Skip to main content
    ProductsReign Gateway

    Govern AI traffic

    Reign Gateway gives applications and agents a governed path to approved models and tools. For each call routed through it, Gateway checks identity and access, applies policy and spend limits, and creates an evidence record showing the caller, policy decision, destination, outcome, time and cost, subject to approved capture settings.

    The boundary every call
    Inside the Gateway deployment Coding agents Applications Agents you wrote One endpoint whoever built the agent Policy decides identity · budget · guard rails Routing decides which permitted model answers an evidence record per call, linked in sequence out models listed by your policy Evidence is written to configured S3-compatible storage you control
    The endpoint, policy and evidence record stay inside the dedicated Gateway deployment. Calls permitted by your policy reach an approved model or tool.
    Benefits

    What you gain.

    Bring AI traffic under control while keeping the clients and tools your teams already use.

    Less application change

    Point applications and agents at one governed endpoint and keep the supported client libraries your teams already use.

    Central control

    Apply route permissions, guard rails and other policy at the Gateway boundary, with changes taking effect centrally.

    Evidence for operations and oversight

    Create an evidence record for each governed call: who called, what policy decided, which destination was reached and what the call cost, subject to approved capture and retention settings. Use it for oversight and troubleshooting.

    Spend control

    Enforce token and spend limits per minute, hour and day, by tenant and route.

    How a model or tool request is handled

    One governed path for model and tool traffic.

    Applications and agents send requests to one endpoint. Gateway checks identity and credentials, applies budget and guard-rail rules, translates permitted requests for the approved upstream service, and returns the response to the caller.

    The customer’s security and engineering functions define approved models, tools, identities and policy. iTmethods operates Gateway and its change process.

    Reign Gateway · one endpoint, operated for you
    Approved upstream · response to your estate
    One endpoint
    Applications and agents send requests to the shared boundary.
    Identity and policy
    Identity, credentials, budget and guard rails are checked before the upstream call.
    Translation
    The permitted request is translated for the approved upstream service.
    Approved model or tool
    The request reaches a provider or MCP tool server listed by policy.
    Response
    The response returns to the application or agent that sent the request.
    Evidence record For each call routed through it, Gateway records the caller, policy decision, destination, outcome, time and cost, subject to approved capture settings.
    Customer guard rails Gateway can use a customer content-safety or policy service when it is registered and deliberately enabled.
    Central policy changes Gateway applies approved policy changes during operation, following the same review process.
    Identity and authorization

    Identity for people and automated workflows.

    Operator identity

    Operator sign-in federates to the customer’s existing identity provider using OpenID Connect over OAuth 2.0, so access can follow the customer’s identity lifecycle.

    Workload identity

    Applications and agents use OAuth client credentials to obtain expiring access tokens. Access is scoped to permitted routes, checked on every request and centrally revocable.

    Least-privilege tool access

    MCP tools must be explicitly enabled and authorized for the calling identity before an agent can use them.

    Evidence records

    Use each evidence record to govern, troubleshoot and optimize.

    Each call routed through Gateway creates an evidence record showing the caller, route, policy decision, destination, outcome, time and cost, subject to approved capture settings. Teams can use it to explain decisions, inform model and application choices, tune policy and spend, and investigate reliability and performance.

    Explain each call

    See who called, which route was used, what policy decided, which destination was reached and what the call cost, subject to approved capture settings.

    Inform model and application choices

    Use usage, cost and operational signals to inform model selection, application design and policy tuning.

    Investigate the call path

    Use traces, metrics and logs to identify reliability, performance and infrastructure issues across the governed path.

    Keep evidence in your systems

    Gateway writes evidence records to configured customer-controlled S3-compatible storage under the customer’s retention and access settings.

    Evidence integrity and content capture
    How the archive is checked
    Evidence records are hash-linked in sequence, so changes to that sequence can be detected against the committed tree. When signing is configured, a signed tree head lets a reviewer check the exported archive’s recorded sequence. This is an archive-level seal: the verifier does not yet recompute each record’s hash from its stored content, so it does not establish that every stored record still matches its original content.
    Capture and retention settings
    The customer chooses the content Gateway captures and sets retention in customer-controlled S3-compatible storage. Object lock provides write-once retention when configured.
    Interfaces and trust

    Supported interfaces and familiar infrastructure.

    Model API compatibility

    OpenAI-compatible and Anthropic-compatible model APIs.

    Protocols

    MCP; OpenID Connect and OAuth 2.0; OpenTelemetry using OTLP.

    Infrastructure

    Kubernetes; S3-compatible object storage.

    What iTmethods holds

    iTmethods holds a SOC 2 Type II attestation for Reign Ops. The report, scope and period are available under non-disclosure.

    Engagement-specific framework mapping

    Specific control and regulatory mappings for a deployment are established jointly with the customer’s compliance function and counsel. The mappings support the customer’s own control-design assessment; they are not certifications or conformance determinations.

    Next step

    Bring one model or agent path.

    We can show how Gateway would apply policy to one traffic path and create an evidence record your teams can use.