GDPR-Compliant AI Gateway
Your company's AI use, controlled and on the record.
AI tools are part of the working day now. But every customer record that reaches one of them is still your responsibility as controller. AI Security Gateway puts your organisation's AI traffic behind a single door: personal data is masked before it leaves, every call is written to a tamper-evident log, and the evidence is ready the moment somebody asks for it.
Installing it is a one-line change in your systems.
Audit log · live
- 14:02national ID masked
- 14:02destination: EU · permitted
- 14:03account number masked
- 14:03entry sealed
Risk
You are carrying a risk you cannot see.
Your staff already use these tools — you just cannot see it
A contract gets summarised, a customer complaint gets drafted, a spreadsheet gets cleaned up. None of it is done in bad faith. But until you record who pasted what into which tool, you genuinely do not know what has left the building.
Sending data outside the EEA is a regulated transfer
Most AI services process your data on servers outside the European Economic Area. Under Chapter V of the GDPR that is an international transfer with its own conditions. How easy the tool is to use does not change that.
The controller carries the liability
When something goes wrong, the regulator comes to you, not to the company that built the model. Administrative fines run to €20 million or 4% of global annual turnover, whichever is higher — and the more expensive damage is usually to customer trust. “We did not know” is not a defence.
And it is no longer only a GDPR question
The EU AI Act's transparency obligations have applied since 2 August 2026, with penalties up to €15 million or 3% of global annual turnover. Its reach does not stop at the border either: if the output of your AI system is used in the Union, you can fall in scope even when your company sits outside it. For anyone selling into Europe, “visibility first, control second” is no longer something to postpone.
Who here is sending what, and where?
Can you answer that today?
How it works
What AI Security Gateway does
All AI traffic in your organisation passes through one point. Three things happen there.
01
Protects
Requests are inspected before they leave. Where personal data is found it is swapped for a placeholder, so the outgoing text carries none of it. When the answer comes back the placeholder is restored and the user's flow is untouched.
02
Records
Every request is logged: who, when, to which tool, with what category of data. Entries are sealed so they cannot be edited afterwards — nobody, including your own team, can quietly correct a line in the past.
03
Evidences
When an audit lands, the report is already there. Which data categories were processed, which destinations were used and which requests were blocked, in one document. No scraping through months of logs.
Features
Nine of them.
- Personal Data Shield
- Names, phone numbers, emails and addresses are masked before a request leaves.
- Special Category Lock
- Health, biometric, religious and criminal-offence data can be governed by a separate, stricter rule set.
- Transfer Control
- You decide which destinations may receive data. A request to anywhere else does not go through.
- Tamper-Evident Log
- Entries are sealed. They cannot be deleted or edited, and the integrity of the record can be demonstrated in an audit.
- One-Click Audit Report
- A ready report for the period you choose: what was processed, where it went, what was blocked.
- AI Usage Map
- Which team uses which tool, how often. The picture you need before writing a policy.
- Malicious Prompt Blocking
- Requests aimed at manipulating your system or escaping its permissions are detected and stopped.
- On-Premise Deployment
- It can run entirely on your own hardware. In that setup no data leaves the organisation at all.
- Works With What You Have
- You do not rewrite your applications; the gateway sits in between and the flow stays the same.
Security
Your data does not sit with us either.
A compliance tool must not become a new source of risk. The gateway is built to pass data through rather than keep it: personal data is already masked by the time a request leaves, and raw content does not accumulate on our side.
Choose the on-premise deployment and the question disappears entirely — the system runs on your hardware, with no outbound connection.
We document what we cover — and, just as clearly, what we do not.
Track record
Built by a studio that works in regulated sectors
AI Security Gateway was designed by Neveratech, which builds software in sectors where data is at its most sensitive — healthcare among them. We run the modernisation of a clinical platform used in roughly a hundred hospitals, on an on-premise architecture where data never leaves the institution. “On-premise deployment” is not a checkbox for us; it is the model we work in every day.
Advisory
If you do not yet know where you stand
Not every organisation needs software first. Some need a clear answer to one question: who here uses which tool, with what data?
The AI Usage Assessment answers exactly that. It produces your usage inventory, maps where data is going, assesses in technical terms whether the EU AI Act applies to you, and leaves you a draft internal usage policy.
You end up with a roadmap: what to fix with process and what to fix with software. If you do not need the gateway, we will say so.
- Usage inventory — who, which tool, what data
- Transfer map — where data goes, and the GDPR Chapter V position
- EU AI Act scoping — technical assessment
- Policy and training — draft usage policy, staff briefing
- Roadmap — what to solve with process, what with software
We build the technical and organisational side. Legal opinions, registrations and sign-off on legal texts sit with the legal side we work alongside.
FAQ
Frequently asked.
- Do we have to ban the tools our staff use?
- No. Bans mostly fail — the usage does not stop, it just becomes invisible. The gateway exists so that use can continue while being visible and recorded.
- How long does deployment take?
- Pointing the address your applications already call at the gateway is enough. No rewrite on the application side.
- Will responses get slower?
- The gateway is a layer in the path, so it adds time per request. What that comes to in your setup is something we can measure together on the call.
- Does our data sit on your servers?
- With the on-premise deployment, no — nothing leaves your organisation. In the hosted deployment personal data is already masked before a request leaves, and raw content does not accumulate.
- Which AI tools does it work with?
- The gateway sits between your applications and the service. Tell us on the call which tools are in use and we will confirm the fit together.
- Will these logs be enough in an audit?
- The logs produce the trail you need to evidence your processing activity. How that trail is assessed and presented is a legal question; we supply the infrastructure and the document.
- We are a small team — is this for us?
- The nature of the data matters more than headcount. If you handle customer records, health data or contracts, the obligation does not scale with team size.
- Can we take the advisory work without the product?
- Yes. The AI Usage Assessment is a scoped, standalone engagement. If it turns out you do not need the gateway, we will tell you.
- Is this legal advice?
- No. We build the technical and organisational side: inventory, transfer map, technical mechanisms, draft policy, training. Legal opinions and sign-off sit with the legal side.
Contact
Fifteen minutes is enough.
We do not need access to your systems — we will show you the product live, then talk about what it means in your setup.
You decide what the call is about: seeing the product, or working out where to start.
or write directly to [email protected]