Product / Secure
IRIS8 Secure

See every AI interaction. Stop what shouldn’t leave.

One drop-in gateway endpoint makes your whole AI estate visible — every model, agent, tool, team, and dollar — and puts a safety net under how your people actually use AI: masking sensitive data, blocking prompt injection, and flagging risky flows, all inline.

Available nowSelf-servePowered by the AI Gateway
app.iris8.ai/secure/live
mask: AWS secret keydev-tools · j.chenMasked
mask: customer SSN ···-··-4417support-copilotMasked
block: prompt injection (multi-turn)inbound email agentBlocked
discovered: cursor-agent · 14 seatsengineeringShadow
alert: source file → external toolengineeringAlerted
5 min

median time from signup to first visibility

100%

coverage of traffic through the gateway

50+

data classes detected and masked inline

<100 ms

security checks on the request path

The problem

You can’t secure the AI you can’t see — and the riskiest AI is the AI people actually use.

Unknown estate

Teams adopt models, agents, and AI tools faster than any registry can track — 60% of enterprise AI is undocumented shadow AI.

Paste-and-pray

Customer records, source code, and credentials flow into AI tools every day — invisible until the breach notification.

Injected instructions

Attackers don’t hack your agents; they talk to them. Indirect injection through email, documents, and tool results is the new phishing.

Capabilities in depth

From first request to full protection.

The gateway

One gateway, total coverage

Swap a base URL and keep your code. The gateway speaks the APIs your teams already use — and everything that flows through it becomes visible, secured, and governable.

  • OpenAI-compatible endpoint; drop-in for existing clients
  • Plugins for LiteLLM, Portkey, Kong, and Azure APIM
  • SDK hooks for LangGraph, CrewAI, AutoGen, and MCP
  • Sub-100ms passthrough — invisible to users
quickstart — 5 minutes
// point your existing client at the gateway
client = OpenAI(
  base_url="https://gw.iris8.ai/v1",
  api_key=env("IRIS8_KEY")
)
// done. every call is now visible, secured, and provable.
Visibility

A living inventory, not a stale spreadsheet

Every model, agent, tool, and MCP connection registers itself from real traffic — shadow systems flagged the moment they touch the gateway, with usage, latency, and spend by team, project, model, and provider.

  • Auto-registration on first request; shadow AI discovered live
  • Lifecycle states, ownership, and autonomy tiers attached automatically
  • Spend and token analytics with provider mix
  • Anomaly flags when usage patterns shift
app.iris8.ai/secure/estate
143AI systems
27shadow
$48.2Kspend / mo
commercial-underwriting-v3frontier-lm-7 · lendingActive
support-copilotgpt-class · contact centerActive
unregistered: cursor-agentengineering · 14 seatsShadow
DLP

Sensitive data stops at the gateway

PII, secrets, API keys, source code, and customer records are detected and masked inline — before they leave your perimeter for any model or AI tool.

  • 50+ built-in data classes plus custom patterns
  • Mask, block, transform, or alert — per team and data class
  • Format-preserving masking that doesn’t break tools
  • Every detection filed as evidence automatically
app.iris8.ai/secure/live
mask: AWS secret keydev-tools · j.chenMasked
mask: customer SSN ···-··-4417support-copilotMasked
block: prompt injection (multi-turn)inbound email agentBlocked
alert: source file → external toolengineeringAlerted
mask: API bearer tokenqa-automationMasked
Injection defense

Attacks caught mid-conversation

Multi-turn attack detection on every interaction — including poisoned tool results, malicious retrieved content, and indirect injection through MCP connections.

  • Multi-turn patterns: the jailbreak that fails once and succeeds on the third try
  • Poisoned tool-result and retrieved-content inspection
  • MCP and agent-to-agent traffic covered
  • Findings streamed to your SIEM as OCSF
app.iris8.ai/secure/dev-insight
212AI-active devs
38%AI-assisted PRs
12risky flows
cursor + internal repoplatform teamPolicy OK
chat paste: config w/ secretspayments teamMasked
codegen on regulated modulelending engReview
Developer insight

See how engineering really uses AI

Prompt patterns, AI-assisted coding flows, tool adoption, and productivity signals — derived from gateway traffic, not from surveilling anyone’s editor.

  • Adoption and usage metrics by team and tool
  • Risky flows flagged: secrets in prompts, regulated code paths
  • Productivity signals without screenshots or spyware
  • Exportable reporting for engineering leadership
app.iris8.ai/secure/dev-insight
212AI-active devs
38%AI-assisted PRs
12risky flows
cursor + internal repoplatform teamPolicy OK
chat paste: config w/ secretspayments teamMasked
codegen on regulated modulelending engReview
Everything included

See it all. Let people use AI. Stop what shouldn’t leave.

Gateway

One drop-in endpoint

Swap your base URL, keep your code. The gateway speaks the APIs your teams already use, with SDK hooks for LangGraph, CrewAI, AutoGen, and MCP — or runs as a plugin behind LiteLLM, Portkey, Kong, and Azure APIM.

Inventory

A live estate map

Models, agents, tools, and MCP connections inventoried automatically from real traffic — with shadow AI surfaced by team, by app, and by data sensitivity, the moment it touches the gateway.

Analytics

Usage & spend analytics

Requests, tokens, latency, and cost by team, project, model, and provider — live dashboards, scheduled reports, export anywhere.

DLP

Sensitive-data leak prevention

PII, secrets, API keys, source code, and customer records detected and masked inline — before they leave your perimeter for a model or an AI tool.

Injection

Prompt-injection & jailbreak defense

Multi-turn attack detection on every interaction — including poisoned tool results and indirect injection through retrieved content and MCP connections. Findings stream to your SIEM as OCSF.

Dev insight

Developer AI insight

See how engineering actually uses AI — prompt patterns, AI-assisted coding flows, tool adoption, and productivity signals — from gateway traffic, not from surveilling anyone's editor.

How it works

Visibility and protection in three steps.

  1. Point your traffic at the gateway. Five-minute setup, free tier, no procurement meeting. The estate lights up and detection starts with sensible defaults.
  2. Tune your policies. Pick data classes, sensitivity levels, and per-team rules — alert-only first if you prefer, then enforce.
  3. Invite security and risk. Hand your SOC live findings in their SIEM and your risk team a live estate map instead of a stale spreadsheet. They’ll thank you.
Questions

The short answers.

Do we have to replace our existing gateway?

No. IRIS8 runs as a drop-in endpoint or as a plugin behind LiteLLM, Portkey, Kong, or Azure APIM — whichever path is least disruptive.

Does this slow down requests?

Visibility is passive and security checks run inline in a sub-100ms budget at p95. Your users won’t notice; your dashboards will.

Can we start in alert-only mode?

Yes. Most teams run a week of alert-only to tune policies, then flip to enforce per data class and team. Masking is format-preserving, so downstream tools keep working.

Your whole estate visible — and nothing leaking — by Friday.

Free to start. No sales call required.

Start free