KIONOVA® gateway. Decide, record, then execute.
One access point to all language models, with permissions, budgets and approvals per workplace. The flight recorder makes every step verifiable offline: evidence for the AI Act, DORA and GDPR.

A proxy between all workplaces and all language models.
Applications keep speaking their usual dialect. The gateway decides before every call, records the decision and then passes the request through byte for byte.
Both dialects
Anthropic dialect (for example Claude Code through a base URL) and OpenAI dialect (Cursor, SDKs, any software with a configurable base URL). Your own agents and automations assign runs through a header.
Virtual keys per workplace
Every workplace gets its own key, stored only as SHA-256, revocable per key and per workplace, with its own rate limit. The provider keys live in the vault and never leave it.
Decision engine: allow, ask, deny
Rules, model allowlist, data classes and token caps. Default is deny, the strictest rule wins. Every result names the rule and the policy hash. The record exists before a single byte reaches the provider.
Budget in micro-euros
Reservation before the call, exact settlement afterwards. Cost centers, warning thresholds, periods. When the budget is exhausted the call is rejected, not delayed.
Approvals by people
Requests with ask are held, owners are notified (Teams compatible) and decide with role and right. Approvals apply to one request or to one run.
Runs and subtasks
Every request is assigned to a run, subtasks appear under their parent. Tool calls and results are observed without altering the stream.
Three layers of protection. Verifiable offline, without the vendor.
The trail format is openly specified. Verifier and format library are public under MIT/Apache licenses. Auditors build them themselves and verify without seeing the commercial gateway code.
Changes are detected
Every entry hashes its predecessor and its own content including the time. A change anywhere breaks the chain from that point.
Recomputation is detected
The chain head is regularly recorded with an RFC 3161 timestamp service and in a WORM sink. Anyone who recomputes everything is caught at the anchor. Qualified under eIDAS for finance and GxP.
A single job is proven
Merkle root over the entries of a run, signed with Ed25519. Proves a single job without disclosing the rest of the trail.
| Export | What was changed | Result |
|---|---|---|
| Unchanged | nothing | 0 findings, chain intact. Note: entries after the last anchor are not yet anchored. |
| Content tampered | "denied" rewritten to "allowed" in one entry | 1 finding: content at that entry, run receipt no longer matches. |
| Recomputed | the same, with all hashes recomputed from there | 1 finding: anchor does not match, run receipt does not match. |
What only a gateway with a flight recorder can deliver.
Developer teams with Claude Code, Cursor and SDKs
One virtual key per workplace, one budget per team. No provider key leaves the vault. Setup at the workplace: one base URL and one key.
Evidence: consumption per workplace and team in the admin console, reconciled with the provider invoice.
Confidential data stays local
The data class "strict" automatically routes to the model inside your own network or in the BrainQubes data center. Plain text never reaches an external provider.
Evidence: rule ID and target provider are recorded with every entry in the trail.
Audit and regulation
Banks, insurers, GxP environments: export one day or one job, the verifier runs offline at the auditor. Timestamps qualified under eIDAS, WORM anchors against recomputation.
Evidence: auditable evidence for the AI Act, DORA and GDPR, not just an assurance.
Approval of sensitive requests
An ask rule holds the request. Owners receive a message and decide with role and right. The decision is recorded in the trail together with the rule.
Evidence: who approved or rejected what and when, for every run.
Cost control per workplace and cost center
Settlement in micro-euros. The reservation before the call prevents overspending, even with many parallel requests. Reconciliation with the provider invoice finds foreign calls.
Evidence: sum of settlements equals consumption, per period.
Agents and automations
n8n, your own agents, nightly jobs: every run with its subtasks is traceable. The run receipt is the signed proof per job. Idle time closes the run automatically.
Evidence: one receipt per job, independently verifiable.
Controlling tools (MCP)
A forbidden tool call is rejected and recorded before execution. A permitted one runs in the sandbox. Observed and enforced appear as a pair.
Evidence: an "enforced" entry with tool, rule and result.
Data protection with probative value
Contents are not stored by default, only metadata and hashes. Optionally encrypted storage with a run key and deletion by destroying the key. Pseudonyms, disclosure only under the four-eyes principle.
Evidence: the chain stays intact, the content is gone.
The guiding principle: decide, record, then execute.
Request
The workplace sends its request with the virtual key.
Ingress
TLS, size limit, rate per key. Unknown or revoked: rejection and record.
Assign run
By header, otherwise traceparent, otherwise fingerprint. A new run creates the "job" entry.
Decision engine
Model allowed? Data class matches the provider? Token cap? Does a rule require a human check?
Budget
Reserve a conservative estimate. If the budget is insufficient, the call is rejected.
Record first
Reservation and record in one transaction, before a single byte reaches the provider.
Pass through
Same path at the provider, body byte for byte, provider key from the vault.
Observe
Every chunk goes to the client immediately and in parallel into the decoder. Nothing is buffered.
Settlement
Tokens, cost, duration, provider ID, model version. Release the reservation.
Abort
If the client closes, the gateway aborts the provider call and settles what it has seen.
Run receipt
When the run ends, the signed receipt is created.
Anchor
Every 15 minutes or 1,000 entries the chain head is anchored.
Eight rules written into the code.
The server decides on approvals
Never the client, never the model.
Provider keys never in log, trail or export
They live encrypted in the vault.
The record exists before the call leaves the gateway
Write first, then execute.
Administration and proxy are separated
Own port, own login, every change in the trail.
Provider errors pass unchanged
Nothing is reshaped or hidden.
Contents are not stored by default
Only metadata and hashes, contents only on request and encrypted.
Virtual keys only as SHA-256
The plain text is shown exactly once.
Outputs are not instructions
Model responses do not steer the gateway.
Foundation: proven building blocks from sepp mini (policy core, provider wiring, signatures), included as a dependency. Format and verifier are open, the gateway is commercial.

Compute from Europe, controlled all the way to the workplace.
KIONOVA gateway is part of the joint solution with BrainQubes. We will show you a call, its trail and the verification.