Try Bifrost Enterprise free for 14 days.
Request access
[ AI SECURITY + BIFROST ]

AI Security for Every Model Request
and Agent Tool Call

Enforce PII redaction, secrets detection, and prompt injection guardrails on every model request and agent tool call from one AI gateway: Bifrost (by Maxim AI).

[ PERFORMANCE AT A GLANCE ]

AI Security Controls at 11µs of Gateway Overhead

11µs
Overhead
Per request at 5,000 RPS with a 100% success rate
Air-gapped
By default
No prompts, responses, files, or telemetry leave your environment
SOC 2
Compliance
SOC 2 Type II, ISO 27001, HIPAA, GDPR
25+
Providers
10,000+ models behind one OpenAI-compatible API

[ THE PROBLEM ]

Secure AI Apps and Agents without Per-App Security Code

Per-app security code works for one or two services; consolidate it at the gateway as agents and tool integrations multiply.

Unify Security Checks Scattered Across AI Apps

PII filtering, credential scanning, and prompt screening live in each service's code, so coverage diverges as implementations are maintained independently.

Stop Indirect Prompt Injection in Tool Results

Agents pass model-generated arguments to tools and feed results back to the model, so output from any connected MCP server can carry indirect prompt injection into the next call.

Prevent AI Data Leakage to Providers and Logs

Prompts can contain customer records or API keys, and without detection in the request path that text reaches the provider and application logs.

Centralize Provider Credentials and Revocation

Each application holds its own provider keys, so access cannot be scoped or revoked centrally.

[ THE QUESTIONS ]

Answer the Agentic AI Security Questions Before Production

Map each question a security review raises about LLM apps and agents to the Bifrost control that answers it.

Question your team is askingHow Bifrost answers itCapability
Can we stop PII from reaching model providers?Detects emails, phone numbers, SSNs, and similar entities, then blocks or redacts before forwardingPII redaction
Can we stop API keys and credentials leaking into prompts or responses?Scans request and response text with 222 Gitleaks default rules and blocks or redacts matchesSecrets Detection
How do we block prompt injection and jailbreaks?Evaluates inputs with guardrail providers such as AWS Bedrock Guardrails, Google Model Armor, and CrowdStrike AIDRGuardrails
Do the same checks apply to agent tool calls?MCP rules inspect tool arguments before execution and tool results before they returnMCP guardrails
Which tools can an agent call?Filters stack at client, request, and virtual key level; an empty client list exposes no toolsTool filtering
Who can call which models, and how much?Each virtual key carries allowed providers and models, budgets, and rate limitsVirtual keys
Who changed a guardrail or access policy, and when?Records administrative activity as HMAC-signed events, exportable and archivable to S3 or GCSAudit logs
Does prompt and response data leave our network?Runs inside your VPC or air-gapped, with no traffic over the public internetIn-VPC deployments
Does Bifrost secure model training data or weights?The gateway governs traffic to and from models; training pipelines are secured in the ML platformOutside gateway scope

[ THREAT MODEL ]

Map AI Security Risks to Gateway Controls

Check each OWASP Top 10 for LLM Applications risk against the control Bifrost enforces, and see what sits outside gateway scope.

Risk (OWASP 2025)Gateway controlCoverage
Prompt injection, including indirect injection in tool resultsInput guardrail rules on model requests; output rules on MCP tool resultsEnforced at gateway (detection depends on provider)
Sensitive information disclosurePII and secrets detection with runtime, logs-only, or reversible redactionEnforced at gateway
Excessive agencyTool filtering, virtual MCPs, and MCP guardrails before executionEnforced at gateway
Unbounded consumptionBudgets and rate limits per virtual key, team, and customerEnforced at gateway
Improper output handlingOutput guardrail rules can block or redact responsesShared: the application still validates output it executes
MisinformationHallucination detection through the Patronus AI profileShared: grounding and evaluation sit in the application
Supply chain, data and model poisoningNoneOutside gateway scope: model provider and ML pipeline
Vector and embedding weaknessesNoneOutside gateway scope: retrieval store access controls

[ HOW IT WORKS ]

Enforce AI Agent Security at the Gateway

Route model requests and MCP tool calls through Bifrost to apply virtual keys, guardrail rules, and tool filters before traffic reaches providers.

Apps and agents
SDKs, MCP clients, coding agents
base URL + virtual key
Bifrost
Guardrail rules, tool filtering, budgets
policy applied
Providers and MCP
Models and tool servers

For Developers: Keep Your SDK and Workflow

Change one base URL as a drop-in replacement; keep the existing SDK.

