Technical
An API proxy. Not an agent.
How it works
The architecture is deliberately straightforward. Applications — internal tools, third-party software, or direct browser interactions — route AI API traffic through CattleGrid before it reaches the provider. No changes are required to those applications. No software is installed on user machines. The intervention happens at the network layer, not the endpoint.
Intercept
Request received - Every outbound AI API call is routed through the CattleGrid gateway before reaching any external provider.
Inspect
Policy applied - Content is scanned in memory against your data classification rules — PII, financial data, trade secrets, custom-defined terms.
Pass
Clean request proceeds - No policy match. The request continues to the AI provider unmodified, in the same round trip.
Block, Redact, or Flag
Policy match found - Depending on the rule: the request is stopped before it leaves CattleGrid, the matched content is redacted and the request continues, or the request proceeds with an alert logged for review — whichever your policy specifies.
Beyond the Prompt — Opt-In Modules
The core gateway above is always-on and covers every customer by default. Two further capabilities are available as named, separately-scoped additions — each with its own retention posture, described here rather than folded into the core claim above.
File Upload & Document Inspection.
The same block/redact/flag policy engine applied to file uploads, not just typed prompts. Covers PDF, Word (.doc/.docx), Excel (.xlsx), OpenDocument Text (.odt), and RTF. The file is extracted, inspected, and discarded — never stored, never written to disk.
Same zero-retention posture as prompt inspection, just applied to a wider surface.
Reversible Tokenisation.
For organisations that need to preserve utility — a customer reference number an AI needs to reason about, for instance — without exposing the real value. Identifiers are swapped for tokens before the request leaves CattleGrid; the AI provider only ever sees the token.
On the way back, real values are restored from an in-memory map that exists for that single round trip only, then destroyed — no persistent key, nothing to store or escrow.
This is precise pseudonymisation under UK GDPR Article 4(5): your organisation remains controller of the data throughout, and CattleGrid never holds a re-identification key you didn't already have.
Technical Specification
Gateway latency
< 50ms. Inspection overhead per request under typical operating conditions.
Architecture type
API proxy gateway. Network-level interception. No endpoint agents. No application modification required.
Data retention
Zero. Inspected content exists in memory only. Nothing is written to disc. Sensitive fragments from blocked requests are never stored.
Deployment model
SaaS, with custom on-premises deployment available for organisations with air-gap or data-residency needs the SaaS model doesn't meet. On-premises is a bespoke engagement — scoped and priced individually, not a standard tier.
Jurisdiction
UK company. UK infrastructure. Not subject to the US CLOUD Act. Data never touches US jurisdiction.
Tenant isolation
Complete. Each organisation's configuration, rules, and audit data are fully isolated. No shared data plane between customers.
Audit trail
Every request is logged: who sent it, when, which rules were evaluated, and what action was taken. Sensitive content is never stored in full — the log captures the event, not the data. Tamper-evident by design: audit records are cryptographically chained and signed, not just timestamped. Exportable as evidence toward ISO/IEC 27001:2022 Annex A controls. Real-time dashboards and alert integrations — email, Slack, and existing SIEM infrastructure — available out of the box.
Deployment
The integration touchpoints are intentionally limited. CattleGrid connects to your existing AI provider API credentials and becomes the routing endpoint for your applications. Nothing changes downstream. No existing applications need to be rebuilt or reconfigured beyond pointing their API calls to the gateway..
Getting started
Hosted on European infrastructure
1. Connect your AI provider API credentials to CattleGrid.
2. Enable pre-built detection rules or define your own.
3. Point your applications to the CattleGrid gateway endpoint.
4. Verify via the test interface. Go live.
On-premises - custom engagement
Within your own infrastructure
For organisations with air-gap requirements, data residency obligations, or security architecture that requires internal deployment. Scoped and priced individually — not part of standard tiers.
1. Deploy within your existing network boundary.
2. Configure against your internal security policies.
3. Integrate with existing SIEM and alerting infrastructure.
4. No outbound data. Audit logs remain on-premises.
Provider Compatibility
CattleGrid is not tied to a single AI provider. It operates across the platforms UK enterprise AI workloads actually run on today.
OpenAI (direct)
Direct API access. Consumer and enterprise tiers.
Anthropic (direct)
Claude API. Direct integration.
Google Gemini (direct)
Direct API access to Google's model family.
Mistral AI (direct)
European-domiciled provider, of particular relevance for EU data sovereignty requirements.
Plus any OpenAI-compatible API.
If your provider exposes a standard OpenAI-compatible endpoint, CattleGrid covers it without custom integration work.
Data Handling
Inspected content exists in memory only, processed in milliseconds, then gone. Nothing is written to disc. Sensitive fragments from blocked requests are never stored in full. The audit log records the event — who, when, which rule, what action — without preserving the data that triggered it.
Credentials, encrypted at rest
API credentials connecting to AI providers are encrypted at rest using AES-256-GCM. They are never exposed in logs or audit exports.
Tenant isolation, complete
Each organisation's data — configuration, rules, audit logs — is fully isolated. There is no shared data plane between customers.
No US jurisdiction
CattleGrid is a UK company operating on UK infrastructure. Not subject to the US CLOUD Act. For regulated sectors with client data obligations, this is not a minor detail.
Audit exports, compliance-ready
Logs are exportable in formats suitable as evidence toward ISO/IEC 27001:2022 Annex A controls and UK GDPR governance obligations. Pre-built templates for common regulatory frameworks are included.
Access Model
CattleGrid is role-based. The people who need visibility get it; the people who need to act can act; and the people who just need to use AI tools encounter nothing different at all.
End users
Nothing, ordinarily. AI tools continue to function as normal. When a request is blocked, the user receives a clear notification explaining why. No software to install. No training required beyond awareness of the policy.
Administrators
Configure detection rules via the visual dashboard. Define what categories of data are governed and how. Manage team access and permissions. All administrative actions are logged.
Security teams
Real-time dashboard visibility across the organisation's AI usage. Immediate alerts on policy violations — via dashboard notification, email, or Slack. Integration with existing SIEM infrastructure. Full audit trail for incident investigation.
Compliance officers
Exportable reports for regulatory audits. Demonstration of data protection controls in operation. Pre-built templates for UK GDPR governance evidence. Configurable data retention policies.