Swfte Connect / Security

Securing the gateway every prompt passes through

An LLM gateway holds provider keys and sees every prompt. Connect is built on that assumption: keys are guarded, access is scoped, content can be filtered, spend is capped and actions are recorded.

The threat model for a gateway

A gateway concentrates risk, so it deserves its own review. It holds credentials for many providers. It sees prompts that may contain customer data, source code or secrets. It decides which model, and therefore which third party, receives each request. And it can be abused, by a leaked key or a runaway loop, to spend money quickly.

The controls below answer those four risks in order: credential theft, data exposure, wrong-destination routing and cost abuse. A fifth section covers how you can see what happened afterwards.

Credential custody

Provider keys are the most valuable thing the gateway holds.

  • Encrypted storage. A workspace's own provider keys are kept in a secrets manager, not in application configuration or the browser.
  • Decrypted at call time. The key is decrypted when a request needs it and cached only briefly.
  • Never sent to the client. Applications authenticate to Connect with their own API keys; they never receive provider keys.
  • Order of use. A workspace's key is used first, then platform access, so a customer's key is never silently replaced.
  • Your boundary. In a self-deployed Connect, keys live in your own secret store and are used from your network.

Identity and access

Every gateway call is authenticated and tied to a workspace. Reading audit data requires an explicit workspace read permission. Permissions are scoped to the workspace so one team's activity and credentials are not another's. For self-deployed environments, the license model includes single sign-on, and audit logging is a licensed capability as well. These controls are part of the Identity and Access facets of the Trust and Governance Fabric that runs through the platform.

Policy on prompt content

Guardrails answer "should this be blocked?". Connect applies them at the point every request passes.

Content policies evaluate a request body against rules. Built-in detectors cover common secrets, including cloud access keys, repository tokens, private-key blocks, signed tokens and API keys, and common personal-data patterns such as email addresses, phone numbers and identifier formats. You can add your own patterns. A matching rule can redact the content, replacing it with a placeholder, before the request is forwarded, and can raise an alert.

Pattern-based detection is a safety net, not a guarantee. It will not catch every sensitive value, and it does not replace deciding which data a workload may send at all. Treat it as one layer alongside provider choice and, for sensitive workloads, self-hosted models.

Limits and cost abuse

  • Rate limits. A per-workspace limit on concurrent requests prevents one client from exhausting the gateway or a provider.
  • Usage caps. Daily token and monthly spend caps, per workspace or per model.
  • Automatic downgrade. When a cap is reached the gateway can switch to a cheaper model instead of failing the request.
  • Alerts. Email and webhook notifications when thresholds are crossed.

Audit and traceability

Usage is metered per workspace, and action audit events are recorded and readable through an authenticated API. Together with the per-model analytics in the Connect dashboard, they let a reviewer reconstruct who called which model, when and at what cost. For the chain from data to model to agent to action, see the AI audit trail guidance on the SecOps pages.

Transport, storage and isolation

API traffic uses TLS 1.2 or later, with TLS 1.3 preferred. Databases are encrypted and object storage is encrypted. Customer data in the managed service is stored in AWS eu-west-1 (Ireland). Where isolation is the requirement, a self-deployed Connect runs inside your network, and the dedicated cloud provides private capacity run for you.

Assurance and honest limits

Swfte does not hold a SOC 2 report or an ISO 27001 certificate and does not sign HIPAA Business Associate Agreements today. A SOC 2 Type I audit is in preparation; the trust page has the current status. The trust centre is the source of record and lists anything still in progress.

  • Zero-data-retention agreements with model providers are in progress. A provider you route to processes requests under its own terms.
  • Customer-managed encryption keys are designed for dedicated deployments and are not generally available today.
  • This page describes controls, and makes no uptime or latency commitment.
  • Swfte does not claim end-to-end encryption of prompts. The gateway must read a request to route it.

Swfte provides the technical controls, governance mechanisms and evidence required to deploy AI within an organization's applicable regulatory, security and policy requirements. The exact posture depends on the customer's use case, jurisdiction, deployment and configuration.

Frequently asked questions

Where are my provider API keys stored?

In a secrets manager, encrypted. They are decrypted when a request needs them, cached briefly, and never sent to the client. In a self-deployed Connect they live in your own secret store.

Can the gateway see my prompts?

Yes. A gateway has to read a request to route and meter it. That is why the controls focus on key custody, access, redaction, limits and audit, and why sensitive workloads can run on a self-deployed gateway with self-hosted models.

Can sensitive data be removed from prompts automatically?

Content policies can detect common secrets and personal-data patterns and redact them before dispatch. Detection is pattern-based and is one layer, not a guarantee.

How do I limit spend through the gateway?

Set daily token and monthly spend caps per workspace or per model, with email or webhook alerts. A cap can trigger an automatic downgrade to a cheaper model.

What security assurance does Swfte have today?

No SOC 2 report, ISO 27001 certificate or HIPAA BAA exists today. A SOC 2 Type I audit is in preparation, and the trust centre lists what is in place and what is in progress.

Connect in the platform

Route every model through one governed gateway

Start managed in minutes, or plan a deployment inside your own boundary with the team.

Automate the response with SecOps Agents

Autonomous security orchestration: triage, investigation and containment, with a full audit trail.