Logo RouteroAI
Governance

Policy routing.

Content checks, PII detection and masking, model access whitelists, budgets, and rate limits — governance rules configured per team and per key, effective on save, reviewable by your security team.

Content safetyPII detectionModel access whitelistSecret detection
Rules
Applied at organization, team, and key granularity
PII
Built-in recognizers: national IDs, phone numbers, bank cards
< 8ms
Guardrail check overhead, P50
0
Code changes needed to add a new rule

"Use Claude for legal, GPT for code,
open-source for PII…" — in if-else?

Every team eventually grows the same tangle: model picks scattered across services, hard-coded provider IDs in environment variables, security exceptions in commit messages. Adding a new model means a deploy. Adding a new rule means a meeting.

Governance rules pull those decisions back into one place — your security team configures and reviews them in the console, and your platform team ships without re-deploying the app.

Every class of risk, one rule.

Content

Content safety

Prompts and responses are checked for content violations; non-compliant requests are blocked before they reach a model. Enable per team and per key.

PII

PII detection & masking

Sensitive personal data — national IDs, phone numbers, bank cards — is identified before it leaves the gateway. Mask, block, or alert per rule.

Secrets

Secret detection

API keys, connection strings, and other credential patterns in prompts or responses are blocked automatically — corporate credentials never leak through a model.

Models

Model access whitelist

Restrict which models each key, team, or organization can call. Access groups turn "who can use which model" into one auditable config.

Budget

Budget enforcement

Soft thresholds alert at 80% (email / IM / on-call); hard caps block with a structured error and a reset time once exceeded.

Limits

RPM / TPM rate limits

Per-team and per-key limits on requests, tokens, and concurrency per minute — protecting downstream provider quotas and stopping runaway loops.

A governance config for a regulated team.

PII masking, credential-leak blocking, model whitelist, budgets, and rate limits — all attached to one team, effective on save.

# Team governance config · finance (illustrative) guardrails: - name: pii-mask # built-in recognizers: IDs / phones / bank cards action: mask # mask | block | alert - name: secret-detector # block keys & credentials in prompts / responses action: block model_access: team: finance: allowed_models: [internal/llama-4-maverick, gpt-5.4] budgets: team: finance: soft_budget: 120000 # alerts at 80% max_budget: 150000 # blocks above rate_limits: team: finance: rpm: 600 tpm: 2000000

Rules managed in one place —
not scattered through your codebase.

→ 01

Define

Define guardrails, model whitelists, and budgets in the console or config file — attached per team and per key.

→ 02

Review

Every config change is recorded in the audit log — who changed what, when it took effect, replayable at any time.

→ 03

Apply

Effective on save, no app redeploy. Rules run in the gateway on every request.

→ 04

Observe

Blocks and alerts are centrally queryable — which rule fired, which requests were stopped. Evidence for compliance reviews.

Validate your rules on real requests.

A 30-minute walkthrough with a solutions engineer — bring your provider list and we'll map it live.