Features
Switch on what you need. Leave the rest off.
The gateway
Always on. The part every customer gets by default.
Drop-in proxy
Change the base URL. Point your existing provider SDK at the CattleGrid endpoint. No application rewrite, no endpoint agent, no rebuild.
Credential swap
Your app never holds the secret. CattleGrid substitutes the upstream provider credential, so the provider key never sits in your application.
Providers
Four, plus anything compatible. OpenAI, Anthropic, Google Gemini and Mistral from the catalogue, and any provider exposing a standard OpenAI-compatible API. Bring your own keys, or use a subscription where the vendor permits it.
Keys and limits
Scoped tightly. Managed keys, hashed and never stored in plain text, with per-key scopes, allowed providers, rate-limit tier, CORS allowlist and IP allowlist.
Streaming
No buffering. Server-sent events pipe straight back to your application at full speed.
Zero retention
On this path, nothing is kept. Prompt content is never written to disk. Usage is metered asynchronously, without blocking the response.
Named capabilities
Each of these has a page of its own.
Anonymise / De-anonymise
Send the meaning, keep the identity. Reversible tokenisation with no persistent key, rule packs for UK PII, financial, legal, secrets and Salesforce, and document inspection across PDF, Word, Excel, OpenDocument and RTF. See the Anonymise page.
Desktop
A workspace, not just a proxy. AI chat, direct messages, team chat and shared projects for Windows, macOS and Linux, with encrypted local storage and three encryption modes. Included in every tier. See the Desktop page.
Audit, Taint & Compliance
Evidence, not assurances. Hash-chained records with Ed25519 seals and external time anchoring, taint governance for agent tool calls, and a compliance-officer role with review and freeze. See the Audit page.
Detection
What the platform recognises, and how it is kept honest.
Engines
Four working together. A rule-pack engine, context-aware regex packs, and a static non-AI engine for environments that require determinism. Detection is deterministic by design: what a rule catches today, it catches tomorrow.
Authoring
Write your own. Create, version, lint and publish rule packs. Test them on the rule bench and run them in preview mode before they touch live traffic.
Beyond plain patterns
Evasion is assumed. Pre-encoded payload detection, side-channel inspection, cross-request fragmentation detection, response-side inspection and multimodal content inspection.
Fail-closed
Safe by default. Where detection cannot complete, the request does not proceed. Capability parity across packs means a gap in one is not a gap in all.
Beyond the gateway
The parts that matter once AI stops being a single API call.
MCP Hub
Govern the tools. A per-tenant namespaced tool registry with role-based access, an approval workflow that makes unapproved tools non-invocable, and a credential vault that never holds plain text. Connect Claude Desktop, Cursor, VS Code and ChatGPT.
Context Engine
Provider-agnostic conversations. A canonical thread with one adapter per provider, so switching provider is a configuration change. Persistence, prompt caching, memory, compaction and context-scoped keys — encrypted and retention-policied under your controls.
Agent Skills
One skill, four providers. Built on the open SKILL.md standard and running unmodified across Anthropic, OpenAI, Gemini and Mistral. Scripts execute in a CattleGrid sandbox; only inference goes to the provider.
Collaboration
AI as a participant, not the default. AI chat, direct messages and team chat as three separate surfaces, with shared chats, projects and real-time delivery enforced by row-level security.
Running it
The administrative surface, for the people who have to answer for all this.
Access
SSO and SCIM. Enterprise single sign-on via Azure AD, Okta, Google Workspace, SAML and OIDC, with group-to-role mappings and SCIM provisioning. MFA enforcement and ownership transfer included.
Fleet
Desktop at scale. Session oversight and revocation, policy-aware update approval, bulk CSV invitations, onboarding configuration and encryption-mode selection.
Analytics
What is actually happening. Usage dashboards with real-time KPIs, metric filtering, CSV export and a per-user Rules Triggered feed.
API management
Governed access. Managed keys, usage dashboards, an audit log, and OpenAPI 3.0 documentation with REST and GraphQL surfaces generated from schema. TypeScript, Python and Go SDKs.
Integrations
Where your team already is. Slack notifications, detection summaries and threshold alerts, SIEM forwarding on the OCSF schema, GRC platform integrations and signed alert webhooks.
Billing
Volume, not seats. Usage metered against gateway throughput and A/D consumption, with a self-service billing portal. Adding people does not add cost.
Not sure what you need?
Most organisations start with the gateway, the GDPR pack and the desktop client, then add capabilities as their exposure becomes clearer. Talk to us and we will scope it against what you actually do, rather than selling you the whole list.