PII & secrets masking
Detect and mask emails, phones, MRNs, card numbers and API keys before any provider call — with reversible tokens for your tenants.
One consistent safety and compliance policy across every model — even local ones — enforced at the gateway with immutable audit lineage.
Controls audited annually
Information security mgmt
PHI controls & BAAs
EU residency & DPIA ready
Every request is inspected, transformed and logged — provider-agnostic, so your policy holds even when the model changes.
Detect and mask emails, phones, MRNs, card numbers and API keys before any provider call — with reversible tokens for your tenants.
Detect prompt-injection, jailbreaks and tool-abuse on both input and output — block, sanitize or quarantine with policy.
Configurable toxicity, violence, self-harm and policy filters with thresholds per tenant and per feature.
Per-tenant token budgets, RPS limits and burst controls — with fair-share scheduling and backpressure.
Region-locked routing keeps regulated workloads inside the right jurisdiction — EU, US, APAC or on-prem.
Every transform, route and policy decision is immutable, searchable and exportable to your SIEM or warehouse.
SSO/SAML, API keys and mTLS. Request is tagged with tenant, scope, residency and sensitivity class.
PII/PHI masking, injection defense, content policy and budget checks run before any model is selected.
The router picks the optimal model respecting residency, budget and quality gates — with failover armed.
Moderation, toxicity, schema validation and secret-leak detection run on the response before release.
The full lineage — transforms, route, cost, latency, policy verdicts — is written immutably and exported.
Run OMNOXA as a managed control plane, in your own VPC, or fully on-prem. Sensitive payloads never have to leave your network.
Get our security whitepaper, latest attestations and a walkthrough with our security team.