Your AI rules,on every prompt and every answer.

Noozle Gate checks prompts, answers and agent tool calls against policies your team can read, test and version. Keep sensitive data within approved boundaries and apply business rules to discounts, refunds and other actions.

  1. Prompt

    Team: support · model: public-llm

    Summarise this case for the customer: Mario Rossi, diagnosed with type 2 diabetes, asks whether the new treatment is covered.

  2. Policy check

    Thousands of queries checked in milliseconds

    Health data stays on EU-hosted models. Written by your compliance team.

  3. Outcome

    Blocked before the model The user sees your message: "Health data can only go to EU-hosted models."

  4. Audit

    Illustrative rule trace · revision 7

    All conditions matched: destination outside the EU; patient diagnosis in the prompt.

    Enable JavaScript for an example trace ID and browser timestamp.

Illustrative examples

A policy check on the path of every request.

Gate runs as its own service next to your AI gateway and works with any model behind it. The gateway asks Gate before it calls the model and again before it returns the answer, so your rules hold for every model provider and whatever the system prompt says.

Works with your AI gateway

  • LiteLLMFull integration
  • agentgatewayBeta
  • Kong AI GatewayBeta
  • BifrostBeta

No AI gateway yet? Start with LiteLLM.

  1. Start LiteLLM with your provider credentials.

  2. Connect Gate using the configuration supplied for your pilot.

  3. Connect an app and verify an allowed request and a blocked request.

Start a pilot with LiteLLM

Using a different gateway? Tell us which one, and we will gladly integrate with it.Tell us your gateway

  1. Request stage

    Before the model

    Gate checks the prompt, the conversation, the tools offered and who is asking. If a rule matches, the request never reaches the model.

  2. Response stage

    Before your users

    Gate checks the answer against your response rules, for example credentials or personal data that should not come back.

  3. Decision log

    On the record

    Each decision names the policy and revision that made it. Logs keep identifiers and outcomes; prompts and answers stay private.

Streamed answers are checked as they flow.

Add every policy you need. Your AI stays fast.

Write rules as your business grows: your teams keep working at the same pace. Gate indexes your policies by what they look for, so each request is checked only against the few that could apply. Skipping is safe: the index follows each policy’s and/or logic and passes over it only when the request lacks the prerequisites of every way it could match. It never hides a match.

Illustrative example.

Autonomous agents follow your rules too.

An agent works through the same model calls as a person, only faster and without anyone watching. Gate checks every step it takes, so the rules you write for people also apply to your agents, along with rules written just for them.

  1. 1 · Instructions

    What the agent is told

    Check the instructions and the context an agent starts from, for example which data a support agent may bring into a conversation.

    Checked by Gate
  2. 2 · Tools offered

    What the agent may use

    Decide which tools each agent or team may be given. A support agent is never offered a payment tool.

    Checked by Gate
  3. 3 · Tool calls

    What the agent is about to do

    Check the actions the model asks the agent to take, including names and arguments, before they run. Stop a refund above a limit or a message to an outside address.

    Checked before it runs
  4. 4 · Results

    What comes back

    Apply rules to what tools return into the agent's context, such as documents and web pages, before the next model call.

    Checked by Gate

The result goes back to the model and the loop starts again. Gate checks every turn.

Gate decides on every agent step that passes through your AI gateway, while your tools keep running where they run today. Every stopped step is logged with the agent's identity, the policy and the revision.

Write your own policies. Audit every one.

Your team writes the rules, for security and for your own business, in one short and readable policy language. Every change creates a new revision. A privacy officer can read a policy, an auditor can review it, and every decision points back to the exact policy and revision that made it.

Deterministic

Patterns, fuzzy and proximity matching, and comparisons on any field of the request.matches · fuzzy · near

Runs first

Linguistic

Language detection, lemmas and proper nouns, so a rule follows every form of a word.detect_language · lemma · propn

Runs next

Semantic

Multilingual similarity to a topic described in plain words, and key-passage extraction.about · about_score · textrank

Runs last, only when needed

Every rule can also use context: the key, team or user making the call, the model, the tools offered or called, and whether it is the request or the response. The bars show relative cost: semantic checks run only when cheaper conditions already hold.


        

Your policies. Not a black box.

Many LLM guardrails give you fixed categories to switch on or off, and when something is blocked you see a label and a score. With Gate every policy is yours: written in your words, adjustable down to the last condition, and explained on every decision.

A typical guardrail
  • Personal data
  • Toxicity
  • Prompt attack
  • Custom topics

Blocked · category personal_data · score 0.91

Fixed categories, a threshold, and a verdict you cannot open.

