Included With Every Account

Autonomous Agents.
Accountable to You.

Agents that can send emails, update your CRM, and spend money need more than a terms-of-service promise. ApiSpi ships a governance layer most platforms reserve for enterprise contracts — on, by default, for everyone.

Every Control, In One Place

🛑 Emergency stop

One click cuts every connector and tool instantly — for a user, or the whole organisation. Org-level stops can't be overridden from below.

💰 Spend & usage caps

Daily and monthly limits in dollars and tokens, per user and org-wide, with alerts at 80% — so an agent can never surprise you on cost.

✋ Approval queues

Set access per connector — full, read-only, or approval-required — down to individual tools. Gated actions file a request an admin reviews with the actual payload; grants expire automatically after 30 minutes.

📜 Policy as code

Write guardrails as versioned YAML — with embedded tests, save-time validation, and rollback — enforced on every message and reply. Read how it works →

🔍 Audit trail

Every message, tool call, approval, and policy change is logged with who, what, and when — exportable as CSV, with a printable governance posture report.

📡 SIEM / webhook export

Stream enforcement events to your own SIEM or log pipeline in real time as they happen — guardrail blocks, spend alerts, tool approvals, policy-as-code matches — HMAC-signed so your receiver can verify each delivery came from ApiSpi. Works with anything that accepts a JSON webhook: Splunk (HEC), Elastic, Microsoft Sentinel / Defender, and the rest.

🧪 Dry-run before you enforce

Test a candidate keyword list or policy-as-code rule against a sample of real, recent prompts and replies before switching it on — see exactly what it would have blocked, with nothing actually enforced yet.

🕶️ PII redaction

Australian-aware redaction — TFNs, Medicare numbers, ABNs — plus keyword guardrails, prompt-injection detection, and optional AI output moderation.

🌏 Data sovereignty

Hosted onshore in Australia. Block connectors by country of origin, allowlist AI providers, and route sensitive content to designated private models. For requirements SaaS can't meet, the same policy engine is coming as a self-hosted on-prem appliance.

🔗 Supply-chain validation

Every external dependency your agents rely on — A2A agent cards, remote MCP tool lists — is fingerprinted on first use and re-validated daily. If an upstream agent quietly gains a skill or a tool definition changes, admins are alerted and the change isn't trusted until explicitly approved.

⏰ Access windows & retention

Restrict when agents may act, set data retention windows with automatic purging, and review connector access on your schedule.

See It Enforce, Live

This is a working simulation of two controls from the real admin console — no account needed. Send a risky prompt at the AI Firewall, then try to loosen a policy and watch maker-checker stop you approving your own change.

🔥 AI Firewall Block mode

Send a prompt "through the gateway". The firewall scans it before any model sees it.

TimeDirectionCategoryAction
No events yet — send a prompt above.
🤝 Maker-Checker Two-admin control

You're signed in as Alex (admin). Loosening a control never applies on one person's say-so.

PII redaction On

    Simulation only — nothing is sent to a model and nothing is stored. The real thing also covers spend caps, approval queues, policy-as-code, and SIEM export. Start your free week to use it on live traffic.

    Standards We Align With

    ApiSpi's controls are designed around the principles of these frameworks. These are alignment statements, not third-party certifications — see the note below.

    ASD ISM

    Australia's Information Security Manual. Onshore AU hosting, per-user access control, and full audit logging of agent actions reflect its core control set.

    ISO/IEC 27001

    Information security management. Versioned policy change control, audit trails, and role-scoped admin access map to its Annex A controls.

    ISO/IEC 42001

    The AI management system standard. The closest fit of all five — human-in-the-loop approval, guardrails, dry-run testing, and full audit trails are exactly what it asks of an AI system's governance.

    PSPF

    Australian Government's Protective Security Policy Framework. Onshore hosting, access windows, retention controls, and exportable audit trails support agencies working to it.

    SOC 2

    Trust Services Criteria for security, availability, and confidentiality. Access control, change management, and continuous audit logging reflect its control objectives.

    ApiSpi is not currently certified or audited against any of these frameworks — this section describes how our existing controls align with their principles, not a formal attestation. Reach out via Contact for our current security documentation or to discuss formal certification for your engagement.

    Strictest Rule Wins

    Governance merges from two levels — organisation policy and per-user settings — and the stricter rule always applies. A user can tighten their own guardrails but never loosen the organisation's. The same policy engine covers every surface: Aria chat, scheduled prompts, background tasks, the LLM gateway, and external agents connecting over MCP or A2A. There is no side door.

    Answers for Your Risk Register

    What happens if an agent misbehaves?

    Layered containment: guardrails block or redact content in-flight, approval mode pauses state-changing actions for human review, spend caps bound the damage financially, and the emergency stop halts everything instantly. Afterwards, the audit trail shows exactly what happened.

    Who can see and change governance settings?

    Organisation policy is admin-only, versioned on every change, and can be rolled back. Policy edits are themselves audit-logged — governance of the governance.

    Does governance apply to API and third-party access too?

    Yes. Gateway API keys, MCP clients like Claude, and A2A agent delegations all execute through the same governed engine as the in-app assistant — same spend/token caps, same approval queues, same kill switch, same keyword and prompt-injection guardrails, and the same policy-as-code YAML rules, including for tool-calling passthrough clients (Cline and similar) that supply their own tools.

    How do we know a new policy won't break something before we turn it on?

    Run it in dry-run mode first: admins can test a candidate keyword list or policy-as-code rule against a sample of real, recent prompts and replies and see exactly what would have fired — no enforcement, no risk — before enabling it for real traffic.

    Can we pipe governance events into our own SIEM?

    Yes. Set a webhook URL from the admin governance page and every enforcement event is POSTed there in real time, HMAC-SHA256 signed so your receiver can verify it actually came from ApiSpi. Point it at a Splunk HTTP Event Collector, an Elastic ingest endpoint, a Microsoft Sentinel / Defender data connector, or any log pipeline that accepts JSON over HTTPS. The on-demand CSV export and posture report are still there too — the webhook is additive, not a replacement.

    What stops a third-party agent or tool server changing underneath us?

    Supply-chain validation. When you connect an external A2A agent or a remote MCP tool server, ApiSpi fingerprints exactly what it advertised — its capabilities, tool definitions, and the endpoint it runs at — and re-checks that fingerprint every day. If the upstream changes in any way (a new skill appears, a tool definition is rewritten, the endpoint moves), admins are alerted with a precise diff of what changed, the event streams to your SIEM, and the platform keeps operating against the version you originally trusted. The new state only becomes trusted when an admin explicitly approves it — a change upstream never becomes a change in your risk posture silently.

    What does this cost?

    Nothing extra. Every control on this page is included with every account — see pricing.

    Deploy Agents You Can Answer For

    Try the full governance suite in your free week — set a cap, gate a tool, hit the stop button.