CattleGrid

Features

Switch on what you need. Leave the rest off.

The whole platform, and how much of it is up to you.

CattleGrid is not a single product with a single switch. Features are enabled per account, because the right configuration for a two-partner practice is not the right configuration for a bank. What follows is everything the platform does. Nothing here runs unless you turn it on.

The gateway

Always on. The part every customer gets by default.

Drop-in proxy

Change the base URL. Point your existing provider SDK at the CattleGrid endpoint. No application rewrite, no endpoint agent, no rebuild.

Credential swap

Your app never holds the secret. CattleGrid substitutes the upstream provider credential, so the provider key never sits in your application.

Providers

Four, plus anything compatible. OpenAI, Anthropic, Google Gemini and Mistral from the catalogue, and any provider exposing a standard OpenAI-compatible API. Bring your own keys, or use a subscription where the vendor permits it.

Keys and limits

Scoped tightly. Managed keys, hashed and never stored in plain text, with per-key scopes, allowed providers, rate-limit tier, CORS allowlist and IP allowlist.

Streaming

No buffering. Server-sent events pipe straight back to your application at full speed.

Zero retention

On this path, nothing is kept. Prompt content is never written to disk. Usage is metered asynchronously, without blocking the response.

Named capabilities

Each of these has a page of its own.

Anonymise / De-anonymise

Send the meaning, keep the identity. Reversible tokenisation with no persistent key, rule packs for UK PII, financial, legal, secrets and Salesforce, and document inspection across PDF, Word, Excel, OpenDocument and RTF. See the Anonymise page.

Desktop

A workspace, not just a proxy. AI chat, direct messages, team chat and shared projects for Windows, macOS and Linux, with encrypted local storage and three encryption modes. Included in every tier. See the Desktop page.

Audit, Taint & Compliance

Evidence, not assurances. Hash-chained records with Ed25519 seals and external time anchoring, taint governance for agent tool calls, and a compliance-officer role with review and freeze. See the Audit page.

Detection

What the platform recognises, and how it is kept honest.

Engines

Four working together. A rule-pack engine, context-aware regex packs, and a static non-AI engine for environments that require determinism. Detection is deterministic by design: what a rule catches today, it catches tomorrow.

Authoring

Write your own. Create, version, lint and publish rule packs. Test them on the rule bench and run them in preview mode before they touch live traffic.

Beyond plain patterns

Evasion is assumed. Pre-encoded payload detection, side-channel inspection, cross-request fragmentation detection, response-side inspection and multimodal content inspection.

Fail-closed

Safe by default. Where detection cannot complete, the request does not proceed. Capability parity across packs means a gap in one is not a gap in all.

Beyond the gateway

The parts that matter once AI stops being a single API call.

MCP Hub

Govern the tools. A per-tenant namespaced tool registry with role-based access, an approval workflow that makes unapproved tools non-invocable, and a credential vault that never holds plain text. Connect Claude Desktop, Cursor, VS Code and ChatGPT.

Context Engine

Provider-agnostic conversations. A canonical thread with one adapter per provider, so switching provider is a configuration change. Persistence, prompt caching, memory, compaction and context-scoped keys — encrypted and retention-policied under your controls.

Agent Skills

One skill, four providers. Built on the open SKILL.md standard and running unmodified across Anthropic, OpenAI, Gemini and Mistral. Scripts execute in a CattleGrid sandbox; only inference goes to the provider.

Collaboration

AI as a participant, not the default. AI chat, direct messages and team chat as three separate surfaces, with shared chats, projects and real-time delivery enforced by row-level security.

Running it

The administrative surface, for the people who have to answer for all this.

Access

SSO and SCIM. Enterprise single sign-on via Azure AD, Okta, Google Workspace, SAML and OIDC, with group-to-role mappings and SCIM provisioning. MFA enforcement and ownership transfer included.

Fleet

Desktop at scale. Session oversight and revocation, policy-aware update approval, bulk CSV invitations, onboarding configuration and encryption-mode selection.

Analytics

What is actually happening. Usage dashboards with real-time KPIs, metric filtering, CSV export and a per-user Rules Triggered feed.

API management

Governed access. Managed keys, usage dashboards, an audit log, and OpenAPI 3.0 documentation with REST and GraphQL surfaces generated from schema. TypeScript, Python and Go SDKs.

Integrations

Where your team already is. Slack notifications, detection summaries and threshold alerts, SIEM forwarding on the OCSF schema, GRC platform integrations and signed alert webhooks.

Billing

Volume, not seats. Usage metered against gateway throughput and A/D consumption, with a self-service billing portal. Adding people does not add cost.

Not sure what you need?

Most organisations start with the gateway, the GDPR pack and the desktop client, then add capabilities as their exposure becomes clearer. Talk to us and we will scope it against what you actually do, rather than selling you the whole list.