Skip to content

GDPR-Compliant AI Gateway

Your company's AI use, controlled and on the record.

AI tools are part of the working day now. But every customer record that reaches one of them is still your responsibility as controller. AI Security Gateway puts your organisation's AI traffic behind a single door: personal data is masked before it leaves, every call is written to a tamper-evident log, and the evidence is ready the moment somebody asks for it.

Installing it is a one-line change in your systems.

Audit log · live

  • 14:02national ID masked
  • 14:02destination: EU · permitted
  • 14:03account number masked
  • 14:03entry sealed

Risk

You are carrying a risk you cannot see.

  • Your staff already use these tools — you just cannot see it

    A contract gets summarised, a customer complaint gets drafted, a spreadsheet gets cleaned up. None of it is done in bad faith. But until you record who pasted what into which tool, you genuinely do not know what has left the building.

  • Sending data outside the EEA is a regulated transfer

    Most AI services process your data on servers outside the European Economic Area. Under Chapter V of the GDPR that is an international transfer with its own conditions. How easy the tool is to use does not change that.

  • The controller carries the liability

    When something goes wrong, the regulator comes to you, not to the company that built the model. Administrative fines run to €20 million or 4% of global annual turnover, whichever is higher — and the more expensive damage is usually to customer trust. “We did not know” is not a defence.

  • And it is no longer only a GDPR question

    The EU AI Act's transparency obligations have applied since 2 August 2026, with penalties up to €15 million or 3% of global annual turnover. Its reach does not stop at the border either: if the output of your AI system is used in the Union, you can fall in scope even when your company sits outside it. For anyone selling into Europe, “visibility first, control second” is no longer something to postpone.

Who here is sending what, and where?

Can you answer that today?

How it works

What AI Security Gateway does

All AI traffic in your organisation passes through one point. Three things happen there.

  1. 01

    Protects

    Requests are inspected before they leave. Where personal data is found it is swapped for a placeholder, so the outgoing text carries none of it. When the answer comes back the placeholder is restored and the user's flow is untouched.

  2. 02

    Records

    Every request is logged: who, when, to which tool, with what category of data. Entries are sealed so they cannot be edited afterwards — nobody, including your own team, can quietly correct a line in the past.

  3. 03

    Evidences

    When an audit lands, the report is already there. Which data categories were processed, which destinations were used and which requests were blocked, in one document. No scraping through months of logs.

Features

Nine of them.

Personal Data Shield
Names, phone numbers, emails and addresses are masked before a request leaves.
Special Category Lock
Health, biometric, religious and criminal-offence data can be governed by a separate, stricter rule set.
Transfer Control
You decide which destinations may receive data. A request to anywhere else does not go through.
Tamper-Evident Log
Entries are sealed. They cannot be deleted or edited, and the integrity of the record can be demonstrated in an audit.
One-Click Audit Report
A ready report for the period you choose: what was processed, where it went, what was blocked.
AI Usage Map
Which team uses which tool, how often. The picture you need before writing a policy.
Malicious Prompt Blocking
Requests aimed at manipulating your system or escaping its permissions are detected and stopped.
On-Premise Deployment
It can run entirely on your own hardware. In that setup no data leaves the organisation at all.
Works With What You Have
You do not rewrite your applications; the gateway sits in between and the flow stays the same.

Security

Your data does not sit with us either.

A compliance tool must not become a new source of risk. The gateway is built to pass data through rather than keep it: personal data is already masked by the time a request leaves, and raw content does not accumulate on our side.

Choose the on-premise deployment and the question disappears entirely — the system runs on your hardware, with no outbound connection.

We document what we cover — and, just as clearly, what we do not.

Track record

Built by a studio that works in regulated sectors

AI Security Gateway was designed by Neveratech, which builds software in sectors where data is at its most sensitive — healthcare among them. We run the modernisation of a clinical platform used in roughly a hundred hospitals, on an on-premise architecture where data never leaves the institution. “On-premise deployment” is not a checkbox for us; it is the model we work in every day.

Advisory

If you do not yet know where you stand

Not every organisation needs software first. Some need a clear answer to one question: who here uses which tool, with what data?

The AI Usage Assessment answers exactly that. It produces your usage inventory, maps where data is going, assesses in technical terms whether the EU AI Act applies to you, and leaves you a draft internal usage policy.

You end up with a roadmap: what to fix with process and what to fix with software. If you do not need the gateway, we will say so.

  • Usage inventory — who, which tool, what data
  • Transfer map — where data goes, and the GDPR Chapter V position
  • EU AI Act scoping — technical assessment
  • Policy and training — draft usage policy, staff briefing
  • Roadmap — what to solve with process, what with software

We build the technical and organisational side. Legal opinions, registrations and sign-off on legal texts sit with the legal side we work alongside.

FAQ

Frequently asked.

Do we have to ban the tools our staff use?
No. Bans mostly fail — the usage does not stop, it just becomes invisible. The gateway exists so that use can continue while being visible and recorded.
How long does deployment take?
Pointing the address your applications already call at the gateway is enough. No rewrite on the application side.
Will responses get slower?
The gateway is a layer in the path, so it adds time per request. What that comes to in your setup is something we can measure together on the call.
Does our data sit on your servers?
With the on-premise deployment, no — nothing leaves your organisation. In the hosted deployment personal data is already masked before a request leaves, and raw content does not accumulate.
Which AI tools does it work with?
The gateway sits between your applications and the service. Tell us on the call which tools are in use and we will confirm the fit together.
Will these logs be enough in an audit?
The logs produce the trail you need to evidence your processing activity. How that trail is assessed and presented is a legal question; we supply the infrastructure and the document.
We are a small team — is this for us?
The nature of the data matters more than headcount. If you handle customer records, health data or contracts, the obligation does not scale with team size.
Can we take the advisory work without the product?
Yes. The AI Usage Assessment is a scoped, standalone engagement. If it turns out you do not need the gateway, we will tell you.
Is this legal advice?
No. We build the technical and organisational side: inventory, transfer map, technical mechanisms, draft policy, training. Legal opinions and sign-off sit with the legal side.

Contact

Fifteen minutes is enough.

We do not need access to your systems — we will show you the product live, then talk about what it means in your setup.

You decide what the call is about: seeing the product, or working out where to start.

Book a call

or write directly to [email protected]