Monitor. Or block.

Move from passive monitoring to active protection. The Guard Gateway sits in your request path and intercepts dangerous responses before they reach users.

Three response modes

Configure per-rule how the gateway handles flagged content.

Block

Reject dangerous responses entirely. When a response contains critical issues, it never reaches the user. Your agent receives a rejection signal to retry or escalate.

Response blocked: contains unredacted SSN

Mask

Partially hide sensitive data while keeping the response useful. Social security numbers become ***-**-6789. Card numbers show only the last four digits.

Your SSN is ***-**-6789

Redact

Fully remove sensitive content and replace with a placeholder. The response continues to flow, but sensitive information is stripped completely.

Your SSN is [REDACTED]

Use your own API key

Route gateway requests through your own provider key. Your key is encrypted at rest and used exclusively for your traffic. You control the provider, model, and spend. We never see your raw key after initial encryption.

Monitoring + protection

Observe monitors passively. Guard acts on what it finds.

ObservePassive

Traces arrive after the fact. You see everything, flag issues, set alerts. Your agent flow is untouched.

Guard GatewayActive

Sits in the request path. Scans responses in real time. Blocks, masks, or redacts before the response reaches your user.

Start monitoring free

Guard Gateway included on all plans. 500 requests/month free.