SENTILAI

The gateway is a target. Here is how ours is protected.

Every AI request your developers make passes through our gateway, so it holds exactly what attackers went after in 2026: provider keys and agent traffic. That year, self-hosted AI gateways were exploited for key theft, and at least one shipped with authentication switched off by default. Below is how ours is protected — every sentence tied to a test in our repository, a decision record or a script, and the parts that are not done yet marked as such.

Nothing reaches a provider without a credential

Keys and tokens

If one organisation's data is reached, the others are not

Transport

A silent gateway is an outage

Supply chain

What we do not do

Reporting a vulnerability

How to read this page: each item names its evidence in the page source (data-evidence). Our website build fails if a cited test, decision record or script stops existing. Links on this page: /security.html.