Secure
Stop sensitive data, secrets and attacks before they reach a model, and scan what comes back.
- PII: monitor, redact, tokenise or block
- Secrets and credential detection
- Prompt-injection detection
- Response DLP scanning
LyfeAI Firewall sits between your people, your apps and AI providers. It protects sensitive data, cuts waste and gives you control, without rewriting a line of application code.
Illustrative mock-up with placeholder values. Not real customer data.
Staff paste client files into chat tools. Developers embed provider keys in code. Bills arrive with no owner. Each model and vendor has its own rules, or none.
Route all AI traffic through LyfeAI Firewall. Apps use a gateway key against one familiar API. The firewall enforces policy, optimises the request and records what happened.
Everything the gateway does falls into one of three jobs.
Stop sensitive data, secrets and attacks before they reach a model, and scan what comes back.
Spend less per answer and stay up when providers do not.
Know who uses which model, for what, and at what cost.
Each capability is a switch. Turn on what you need, monitor before you enforce.
OpenAI-compatible and Anthropic-compatible, across providers.
Per-app keys, model permissions, budgets and rate limits.
Detect Medicare, TFN, ABN, licence and passport numbers.
Catch API keys, tokens and passwords before they leave.
Flag and stop instruction-override attempts.
Scan what comes back, not just what goes out.
Trim wasted tokens without changing meaning.
Exact caching by default. Semantic caching is opt-in.
Right model for the task, with a reason you can read.
Keep working when a provider does not.
See cost by app, team, user, model and provider.
A record you can stand behind, and export.
Start from a preset. Every control is on or off.
Admin console sign-in with your existing identities.
Every request passes through the same checks, in the same order, whichever model it is bound for.
Any OpenAI or Anthropic SDK, with a gateway key instead of a provider key.
Key, team, model permissions, budget and rate limit are checked first.
PII, secrets and prompt-injection checks run. Content is redacted, tokenised, blocked or just monitored.
Safe prompt clean-up, cache lookup, then the best model for the job, with failover ready.
The gateway holds the provider keys. Your apps never do.
Response DLP runs, tokens are restored, and spend and audit records are written.
Keep patient identifiers such as Medicare numbers out of prompts while clinicians and admin staff get the benefit of AI.
Healthcare presetTokenise account and tax identifiers, cap spend by desk, and keep an audit trail for review.
Finance presetEnforce approved models only, with strict blocking and region controls for sensitive information.
Government presetProtect client confidences, restrict models per matter team and record every use.
High Security presetGive staff and students safe access with budgets per faculty and guard rails on personal data.
Default presetHandle TFNs and ABNs safely, with usage attributed to clients and teams for recharging.
Finance presetPresets are starting points. They support, but do not by themselves ensure, your compliance obligations.
Use the official OpenAI SDK as you do now. Point it at the gateway and use a gateway key. Anthropic-style clients can use the same gateway.
from openai import OpenAI
client = OpenAI(
base_url="https://llmfw.peritusdigital.com.au/v1",
api_key="sk-your-gateway-key", # a gateway key, not a provider key
)
resp = client.chat.completions.create(
model="gpt-4o",
messages=[{"role": "user", "content": "Summarise this client file"}],
)
print(resp.choices[0].message.content)Almost never. LyfeAI Firewall speaks the OpenAI and Anthropic APIs. In most cases you change the base URL and swap your provider key for a gateway key.
OpenAI, Anthropic, Azure AI Foundry, AWS Bedrock, Google Gemini, Mistral and self-hosted models, all behind one endpoint. Your administrator chooses which are enabled.
You choose per policy: monitor it, redact it, replace it with a reversible token that is restored in the response, or block the request. Australian identifiers such as Medicare, TFN, ABN, driver licence and passport numbers are covered.
No. Provider keys live inside the gateway. Applications get gateway keys that you can limit, budget and revoke.
No. Optimisation is limited to safe changes such as whitespace, JSON compaction and duplicated context, and you can see the before and after token counts. It does not remove punctuation blindly.
No. Exact caching is available by default and semantic caching is opt-in, because similar is not the same as identical.
No. It is a control layer that helps you enforce policy and gain visibility. Detection is probabilistic, so test it against your own data and keep your other safeguards.
Plans are Starter, Business and Enterprise. Pricing depends on your usage and requirements, so please contact us for a quote. Prices are quoted in AUD ex-GST.
Request access and we will help you set up your first policy, key and budget.