Skip to content
AI Gatewarden emblemAI Gatewarden

How it works

Every interaction with an AI service, classified in real time

AI Gatewarden sits inline behind your existing firewall. Traffic from devices on the network routes through the appliance, where AI service activity is detected and classified — with no endpoint agent on employee devices, just a one-time per-device certificate and DNS setting.

Gatewarden inspects traffic inline as it leaves your network. When a device reaches an AI service, the appliance recognizes it and records the interaction, then classifies the risk it represents.

Detection works in two stages. First, network-layer signals fire the moment a device contacts a known AI service — even when the content of the request can’t be read. Then, where content inspection is available, Gatewarden AI inspects the prompt and records a plain-English reason for the rating it assigns.

Every interaction is scored

LOWMEDIUMHIGH

Risk levels drive the dashboard, alerting, and the compliance report.

Classification

Three-tier detection

Layered detection means AI service access is caught even when a prompt can't be inspected.

< 1 ms

Tier 1 — DNS + TCP SYN detection

Fires whenever a device reaches a known AI service, regardless of whether content can be inspected. Detection happens even when TLS prevents reading the request.

Logs a Medium event

zero added latency

Tier 1.5 — Traffic-pattern analysis

Fingerprints connection behavior to recognize AI activity from how traffic moves, not just where it goes.

Strengthens detection confidence

asynchronous

Tier 2 — Content inspection via Gatewarden AI

Inspects the prompt with Gatewarden AI, the on-device model, and records a plain-English reason. The prompt text never leaves the device. If Gatewarden AI is unavailable or unsure, a configurable failure policy with a safe default applies, so the event is never silently passed as low-risk.

Produces High events when warranted

Network inspection

Built like an enterprise SSL-inspection appliance

Transparent HTTPS inspection via a trusted CA certificate — the same model used by Zscaler, Netskope, and Palo Alto.

  • AI service detection across 17 domains / domain groups covering all major AI providers.
  • ECH, DoH, and DoT suppression prevents browsers from bypassing network-layer inspection.
  • QUIC (HTTP/3) is blocked to force inspectable TCP HTTPS.
  • IPv6 forwarding is blocked on the monitored segment to force IPv4, consistent with standard SSL-inspection appliances.
  • WebSocket inspection captures prompts sent to streaming / real-time AI services.

Deployment footprint

No endpoint agent — a one-time per-device setup

Tier 1 DNS/TCP detection needs nothing on the device. Tier 2 content inspection of browser and standard-app traffic requires a one-time per-device setup — installing the Gatewarden CA certificate and disabling the browser's DNS-over-HTTPS ('Secure DNS') — deployable centrally via MDM/GPO. Cert-pinned native and mobile apps are still detected at Tier 1, though their content isn't inspected.

  • Monitors all AI service activity from devices whose traffic routes through the appliance — including remote employees on a corporate VPN back to the network.
  • Fresh devices are intercepted immediately; existing devices with cached TLS state are fully intercepting within 24 hours as self-healing completes.
  • Covers all major AI services. Cert-pinned native and mobile apps aren't content-inspected by the certificate, but they're still detected at Tier 1 (the AI service, device, and time).