How it works
Every interaction with an AI service, classified in real time
AI Gatewarden sits inline behind your existing firewall. Traffic from devices on the network routes through the appliance, where AI service activity is detected and classified — with no endpoint agent on employee devices, just a one-time per-device certificate and DNS setting.
Gatewarden inspects traffic inline as it leaves your network. When a device reaches an AI service, the appliance recognizes it and records the interaction, then classifies the risk it represents.
Detection works in two stages. First, network-layer signals fire the moment a device contacts a known AI service — even when the content of the request can’t be read. Then, where content inspection is available, Gatewarden AI inspects the prompt and records a plain-English reason for the rating it assigns.
Every interaction is scored
Risk levels drive the dashboard, alerting, and the compliance report.
Classification
Three-tier detection
Layered detection means AI service access is caught even when a prompt can't be inspected.
< 1 ms
Tier 1 — DNS + TCP SYN detection
Fires whenever a device reaches a known AI service, regardless of whether content can be inspected. Detection happens even when TLS prevents reading the request.
Logs a Medium event
zero added latency
Tier 1.5 — Traffic-pattern analysis
Fingerprints connection behavior to recognize AI activity from how traffic moves, not just where it goes.
Strengthens detection confidence
asynchronous
Tier 2 — Content inspection via Gatewarden AI
Inspects the prompt with Gatewarden AI, the on-device model, and records a plain-English reason. The prompt text never leaves the device. If Gatewarden AI is unavailable or unsure, a configurable failure policy with a safe default applies, so the event is never silently passed as low-risk.
Produces High events when warranted
Network inspection
Built like an enterprise SSL-inspection appliance
Transparent HTTPS inspection via a trusted CA certificate — the same model used by Zscaler, Netskope, and Palo Alto.
- AI service detection across 17 domains / domain groups covering all major AI providers.
- ECH, DoH, and DoT suppression prevents browsers from bypassing network-layer inspection.
- QUIC (HTTP/3) is blocked to force inspectable TCP HTTPS.
- IPv6 forwarding is blocked on the monitored segment to force IPv4, consistent with standard SSL-inspection appliances.
- WebSocket inspection captures prompts sent to streaming / real-time AI services.
Deployment footprint
No endpoint agent — a one-time per-device setup
Tier 1 DNS/TCP detection needs nothing on the device. Tier 2 content inspection of browser and standard-app traffic requires a one-time per-device setup — installing the Gatewarden CA certificate and disabling the browser's DNS-over-HTTPS ('Secure DNS') — deployable centrally via MDM/GPO. Cert-pinned native and mobile apps are still detected at Tier 1, though their content isn't inspected.
- Monitors all AI service activity from devices whose traffic routes through the appliance — including remote employees on a corporate VPN back to the network.
- Fresh devices are intercepted immediately; existing devices with cached TLS state are fully intercepting within 24 hours as self-healing completes.
- Covers all major AI services. Cert-pinned native and mobile apps aren't content-inspected by the certificate, but they're still detected at Tier 1 (the AI service, device, and time).