Keera Gateway
One endpoint for every model in the company
Between your teams and every LLM sits one base URL: Keera's models, your own fine-tunes and external providers where the policy allows it. Policies, budgets and audit in one place.
How it works
Everything that calls a model points at the same address. The gateway checks each request, writes it to the log and passes it on.
Your tools
- Coding agent in the terminal and the IDE
- Internal apps and copilots
- Notebooks and CI jobs
Keera Gateway
- Identity and team from your IdP
- Check policy, quota and budget
- Redact secrets and personal data
- Route to the model that is allowed
Models
- Open models on Keera Engine in Switzerland
- Your fine-tunes and on-prem clusters
- External providers, opened by policy
Every request into the audit log and your SIEM
OpenAI- and Anthropic-compatible: existing SDKs and agents switch with one environment variable.
Four things it controls
One endpoint that belongs to you - and four decisions it makes on every single request.
The end of shadow AI
Block direct egress at the proxy and every AI request in the company becomes visible.
A policy per team
Which models and data classes a team or an API key can reach is written as a versioned policy - enforced on every request.
Cost you can attribute
Spend by team, API key and cost centre, with hard budget limits and an alert before the invoice.
Audit and redaction
Secrets and personal data drop out at the edge. Who, which model, how many tokens and which decision stream immutably into your SIEM - the prompt itself does not.
Web UI or CLI, the same control
You administer the gateway from a web UI that hides nothing: policies, budgets, teams, models and every single session are a few clicks away. If you would rather type or automate, take the keera CLI - same reach, scriptable, ready for your pipeline. Both write the same versioned policy: what you click in the browser is what the CLI reads, and the other way round.
And because every request goes through the same endpoint, you see for the first time what your company really does with LLMs. The live map draws a line where a request leaves your network and shows how many tokens and francs end up outside. Tokens, cost and refused requests per team, model and period are there in the browser or as CSV for your own reporting.
Features
The gateway is more than a proxy. Here are some of its powerful features - each of them in the web UI and in the CLI.
Guardrails
Allowed models, rate limits and budgets - per organisation, team and key. Versioned, checked on every request, refused when in doubt.
Smart Filters
A small model reads every request and takes out secrets, client names and personal data - or stops it. Measure in shadow mode first, then enforce.
Smart Routers
A small model picks which model answers: the fast local one for short edits, the large one only when the task needs it.
Live map
Clients, gateway and models as a picture, with one line across it: above it stays on your own network, below it leaves the building. Requests cross it live.
Agent Sandboxes
The gateway offers coding agents isolated containers - as a development environment, or for a CI pipeline. Inside, they reach only what they really need.
SSO and roles
Sign-in against your own identity provider, permissions from your directory groups. Every change goes into the audit log.
Common questions
What teams ask us most before they set the gateway up.
Do you store my prompts?
No. Neither the prompt nor the model's answer is stored - the content passes through and is then gone. What is kept is the request itself: who, when, which model, how many tokens, which decision. That is what gives you cost per team and an audit trail, and the log sits in your infrastructure.
Does it make us more secure?
Yes, mostly through the keys. The API keys for every model sit in one place instead of scattered across .env files, CI secrets and laptops. You grant them per team and revoke them in one place. Your applications never see the real key.
Does it help me with the EU AI Act?
Yes. The AI Act asks you to show what your company does with AI. The gateway logs every request with identity, model and decision, and shows you usage and cost per team. The evidence is there when somebody asks. The compliance work stays yours.
How is it different from other AI gateways?
Others route requests too, and as open source that costs nothing. Three things do not come with them. We run the gateway in Swiss data centres, you get enterprise support directly from us with someone to talk to in Switzerland, and the Keera models sit behind it from day one. None of that needs a special client or a library of its own: your tools keep speaking the APIs they already speak, and you change one base URL. That keeps you independent - of us as well. You can read the source code on GitHub.
Does Claude Code work with it?
Yes. The gateway speaks the OpenAI and the Anthropic API. Claude Code, your own agent, an internal app or a notebook point at the gateway's base URL and carry on as before.
Does it add latency?
Very little. The path through policy, budget and log costs microseconds - next to a model answer that takes seconds, nobody notices. Only Smart Filters and Smart Routers add a small model call, and you switch those on yourself.
Is it lightweight?
Yes. It uses very little memory and it is fast. No heavy runtime, no farm of services in front of it - you put it next to your applications without building a platform for it.
Is it cloud native?
Yes, cloud and Kubernetes are its home. It runs as a container, scales horizontally and takes its configuration from the cluster. In your cloud, in your cluster or in your own data centre it is the same software.
Try Keera
We put one team on the gateway and show you which models it uses and what that costs. After 30 days you decide.