a vector index. Redacts on the wire, role-preserving.
Full Shield details
Intake Portal

Let's Build.

Submit your technical details and we will formulate a production scope, architectural dependencies, and exact model selection profiles.