A Noozle Gate policy
// Health data stays on EU-hosted models
!(doc.model startsWith "eu-private/")          your models
  && doc.request_data.team != "team-claims"   your exception
  && about(text, "patient diagnosis", 0.85)   your threshold

Blocked · health-topics-eu-only rev 7 · every condition traced

Every condition is readable, editable and versioned by your team.

Can your team…Typical guardrailsNoozle Gate
…read and change what a policy checks?Usually a fixed category to switch on or offYes, every condition is yours
…see why a request was blocked?Usually a category label and a scoreYes, the full reasoning with the matching text
…make exceptions ("everything except…")?Usually left to a model to interpretYes, written into the rule
…match competitor or product names?Usually described in words for a model to interpretYes: names, patterns, fuzzy matching
…depend on team, user, model and tools?Usually set per configurationYes, in the same rule
…get the same decision for the same input?Varies when a model is the judgeYes, traced to a policy revision

A category comparison. Individual products differ, and fixed categories are often quicker to switch on.

Policies as code, your way.

Manage Gate policies with the Noozle Terraform provider or the command line, in the same repositories and pipelines as the rest of your infrastructure.

  • Reviewed like code. Every policy change is a pull request, approved by security, privacy or legal before it goes live.
  • One process for every team. Plan, apply and roll back policies with the pipeline you already trust.
  • Scriptable from the command line. Validate, dry-run and publish policies with noozle-cli, from a laptop or any CI job.
  • Test, then promote. Run the same files in test and production, so what you approved is what enforces.
  • An audit trail for free. Your git history shows who changed which rule, when and why.
  • Built for scale. Hundreds of teams and policies from one place, with drift shown on every plan.
policies/health.tfIllustrative example
resource "noozle_query" "health_eu_only" {
  name            = "Health data stays on EU-hosted models"
  description     = "Owned by compliance. Reviewed quarterly."
  full_expression = <<-EOT
    !(doc.model startsWith "eu-private/")
      && about(text, "patient diagnosis", 0.85)
  EOT
  tags      = ["gdpr-art-9", "compliance"]
  is_active = true
}
$ terraform plan~ noozle_query.health_eu_only threshold 0.80 → 0.85Plan: 0 to add, 1 to change, 0 to destroy.
Or from the command lineIllustrative example
$ noozle-cli queries validate --expr-file health.expr
$ noozle-cli queries create \
    --name "Health data stays on EU-hosted models" \
    --expr-file health.expr --direction request

Every decision can be traced. Failures are never silent.

Live policy trace · illustrative example Business rules
MATCH q:377 rev 4 request
Keep pricing and discount terms out of external AI
Query reasoning
AND
  metadata  request_data.team == "team-sales"    matched
  OR
    semantic  about(confidential discounts and commercial terms)   score 0.8712 / 0.8500
    regex     (floor price|discount)   skipped after ancestor short-circuit
  keyword   "Acme"   matched
Decision log: block, rule_match, q:377 rev 4

  • Explain any decisiona trace shows which conditions ran, each score against its threshold, what was skipped and the text that matched.
  • A known violation always blockseven when another rule errors or times out.
  • Incomplete evaluations are labelledand follow the fail-open or fail-closed setting you choose.
  • No accidental bypassa disabled Gate or suspended tenant is rejected, not waved through.
  • Safe policy changesnew rules are validated without calling a model; if a revision fails, the last valid one keeps enforcing.
  • Correlated with your gatewayrecords carry your gateway’s call and trace IDs for incident review.

Always. Every decision is logged with its policy and revision.

On demand. Open a trace session for a policy, for a limited time, and authorized people see the full reasoning, including the matching snippets. Traces are streamed live, straight to the people who asked for them.

Start in our EU cloud. Move on-premise when you are ready.

The same product and the same policy language in both. Every pilot starts in the cloud, so you can try Gate before installing it yourself.

EU cloud

Made and hosted in Europe

Every pilot starts here.

  • Operated by Noozle on EU-owned infrastructure
  • Prompts and answers processed in memory and discarded
  • Decision records kept for your audit trail
  • Lower price, suited to smaller companies and pilots

On-premise

When you are ready to run it yourself.

  • In your data centre or private cloud
  • Everything stays inside your perimeter
  • You set log retention
  • Suited to large regulated organisations

Never stored

Prompt and answer text, tool definitions and tool-call arguments. They are processed in memory and discarded.

Kept for your audit trail

Evaluation ID, policy and revision, outcome and completeness, model name, gateway call and trace IDs, timings.

More people using AI. More prompts. More policy violations.

Company data is flowing into AI. Sensitive data is at risk in both prompts and answers.

