Govern AI traffic
Reign Gateway gives applications and agents a governed path to approved models and tools. For each call routed through it, Gateway checks identity and access, applies policy and spend limits, and creates an evidence record showing the caller, policy decision, destination, outcome, time and cost, subject to approved capture settings.
What you gain.
Bring AI traffic under control while keeping the clients and tools your teams already use.
Less application change
Point applications and agents at one governed endpoint and keep the supported client libraries your teams already use.
Central control
Apply route permissions, guard rails and other policy at the Gateway boundary, with changes taking effect centrally.
Evidence for operations and oversight
Create an evidence record for each governed call: who called, what policy decided, which destination was reached and what the call cost, subject to approved capture and retention settings. Use it for oversight and troubleshooting.
Spend control
Enforce token and spend limits per minute, hour and day, by tenant and route.
One governed path for model and tool traffic.
Applications and agents send requests to one endpoint. Gateway checks identity and credentials, applies budget and guard-rail rules, translates permitted requests for the approved upstream service, and returns the response to the caller.
The customer’s security and engineering functions define approved models, tools, identities and policy. iTmethods operates Gateway and its change process.
Identity for people and automated workflows.
Operator identity
Operator sign-in federates to the customer’s existing identity provider using OpenID Connect over OAuth 2.0, so access can follow the customer’s identity lifecycle.
Workload identity
Applications and agents use OAuth client credentials to obtain expiring access tokens. Access is scoped to permitted routes, checked on every request and centrally revocable.
Least-privilege tool access
MCP tools must be explicitly enabled and authorized for the calling identity before an agent can use them.
Use each evidence record to govern, troubleshoot and optimize.
Each call routed through Gateway creates an evidence record showing the caller, route, policy decision, destination, outcome, time and cost, subject to approved capture settings. Teams can use it to explain decisions, inform model and application choices, tune policy and spend, and investigate reliability and performance.
Explain each call
See who called, which route was used, what policy decided, which destination was reached and what the call cost, subject to approved capture settings.
Inform model and application choices
Use usage, cost and operational signals to inform model selection, application design and policy tuning.
Investigate the call path
Use traces, metrics and logs to identify reliability, performance and infrastructure issues across the governed path.
Keep evidence in your systems
Gateway writes evidence records to configured customer-controlled S3-compatible storage under the customer’s retention and access settings.
Supported interfaces and familiar infrastructure.
Model API compatibility
OpenAI-compatible and Anthropic-compatible model APIs.
Protocols
MCP; OpenID Connect and OAuth 2.0; OpenTelemetry using OTLP.
Infrastructure
Kubernetes; S3-compatible object storage.
iTmethods holds a SOC 2 Type II attestation for Reign Ops. The report, scope and period are available under non-disclosure.
Specific control and regulatory mappings for a deployment are established jointly with the customer’s compliance function and counsel. The mappings support the customer’s own control-design assessment; they are not certifications or conformance determinations.
Bring one model or agent path.
We can show how Gateway would apply policy to one traffic path and create an evidence record your teams can use.