Sentry · In-line Governance

The proxy that stands between your AI and every prompt.

Sentry terminates model traffic, evaluates every request against your policies, and brokers it to the right provider — with a signed audit trail on every decision.

+6ms
p95 hot-path overhead
SentryDSL
Rego-inspired policy language
<15s
policy rollout across 1,000 pods
100%
signed, reproducible bundles
Live Playground
Gateway will screen the request against all enabled policies.
Gateway

Go-based in-line proxy. Native HTTP/2 + gRPC. Fails open or closed per tenant policy.

SentryDSL

Author policies in a simple, Rego-inspired DSL. Compiled to bytecode. Content-addressable.

Reproducibility

Every decision links to a policy bundle. Replay any decision at any time.

SentryDSL — example
match: /\b\d{3}-\d{2}-\d{4}\b/
action: deny
reason: "US SSN detected — HIPAA §164.514"

match: /[a-z0-9._%+-]+@[a-z0-9.-]+\.[a-z]{2,}/i
action: redact
reason: "Email redacted — GDPR Art. 5"

match: /ignore (previous|all) instructions/i
action: deny
reason: "Prompt injection guard"
Bytecode-compiled Content-addressable Signed with SHA-256