Agents that can send emails, update your CRM, and spend money need more than a terms-of-service promise. ApiSpi ships a governance layer most platforms reserve for enterprise contracts — on, by default, for everyone.
One click cuts every connector and tool instantly — for a user, or the whole organisation. Org-level stops can't be overridden from below.
Daily and monthly limits in dollars and tokens, per user and org-wide, with alerts at 80% — so an agent can never surprise you on cost.
Set access per connector — full, read-only, or approval-required — down to individual tools. Gated actions file a request an admin reviews with the actual payload; grants expire automatically after 30 minutes.
Write guardrails as versioned YAML — with embedded tests, save-time validation, and rollback — enforced on every message and reply. Read how it works →
Every message, tool call, approval, and policy change is logged with who, what, and when — exportable as CSV, with a printable governance posture report.
Stream enforcement events to your own SIEM or log pipeline in real time as they happen — guardrail blocks, spend alerts, tool approvals, policy-as-code matches — HMAC-signed so your receiver can verify each delivery came from ApiSpi. Works with anything that accepts a JSON webhook: Splunk (HEC), Elastic, Microsoft Sentinel / Defender, and the rest.
Test a candidate keyword list or policy-as-code rule against a sample of real, recent prompts and replies before switching it on — see exactly what it would have blocked, with nothing actually enforced yet.
Australian-aware redaction — TFNs, Medicare numbers, ABNs — plus keyword guardrails, prompt-injection detection, and optional AI output moderation.
Hosted onshore in Australia. Block connectors by country of origin, allowlist AI providers, and route sensitive content to designated private models. For requirements SaaS can't meet, the same policy engine is coming as a self-hosted on-prem appliance.
Every external dependency your agents rely on — A2A agent cards, remote MCP tool lists — is fingerprinted on first use and re-validated daily. If an upstream agent quietly gains a skill or a tool definition changes, admins are alerted and the change isn't trusted until explicitly approved.
Restrict when agents may act, set data retention windows with automatic purging, and review connector access on your schedule.
This is a working simulation of two controls from the real admin console — no account needed. Send a risky prompt at the AI Firewall, then try to loosen a policy and watch maker-checker stop you approving your own change.
Send a prompt "through the gateway". The firewall scans it before any model sees it.
| Time | Direction | Category | Action |
|---|---|---|---|
| No events yet — send a prompt above. | |||
You're signed in as Alex (admin). Loosening a control never applies on one person's say-so.
Simulation only — nothing is sent to a model and nothing is stored. The real thing also covers spend caps, approval queues, policy-as-code, and SIEM export. Start your free week to use it on live traffic.
ApiSpi's controls are designed around the principles of these frameworks. These are alignment statements, not third-party certifications — see the note below.
Australia's Information Security Manual. Onshore AU hosting, per-user access control, and full audit logging of agent actions reflect its core control set.
Information security management. Versioned policy change control, audit trails, and role-scoped admin access map to its Annex A controls.
The AI management system standard. The closest fit of all five — human-in-the-loop approval, guardrails, dry-run testing, and full audit trails are exactly what it asks of an AI system's governance.
Australian Government's Protective Security Policy Framework. Onshore hosting, access windows, retention controls, and exportable audit trails support agencies working to it.
Trust Services Criteria for security, availability, and confidentiality. Access control, change management, and continuous audit logging reflect its control objectives.
ApiSpi is not currently certified or audited against any of these frameworks — this section describes how our existing controls align with their principles, not a formal attestation. Reach out via Contact for our current security documentation or to discuss formal certification for your engagement.
Governance merges from two levels — organisation policy and per-user settings — and the stricter rule always applies. A user can tighten their own guardrails but never loosen the organisation's. The same policy engine covers every surface: Aria chat, scheduled prompts, background tasks, the LLM gateway, and external agents connecting over MCP or A2A. There is no side door.
Layered containment: guardrails block or redact content in-flight, approval mode pauses state-changing actions for human review, spend caps bound the damage financially, and the emergency stop halts everything instantly. Afterwards, the audit trail shows exactly what happened.
Organisation policy is admin-only, versioned on every change, and can be rolled back. Policy edits are themselves audit-logged — governance of the governance.
Yes. Gateway API keys, MCP clients like Claude, and A2A agent delegations all execute through the same governed engine as the in-app assistant — same spend/token caps, same approval queues, same kill switch, same keyword and prompt-injection guardrails, and the same policy-as-code YAML rules, including for tool-calling passthrough clients (Cline and similar) that supply their own tools.
Run it in dry-run mode first: admins can test a candidate keyword list or policy-as-code rule against a sample of real, recent prompts and replies and see exactly what would have fired — no enforcement, no risk — before enabling it for real traffic.
Yes. Set a webhook URL from the admin governance page and every enforcement event is POSTed there in real time, HMAC-SHA256 signed so your receiver can verify it actually came from ApiSpi. Point it at a Splunk HTTP Event Collector, an Elastic ingest endpoint, a Microsoft Sentinel / Defender data connector, or any log pipeline that accepts JSON over HTTPS. The on-demand CSV export and posture report are still there too — the webhook is additive, not a replacement.
Supply-chain validation. When you connect an external A2A agent or a remote MCP tool server, ApiSpi fingerprints exactly what it advertised — its capabilities, tool definitions, and the endpoint it runs at — and re-checks that fingerprint every day. If the upstream changes in any way (a new skill appears, a tool definition is rewritten, the endpoint moves), admins are alerted with a precise diff of what changed, the event streams to your SIEM, and the platform keeps operating against the version you originally trusted. The new state only becomes trusted when an admin explicitly approves it — a change upstream never becomes a change in your risk posture silently.
Nothing extra. Every control on this page is included with every account — see pricing.
Try the full governance suite in your free week — set a cap, gate a tool, hit the stop button.