Book a Demo →
🇦🇺 Sovereign-First Platform
Step 2 of the Songlines Journey: Songlines Gateway sits between your applications and every AI model — enforcing policy inline, before the request lands. See the full journey →
Songlines Gateway
Songlines Gateway · Step 2 — Expand

Every AI request
transits the Gateway

Songlines Gateway is the mandatory inline enforcement layer for all AI traffic. Policy is enforced, PII is redacted, and every interaction is audit-logged — before the request reaches any model. Zero application code changes required.

Start Your 2-Week POC → Explore Capabilities
0ms
Added latency overhead — sub-millisecond policy evaluation
100%
AI traffic coverage — no request bypasses the Gateway
19+
AI models supported across all major providers
AU
Data never leaves Australian infrastructure
Core Capabilities

Inline enforcement at the point of every AI interaction

Songlines Gateway intercepts every AI request before it reaches a model. Policies are evaluated, sensitive data is handled, and every interaction is recorded — all in real time, with no changes to your application code.

🛡️

Inline Policy Enforcement

Define governance rules once — Gateway enforces them on every request, across every model and every team. Block, redact, route, or escalate based on content, user, department, or data classification.

🔏

PII Auto-Redaction

Automatically detect and redact personally identifiable information before it reaches any AI model. Supports Australian Privacy Act definitions, Medicare numbers, TFNs, and custom entity types.

🚫

Prompt Injection Prevention

Detect and block prompt injection attacks, jailbreak attempts, and adversarial inputs in real time. Protect your AI systems from manipulation without slowing legitimate workflows.

Human-in-the-Loop Approvals

Route high-risk or sensitive requests to a human approver before they proceed. Configurable approval workflows with full audit trail — ideal for regulated industries and government use cases.

🗺️

Sovereign Data Routing

Automatically route requests containing sensitive or classified data to approved sovereign models only. Ensure PII, health data, and government information never leaves Australian infrastructure.

📋

Immutable Audit Logging

Every request, every policy decision, every redaction — logged immutably with full context. Tamper-evident records ready for compliance audits, IRAP assessments, and regulatory review.

Sub-Millisecond Latency

Gateway policy evaluation adds less than 1ms to request latency. Enterprise-grade throughput with no perceptible impact on end-user experience — even at scale.

🔌

Zero Code Changes

Deploy Gateway as a transparent proxy in front of your existing AI integrations. No SDK changes, no application refactoring — your teams keep working exactly as they do today.

📊

Policy Analytics

Real-time dashboards showing policy trigger rates, blocked requests, redaction volumes, and approval queue status. Understand your AI risk posture at a glance.

The Gateway request lifecycle

Every AI request from every application in your organisation flows through Songlines Gateway. Here's what happens in under a millisecond.

1

Request Intercept

Your application sends an AI request as normal. Gateway intercepts it transparently — no SDK changes, no proxy configuration visible to developers. The request is captured with full metadata: user identity, department, application, timestamp, and data classification.

2

Policy Evaluation

The request is evaluated against your active policy set in real time. Policies can inspect content, user attributes, data classification, model selection, and request context. Evaluation is complete in under 1ms — imperceptible to end users.

3

PII Detection & Redaction

Sensitive data is detected using Australian-specific entity recognition — Medicare numbers, TFNs, ABNs, health identifiers, and custom types. PII is redacted or tokenised before the request proceeds, with the original preserved in the secure audit log.

4

Route or Escalate

Based on policy outcome, the request is routed to the appropriate model (including sovereign-only routing for sensitive data), escalated to a human approver, or blocked with a structured response returned to the application. All outcomes are logged.

5

Immutable Audit Record

Every request, policy decision, redaction, and response is written to the immutable audit log. Records are tamper-evident and retained according to your data governance policy — ready for compliance audits, IRAP assessments, and regulatory review at any time.

The Songlines Journey

Gateway is Step 2 of 3

Start with Songlines Control for immediate visibility. Expand to Gateway for inline enforcement. Complete the journey with the full sovereign Songlines Platform.

Step 1
Songlines Control
Songlines Control
Visibility & governance — deployed in hours.
Learn more →
You are here
Step 2 — Current
Songlines Gateway
Songlines Gateway
Inline enforcement — every request, every model.
Step 3
Songlines
Platform
Songlines Platform
Full sovereign stack — IRAP, air-gapped, on-prem.
Talk to us →

Deploy Songlines Gateway in two weeks

Our structured POC puts Gateway in front of your AI traffic in Week 1 and delivers a full executive readout in Week 2 — with zero risk and zero infrastructure changes.