Governance & Compliance Appliance
Compliance you can prove.
A network appliance that turns everyday network activity into audit-ready compliance evidence.
U.S. Patent PendingA managed appliance from Sigma Technical Group
Compliance you can trust, configurability you can use.
Why Gatewarden
Defensible AI-usage evidence, built on honest monitoring
Every claim below maps to a capability the appliance ships with today.
Every interaction with an AI service, classified in real time.
Gatewarden sits inline behind your existing firewall and inspects what employees send to AI services (the prompt) as it happens, assigning each a Low, Medium, or High risk level.
We know what happened without storing what was said.
Raw prompt text is never stored. Only metadata and a plain-English classification reason are kept — content inspection runs on Gatewarden AI, an on-device model that never sends prompt text off the device.
If we miss something, we tell you.
Alerts fire on any monitoring degradation, not only on AI events. Every compliance report includes a Monitoring Health section so you know exactly how reliable your evidence trail is.
No endpoint agent on employee devices.
Monitoring happens at the network layer — there's no agent app to install. Tier 1 DNS/TCP detection needs nothing on the device; Tier 2 content inspection of browser and standard-app traffic requires a one-time per-device setup — installing the Gatewarden CA certificate and disabling the browser's DNS-over-HTTPS ('Secure DNS' in Chrome, 'DNS over HTTPS' in Firefox) — which you can push centrally via MDM/GPO (Intune, etc.). Cert-pinned native and mobile apps are still detected at Tier 1 (the AI service, device, and time), though their content isn't inspected.
The log IS the legal defense.
A tamper-evident, hash-chained audit log turns your AI-usage record into defensible evidence of good-faith monitoring and reasonable care.
How it works
Every interaction with an AI service, classified in real time
Gatewarden sits inline behind your existing firewall. AI service activity is detected and classified across three tiers — with no endpoint agent on devices, just a one-time per-device certificate and DNS setting.
< 1 ms
Tier 1 — DNS + TCP SYN detection
Fires whenever a device reaches a known AI service, regardless of whether content can be inspected. Detection happens even when TLS prevents reading the request.
Logs a Medium event
zero added latency
Tier 1.5 — Traffic-pattern analysis
Fingerprints connection behavior to recognize AI activity from how traffic moves, not just where it goes.
Strengthens detection confidence
asynchronous
Tier 2 — Content inspection via Gatewarden AI
Inspects the prompt with Gatewarden AI, the on-device model, and records a plain-English reason. The prompt text never leaves the device. If Gatewarden AI is unavailable or unsure, a configurable failure policy with a safe default applies, so the event is never silently passed as low-risk.
Produces High events when warranted
Capabilities
What the POC ships with
Shadow-AI discovery, an On-Patrol dashboard, a tamper-evident evidence trail, self-healing monitoring integrity, and immediate email alerting.
Shadow-AI discovery & coding-tool visibility
Surfaces AI usage employees may never report — including the tools that talk to provider APIs in the background.
The "On Patrol" dashboard
A single management view of monitoring health, AI activity, and the evidence log.
Tamper-evident evidence trail
An audit log built to stand up to scrutiny: any modification is detectable.
Self-healing & monitoring integrity
The product's core trust promise: silent monitoring gaps are unacceptable.
Immediate alerting (Observer Mode)
The right people are told the moment a High-risk AI interaction is logged.
Readable attribution
Logs a human can read, with the technical detail still intact.
Privacy & trust
We know what happened without storing what was said
- Raw prompt text is never stored on the device.
- Only metadata plus the Gatewarden AI classification reason are persisted — for example, “Prompt appeared to contain employee compensation data and PII.”
- Content inspection runs on Gatewarden AI on the device, so prompt text never leaves the device or your network.
Compliance
The log is the legal defense
- Gatewarden's compliance logic lives in policy packs. The core appliance is policy-agnostic — it knows only about risk levels, rules, events, and reports.
- A policy pack supplies the specific regulatory rules, the classification reasons, and the compliance-report mapping, so the same appliance can serve different regulatory frameworks over time.
- The first pack covers AI service governance and is built around Texas's TRAIGA (HB 149).
Ready to put your AI usage on the record?
Sigma Technical Group deploys and maintains Gatewarden as a managed appliance. Let’s talk about your network and deployment sizing.
Contact us