45%Increase of 200%vs. 2025 report

of employees regularly use AI on corporate devices.

2025 report: 15% Verizon DBIR, 2026
69per weekIncrease of 57%vs. 2025

data policy violations involving sensitive data sent to AI, in the average organisation.

2025: 44 per week Netskope AI Report, 2026
31per weekIncrease of 158%vs. 2025

data policy violations involving sensitive data returned by AI.

2025: 12 per week Netskope AI Report, 2026

Relative increases within each source’s dataset, rounded to the nearest whole percent. Verizon compares its 2026 and 2025 reports; Netskope compares 2026 observations with 2025. Regular AI use means access at least once every 15 days.

Netskope also reports a sixfold increase in monthly prompts sent to generative AI apps.

Written policies set the rules; enforcement makes them hold. Nearly half of the privacy and security professionals surveyed by Cisco admit to entering personal or non-public data into GenAI tools (Cisco, 2025). Safety research points the same way. Aligned models can still be jailbroken (JailbreakBench), and detectors both miss attacks and block legitimate work (PIGuard, CAPTURE, GuardBench). That is the case for an independent layer, with rules you can read, that checks what goes in and what comes out.

Technical controls for GDPR and the EU AI Act.

Gate turns your compliance decisions into enforced, logged controls, and gives your DPO evidence for each one.

ControlHow Gate implements itSupports
Personal data and identifiersPattern, fuzzy and semantic rules on promptsGDPR Art. 5, 25, 32
Special-category dataMultilingual topic rules by team and modelGDPR Art. 9
Secrets and source codePattern rules on requests and responsesGDPR Art. 32
Tool and agent useRules on tools offered and tool callsOWASP LLM: excessive agency
TraceabilityDecisions tied to policy revisionsAI Act Art. 12, 26
Prompt injectionRules on requests, answers and tool callsAI Act Art. 15 · EDPS guidance

What Gate does today, and what comes next.

  1. Today

    Enforcement

    Allow or block requests and responses. LiteLLM fully integrated; agentgateway, Kong AI Gateway and Bifrost in beta.

    Rules

    Deterministic, linguistic and multilingual semantic rules on text, tools, identity and model.

    Evidence

    Privacy-safe decision records, dashboards and live policy tracing.

    Deployment

    EU cloud and on-premise.

  2. Next

    Policies in natural language

    Describe a rule in plain words; Gate writes it as a readable policy you review, and explains every decision in plain words too.

  3. Then

    Masking and pseudonymisation

    Replace personal data with placeholders before the prompt leaves, and keep the rest of the request working.

  4. After that

    Image content inspection

    Apply your rules to images in prompts and answers, not only to text.

  5. Later

    A web studio for domain specialists

    Privacy, legal and business teams write, test and review policies in a web interface, with no code to learn.

Designed and built in Europe, on open and inspectable foundations.

Noozle is an Italian company, and your data stays under EU law, wherever your teams work. The team that wrote the policy language, the matching engine and the gateway integration is the team you talk to. Need a new kind of check? Tell us: we extend the product around what customers need.

Made
and hosted
in Europe

  • Tested against the real gatewayend-to-end test suites against a pinned LiteLLM release, deployment canaries and drift checks.

Noozle Streaming

Route the events your business needs.

Gate checks your AI requests and responses. Streaming routes business events to the right destinations. Use the same policy language for both.

Follow one event from its source to every team and system that needs it.

See how Streaming routes events
  • Kafka
  • AMQP
  • Pulsar
  • NATS JetStream
  • Google Pub/Sub
  • AWS SQS
  • AWS SNS
  • AWS S3
  • SQL database
  • Elasticsearch
  • HTTP webhooks
  • HTTPS API
  • HTTP streams
  • SSE
  • Push alerts

Your first policies, running in our EU cloud.

Tell us what you want to control. We reply within 24 hours, usually sooner.

  1. Step 1: Assess · next

    We map your LLM data flows and privacy risks with you.

  2. Step 2: Go live

    Your first policies run in our EU cloud. Your privacy officer reviews the decisions.

  3. Step 3: Choose

    Stay in the cloud, or move Gate into your own infrastructure.

Start with one email.

Tell us which gateway you use and what you need to control. We reply within 24 hours, usually sooner.

We use your details only to reply to your request. Privacy policy.

Contacts. Talk to us about Noozle.

Evaluating Noozle Gate or Noozle Streaming? Tell us which product you're interested in and what you need it to do. We're happy to answer questions about capabilities, integrations and deployment options.

We use these details to reply to your message. Privacy policy. Protected by Cloudflare Turnstile.