Keera Gateway
One endpoint for every model in the company
Between your teams and every LLM sits one base URL: Keera's models, your own fine-tunes and external providers where the policy allows it. Policies, budgets and audit in one place.
How it works
Everything that calls a model points at the same address. The gateway checks each request, writes it to the log and passes it on.
Your tools
- Coding agent in the terminal and the IDE
- Internal apps and copilots
- Notebooks and CI jobs
Keera Gateway
- Identity and team from your IdP
- Check policy, quota and budget
- Redact secrets and personal data
- Route to the model that is allowed
Models
- Keera Deep, Swiss and Fast in Switzerland
- Your fine-tunes and on-prem clusters
- External providers, opened by policy
↓ Every request into the audit log and your SIEM
OpenAI-compatible: existing SDKs and agents switch with one environment variable.
Four things it controls
One endpoint that belongs to you - and four decisions it makes on every single request.
The end of shadow AI
Block direct egress at the proxy and every AI request in the company becomes visible.
A policy per team
Which models, repos and data classes are reachable is written as a versioned policy - enforced on every request.
Cost you can attribute
Spend by team, repo and cost centre, with hard budget limits and an alert before the invoice.
Audit and redaction
Secrets and personal data drop out at the edge. Prompt, model, decision and identity stream immutably into your SIEM.
Web UI or CLI, the same control
You administer the gateway from a web UI that hides nothing: policies, budgets, teams, models and every single session are a few clicks away. If you would rather type or automate, take the keera CLI - same reach, scriptable, ready for your pipeline. Both write the same versioned policy: what you click in the browser is what the CLI reads, and the other way round.
And because every request goes through the same endpoint, you see for the first time what your company really does with LLMs: tokens, cost and refused requests per team, model and period - in the browser or as CSV for your own reporting.
Features
The gateway is more than a proxy. Here are some of its powerful features - each of them in the web UI and in the CLI.
Guardrails
Allowed models, rate limits and budgets - per organisation, team and key. Versioned, checked on every request, refused when in doubt.
Smart Filters
A small model reads every request and takes out secrets, client names and personal data - or stops it. Measure in shadow mode first, then enforce.
Smart Routers
A small model picks which model answers: the fast local one for short edits, the large one only when the task needs it.
Live map
Clients, gateway and models as a picture, with one line across it: above it stays on your own network, below it leaves the building. Requests cross it live.
Sessions
One instruction to the coding agent is forty calls. Cost, duration and outcome are shown per task - the number you can actually talk about.
SSO and roles
Sign-in against your own identity provider, permissions from your directory groups. Every change goes into the audit log.
Try Keera
We onboard one team, connect it to your repos and hand you the numbers. After 30 days you decide.