  • Same OpenAI-compatible request format
  • Same agent frameworks and MCP clients
  • No guardrail code in each service
  • Blocked requests return a guardrail intervention the app can handle

For Security Teams: Enforce One Policy Everywhere

Define policy once and apply it to every caller of the gateway.

  • Guardrail rules written as CEL expressions
  • Per-key, per-team, and per-user scoping
  • Redacted values in stored logs and exported traces
  • Signed record of every policy change

[ CORE CAPABILITIES ]

Stop Prompt Injection Attacks, PII Leaks, and Secret Exposure

Configure each control once in the Bifrost dashboard or config file, and apply it to every request.

Redact PII Before It Reaches Model Providers

PII redaction uses the Custom Regex PII Detection template, Presidio, or Azure AI Language PII. The logs_only mode leaves the live call unchanged and redacts Bifrost logs and trace-export content.

Runtime, logs, or both

Detect Leaked Secrets and API Keys

Secrets Detection runs inside Bifrost with no external service, finds API keys, access tokens, and private keys in request and response text, and detects, blocks, or redacts them.

222 Gitleaks rules

Block Prompt Injection Attacks

Guardrail rules link to profiles from AWS Bedrock Guardrails, Azure Content Safety, Google Model Armor, Check Point's AI Agent Security, and other providers. Prompt Guardrails enforce your written policies with an LLM judge.

3 managed + 11 external

Secure MCP Tool Calls at Execution

MCP guardrail rules run at the tool-execution boundary and can target a client, tool, or argument. An input block stops the tool before it runs; an output block keeps the result from the model.

Arguments and results

Filter Agent Tools with Virtual MCPs

Tool filtering limits each agent to approved tools, and a tool must pass every filter level. Virtual MCPs bundle curated tools behind one endpoint attached to virtual keys.

Client, request, VK

Control AI Access and Audit Every Change

Virtual keys scope models, providers, budgets, and rate limits per caller. Audit logs record administrative changes as signed events, exportable as JSON, JSON Lines, or Syslog.

HMAC-signed events

[ GUARDRAIL PROVIDERS ]

[ COMPARISON ]

AI Security Solutions: AI Agents alone vs. AI Agents + Bifrost

CapabilityAI agents aloneAI agents + Bifrost
PII handlingImplemented per application where neededDetect, block, or redact on every request
Credential leakageDepends on each service's scanningGitleaks-backed detection on inputs and outputs
Prompt injection screeningPer-application integration with a screening serviceGuardrail profiles shared across all traffic
Tool-call inspectionHandled inside each agent frameworkGuardrails on tool arguments and results
Tool accessDefined in each agent's configurationFiltered by client, request, and virtual key
Model access and spendProvider keys held in each serviceVirtual keys with budgets and rate limits
Provider key storageEnvironment variables per serviceResolved at runtime from AWS Secrets Manager, GCP Secret Manager, or HashiCorp Vault
Policy change historySpread across repositories and consolesSigned audit logs in one place

A practical evaluation is to route one agent's model and tool traffic through Bifrost with a PII and secrets rule in logs_only mode, then review what the rules detect before enabling blocking.

[ USE CASES ]

Apply Enterprise AI Security Across Teams

Standardize Data Leakage Prevention Across AI Apps

One PII and secrets policy applies to every application behind the gateway, so a security review checks one rule set.

Give Agents Curated, Guarded Tool Access

Each team's agents receive a virtual MCP of approved tools, and MCP guardrails inspect arguments before write actions run.

Protect AI Data Privacy in Regulated Industries

Healthcare and financial services teams run Bifrost in-VPC or air-gapped and redact regulated fields from prompts, logs, and exported traces.

Govern Coding Agents with the Same Policy

CLI coding agents route through virtual keys, so secrets detection and budgets apply to terminal traffic too.

[ GOVERNANCE & COMPLIANCE ]

Meet AI Compliance Requirements for Regulated Enterprises

Bifrost is built for enterprises running mission-critical AI workloads that require top-tier performance, scalability, and reliability.

Multiple Fortune 500 companies in financial services, healthcare, technology, pharmaceuticals, and defense run it in production. Bifrost Enterprise adds the controls below to the AI guardrails platform.

AICPA SOC
GDPR
ISO 27001
HIPAA

SOC 2 Type II · ISO 27001 · HIPAA · GDPR

Scope Access with RBAC and Data Access Control

RBAC defines what each role can change, and data access control limits which guardrail configurations, keys, and MCP clients each role sees.

Sync Access from Your Identity Provider

User provisioning connects Okta, Microsoft Entra, Google Workspace, and other OIDC providers, so access follows the directory.

