SecuriX

Enterprise LLM + MCP Gateway

The control plane for your organization’s AI traffic.

SecuriX sits in front of every LLM and MCP server your teams touch — enforcing SSO, budgets, virtual keys, and DLP policy before a token leaves your network. Deploy as SaaS or self-hosted with Docker.

Admin consoleSSO connected · Okta
Monthly budget$42,300 / $60,000

Virtual keys

128 / 6 teams

DLP this month

214 redactions

Same policies, either way
SaaSOn-prem · Docker

Access control

Single sign-on, enforced at the gateway.

Connect Okta, Azure AD, or any SAML/OIDC provider. Every request is tied to a real identity — no shared API keys floating around in Slack.

  • SAML 2.0 & OIDC
  • SCIM provisioning
  • Role-based access per team
Identity providers
Okta · SAML 2.0connected
Azure AD · OIDCconnected
Google Workspaceavailable
128 users provisioned via SCIM

Cost control

Set a budget. Never blow through it by accident.

Cap spend per user, team, or project. SecuriX downgrades or blocks requests automatically when a limit is hit — before the invoice surprises anyone.

  • Per-team and per-project caps
  • Automatic model downgrade at threshold
  • Real-time spend alerts
Spend by team · this month
Engineering$18,200 / $25,000
Support$6,100 / $10,000
Growth$8,000 / $8,000
Growth capped at 100% — auto-downgraded to a cheaper model

Credential hygiene

Generate keys your real provider credentials never touch.

Every team, app, or environment gets its own scoped virtual key — rotate or revoke instantly without touching the underlying OpenAI, Anthropic, or Azure credentials.

  • Scoped to model, rate, and team
  • Instant revoke, no redeploy
  • Full usage attribution per key
Virtual keys128 active
sk-vx-prod-checkoutgpt-4o, claude-sonnet-5 · 500 req/min
revoke
sk-vx-staging-support-botclaude-haiku · 100 req/min
revoke
sk-vx-sales-copilotgpt-4o-mini · 50 req/min
revoke

Data protection

Catch sensitive data before it leaves your network.

SecuriX inspects prompts and completions for PII, secrets, and policy violations in real time — redact, block, or just log, per policy.

  • Built-in PII & secret detectors
  • Redact, block, or log per policy
  • Full audit trail per request
Policy log live

Redacted SSN pattern in prompt · checkout-bot

Redacted AWS access key in completion · sales-copilot

Blocked customer record export · support-bot

214 redactions this month · 0 leaked

Tool governance

Granular policy on every MCP tool call — not just the prompt.

SecuriX runs as the MCP gateway between your users and your MCP servers, plus a growing set of first-party integrations — so every tool call passes through policy, not just the prompt. Conditions on the request itself — who's asking, what they're touching, what it's worth — decide whether it runs.

  • Gateway for any MCP server, not just first-party
  • Attribute-based conditions, not just per-team access
  • Allow, block, or require approval per action
MCP tool policiesattribute-based
calendar.create_eventattendees: internal only
allowed
github.merge_pull_requesttarget: main, approvals: 0
blocked
stripe.issue_refundamount > $1,000
needs approval
gdrive.share_fileclassification: confidential, recipient: external
blocked

Governed RAG

Ask your company's docs — but only the ones you're allowed to see.

Upload documents and SecuriX indexes them for retrieval-augmented answers. Scope a doc to a team — Finance, say — and only that team's questions ever surface its chunks, no matter who else asks.

  • Per-team and per-user document scoping
  • Access enforced in the retrieval index, not the UI
  • Same identity, same permissions as everywhere else
Knowledge base
Priya · Finance3 sources found

What was our Q3 burn rate?

Marcus · Support0 sources visible

What was our Q3 burn rate?

Q3-Board-Deck.pdf is scoped to Finance — the index respects it, not just the UI

Deployment

SaaS in minutes, or fully self-hosted.

Run SecuriX as a managed service, or deploy the same image in your own VPC with a single docker run. Your data plane, your call — same policies either way.

  • One Docker image, SaaS or self-hosted
  • No data plane lock-in
  • Identical admin console either way
Deployment
SaaS
  • Live in minutes
  • Managed & auto-updated
  • Same admin console
Self-hosted · Docker
  • docker run securix/gateway
  • Runs in your VPC
  • Same admin console

How it works

From SSO to your first governed request in under a day.

01

Connect identity & providers

Point SecuriX at your Identity Provider for SSO (Okta, Azure AD, or any SAML/OIDC provider) and the model or MCP providers your teams already use. No client-side code changes.

02

Define policy

Set budgets, virtual keys, DLP rules, and attribute-based MCP tool policy — per team, per user, or per request attribute. As granular as your org needs.

03

Route through the gateway

Point client apps at your SecuriX endpoint instead of the provider directly. Deploy as SaaS or self-hosted with a single docker run.

04

Monitor & audit

Every request, tool call, and knowledge-base query lands in one console — spend, redactions, and policy decisions, all attributable to a real identity.

See SecuriX in front of your own traffic.

Tell us where to reach you and we'll set up a walkthrough with your identity provider, your policies, and your budget structure.

Request a demo

We'll reach out within 2 business days.