Self-hosted · EU-native · air-gappable · your data never leaves

Your AI.
Your rules.
Your proof.

TruCert puts one governed, OpenAI-compatible API between your applications and every AI provider — running on your own infrastructure, so prompts and data never leave your network. Then it turns that live traffic into evidence your auditor can check.

BUILT FOR DORA · NIS2 · EU AI ACT · GDPR — DEADLINE DATES WE ACTUALLY GET RIGHT
10AI providers in one catalog — plus any OpenAI-compatible endpoint
16governance modules, built in — not bolted on
100%on your infrastructure, EU-hosted or air-gapped
0prompts that leave your network
✓ Claims team hit its €50 monthly budget → next request refused by the cost engine. No surprise invoice. ✓ Provider returned 503 → adaptive routing sent the request to the fallback. Nobody noticed. TruCert #4411 · valid 29 days · renews itself while the controls keep working ✓ Someone left the company → every virtual key revoked in one action, provider secrets untouched ✓ IBAN caught by the data-protection catalog and redacted before the prompt left ✓ Semantic cache hit — the same answer served again, at no provider cost Audit-log entry signed and chained · who changed what, and when
01 — THE PROBLEM

Sound familiar?

If any of this is your company, you're normal. You're also exposed.

The bill

Nobody can see the total AI spend

Every team buys its own AI subscriptions. Finance sees a pile of invoices, not a picture.

The risk

There is no off switch

If an AI tool misbehaves today, how long until someone cuts its access everywhere? Hours? Days?

The audit

Nothing to show the auditor

Your AI policy is a PDF. A PDF proves what you intended — not what happened last month.

The fact

57% of employees hide AI use from IT

KPMG / University of Melbourne, 2025. You cannot govern what you cannot see.

02 — WHAT TRUCERT IS

A control plane you actually own.

Every request is proxied inside your own network. Your applications talk to the gateway; the gateway talks to the providers you approve. You get provider choice, guardrails and full auditing without sending a single prompt to a third-party cloud. The gateway is Xcellerate AIG, built in the EU by RMM Labs Ltd; the evidence layer on top is ours.

It installs inside your network

Docker, Kubernetes, or a self-contained appliance answering on 443 from first boot. Fully air-gappable. Your building or your cloud — never ours.

You set the rules

Virtual keys under a companies-and-teams hierarchy, each with its own budget, rate limit and model allow-list. Guardrails your DPO configures in business language, not regular expressions.

The proof writes itself

Every refused overspend, every routing fallback, every redacted record becomes audit evidence automatically — signed, chained and mapped to the regime it satisfies.

03 — ONE GATEWAY, COMPLETE CONTROL

Everything you need to put AI traffic under governance.

From provider routing to data protection — sixteen modules, all self-hosted. Your teams keep the models they want; you finally get the control point. All sixteen, in detail →

One API

Every model behind a single endpoint

Point your applications at one OpenAI-compatible endpoint and reach every provider behind it. The same request shape works whether the model runs at OpenAI, Anthropic, in your own data centre or anywhere in between.

OpenAIAnthropicGoogle GeminiAzure OpenAIAWS BedrockMistralGroqOllamaOpenRouter+ any OpenAI-compatible endpoint
Spend

Budgets that stop spending, not just report it

Set spend caps and rate limits per company, team or key — enforced by the cost engine in real time. When the budget is gone, the request stops. Tag every call and hand finance the chargeback file it actually asked for.

Claims team · monthly budget €50€50.00 / €50.00
Routing

Each request to the right model

Routing rules an operator can read: prefer the lowest-latency provider, keep data in a region, send a slice to a canary, run an A/B test, or route on what the request is actually about — and fall through when a provider fails.

primary→fallback→eu-endpoint
Access

Virtual keys, not raw credentials

Teams get a gateway key that maps to your provider accounts — the real provider secrets never leave the vault. Rotate or revoke any key without touching a provider account. Someone leaves, one action, gone everywhere.

finance-appleaver@corpds-teamagents-mcp
Privacy

Data protection in your own words

A sensitive-data catalog written in business language: national identifiers, IBANs, cards, health, salary, legal terms, internal codenames — and what should happen when each appears. Block, redact, or simply record.

Guardrails

Screen every prompt and response

Guardrails inspect traffic on the way in and the way out — as plain topics, backed by a model asked to judge the content, or by an external service you call.

Record

Tamper-evident audit log

Who changed what, and when — chained so it cannot be quietly rewritten. Signed outbound webhooks let downstream systems trust the events they receive.

04 — THE PROOF (ASSURE)

A certificate that stays honest — or visibly expires.

A normal certificate says your controls worked on audit day. A TruCert is rebuilt every 29 days from what actually happened in the gateway's own request logs, audit trail and routing records — and it lapses the moment good behaviour stops. Your auditor sees living proof or an honest gap, never a stale yes. How Assure works →

PROOF OF WORKING CONTROLS
TruCert № 4411
29d
AI requests through the gateway214,092
Budgets enforced by the cost engine3 ✓
Routing fallbacks on real traffic2 ✓
Requests sent outside Europe0 ✓
⧗ KEPT FRESH BY REAL USE — NOT BY A SIGNATURE
EU AI ActYour disclosure list is ready today (Art. 50) · logging shaped for the Dec 2027 duties — start the paper trail early.
DORAYour AI provider register, plus proof your exit plan actually works (Arts. 28–30).
NIS2 + GDPRAccess-control proof and data-processor maps — built from real traffic, not questionnaires.
SovereigntySigned proof of where every request went. No other gateway offers this — verified, mid-2026.
05 — READINESS CHECK

How exposed is your company today?

Five yes/no questions, one at a time. Your score appears immediately — we only ask for email to send the full report.

Your ECB action plan is due 31 October 2026. One sentence belongs in it: all AI traffic passes through one gateway you own.
QUESTION 1 / 5 · COST
Do you know what each team spends on AI, today?
QUESTION 2 / 5 · CONTINUITY
If your main AI provider went down tomorrow, could you switch within a week — without changing your software?
QUESTION 3 / 5 · CONTROL
Can you revoke every AI access credential from one place?
QUESTION 4 / 5 · CUSTODY
Do your AI prompts and records stay inside your own infrastructure?
QUESTION 5 / 5 · PROOF
Could you hand an auditor proof that these controls actually ran last month?

See TruCert on your own stack.

Tell us which providers and applications you run today and we'll show you how to put them under one governed gateway — and what the evidence looks like when it comes out the other side.

Talk to us How we work — in the open