The gateway is a target. Here is how ours is protected.
Every AI request your developers make passes through our gateway, so it holds exactly what attackers went after in 2026: provider keys and agent traffic. That year, self-hosted AI gateways were exploited for key theft, and at least one shipped with authentication switched off by default. Below is how ours is protected — every sentence tied to a test in our repository, a decision record or a script, and the parts that are not done yet marked as such.
Sentilai · Last verified 29 September 2026
Nothing reaches a provider without a credential
- Every gateway route except a health check and the public, anonymised Slopsquatting Observatory refuses a caller with no credential, a malformed one, or a well-formed token signed by anyone else — whether the token is sent in a header or in the URL path.
- A revoked device, or a device whose session has expired, is refused within about 30 seconds; an admin can revoke a device in one click, and cannot revoke another organisation's.
Keys and tokens
- Provider keys you add are sealed with authenticated encryption before they are stored, under a versioned keyring that supports rotation; a tampered ciphertext does not open.
- Once a key is saved, the console only ever shows its last four characters.
- The Endpoint Suite's device token travels in the URL path, so the access log redacts it. Neither the token nor a provider key reaches a log line — on the failure path included, which is the path a scanner exercises thousands of times.
- A secret in a remote MCP server's endpoint URL (
?token=,?api_key=) is stripped from our logs when that server fails. We found this one while writing this page; it is fixed. - Not yetOne master keyring covers every organisation today. A per-organisation sealing boundary is designed but not built.
If one organisation's data is reached, the others are not
- Row-level security is enabled on 32 tenant tables in production (measured 29 September 2026): a query that forgets its organisation filter returns nothing, rather than another organisation's rows.
- The credential your SIEM uses to pull events carries a single read scope, checked on every call; it cannot change policy.
Transport
- Every host we serve sends HSTS,
nosniffand a referrer policy; our consoles and website add a content security policy that forbids framing. A script checks every public host. - Not yetOur identity provider's host (hekate) does not send HSTS yet. A browser that has visited sentilai.com is covered by its subdomain-wide policy; one that goes straight to a console login is not.
A silent gateway is an outage
- A provider that is slow to answer does not make the gateway look dead to proxies in between: long requests, streamed or not, are held open until the provider speaks.
- Every request leaves an audit row — including the ones whose client disconnected, which are disproportionately the ones somebody later wants to investigate.
Supply chain
- Go, Rust and JavaScript dependencies are scanned for known vulnerabilities in CI on every push.
- The macOS and Windows Endpoint Suite apps are code-signed.
What we do not do
- We do not store prompt or response text unless your organisation turns capture on.
- The optional LLM classifier tier sends text to an EU-hosted model provider, listed on our sub-processors page; nothing else leaves our infrastructure for a model.
- We hold no security certification today, and say so in our DPA. Our CAIQ self-assessment is public in the CSA STAR Registry.
Reporting a vulnerability
- Our security contact is in /.well-known/security.txt. Reports get a human reply.
How to read this page: each item names its evidence in the page source (data-evidence). Our website build fails if a cited test, decision record or script stops existing. Links on this page: /security.html.