Store Provider Keys in Your Own Vault

Secret management resolves provider keys, virtual key values, and MCP auth headers from AWS Secrets Manager, GCP Secret Manager, or HashiCorp Vault at runtime.

Deploy In-VPC or Air-Gapped

Bifrost runs in your VPC, on-premises, or fully disconnected, and no prompts, responses, files, or telemetry leave your environment.

[ SHIP RELIABLE AI ]

Start Enforcing AI Security on Every Model Request

Evaluate Bifrost by routing one production agent through detect-only guardrails, then enable blocking and redaction for the rules that matter.

[ BIFROST FEATURES ]

Open Source & Enterprise

Everything you need to run AI in production, from free open source to enterprise-grade features.

01 Governance

SAML support for SSO and Role-based access control and policy enforcement for team collaboration.

02 Adaptive Load Balancing

Automatically optimizes traffic distribution across provider keys and models based on real-time performance metrics.

03 Cluster Mode

High availability deployment with automatic failover and load balancing. Peer-to-peer clustering where every instance is equal.

04 Alerts

Real-time notifications for budget limits, failures, and performance issues on Email, Slack, PagerDuty, Teams, Webhook and more.

05 Log Exports

Export and analyze request logs, traces, and telemetry data from Bifrost with enterprise-grade data export capabilities for compliance, monitoring, and analytics.

06 Audit Logs

Comprehensive logging and audit trails for compliance and debugging.

07 Vault Support

Secure API key management with HashiCorp Vault, AWS Secrets Manager, Google Secret Manager, and Azure Key Vault integration.

08 VPC Deployment

Deploy Bifrost within your private cloud infrastructure with VPC isolation, custom networking, and enhanced security controls.

09 Guardrails

Automatically detect and block unsafe model outputs with real-time policy enforcement and content moderation across all agents.

[ SHIP RELIABLE AI ]

Try Bifrost Enterprise with a 14-day Free Trial

[quick setup]

Drop-in replacement for any AI SDK

Change just one line of code. Works with OpenAI, Anthropic, Vercel AI SDK, LangChain, and more.

1import os
2from anthropic import Anthropic
3
4anthropic = Anthropic(
5 api_key=os.environ.get("ANTHROPIC_API_KEY"),
6 base_url="https://<bifrost_url>/anthropic",
7)
8
9message = anthropic.messages.create(
10 model="claude-3-5-sonnet-20241022",
11 max_tokens=1024,
12 messages=[
13 {"role": "user", "content": "Hello, Claude"}
14 ]
15)
Drop in once, run everywhere.

[ FAQ ]

AI Security: Frequently Asked Questions

Bifrost secures AI agents by routing their model requests and MCP tool calls through one AI gateway that applies guardrail rules, tool filters, and access limits. A typical setup gives each agent a virtual MCP of approved tools, redacts PII and secrets in both directions, and screens inputs and tool results for prompt injection.

Bifrost secures agent access with virtual keys, which scope the providers, models, budgets, and rate limits each agent can use. Tool access is filtered at client, request, and virtual key level, and MCP authentication supports per-user OAuth so each person connects under their own account.

The OWASP Top 10 for LLM Applications lists prompt injection, sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, misinformation, and unbounded consumption. Bifrost enforces controls for prompt injection, sensitive information disclosure, excessive agency, and unbounded consumption at the gateway.

Bifrost inspects MCP tool results with output guardrail rules before they return to the model. Detection comes from the linked provider: Azure Content Safety, Google Model Armor, and Gray Swan support indirect prompt injection detection, and several others support it depending on policy. An output block keeps the result out of the model's context.

Bifrost adds about 11µs of overhead per request at 5,000 RPS in sustained benchmarks. Guardrail providers add their own evaluation time, which is lowest for in-process checks such as Secrets Detection and Custom Regex. Rules can be sampled to a percentage of requests, and detect-only rules do not delay streaming.

Bifrost starts with `npx -y @maximhq/bifrost` or `docker run -p 8080:8080 maximhq/bifrost`, and existing applications need one base URL change because the gateway is OpenAI-compatible. Most teams route traffic the same day and then add guardrail rules, tool filters, and virtual keys from the dashboard.

Bifrost's open-source core, licensed under Apache 2.0, includes virtual keys, budgets and rate limits, MCP tool filtering, and virtual MCPs. Bifrost Enterprise adds guardrails (PII redaction, secrets detection, prompt injection providers), signed audit logs, RBAC, data access control, SSO, secret management, and in-VPC deployment support, with a free 14-day trial.