Enterprise module · exclusively within the BrainQubes partnership

KIONOVA® gateway. Decide, record, then execute.

One access point to all language models, with permissions, budgets and approvals per workplace. The flight recorder makes every step verifiable offline: evidence for the AI Act, DORA and GDPR.

Available With BrainQubes
What the gateway is

A proxy between all workplaces and all language models.

Applications keep speaking their usual dialect. The gateway decides before every call, records the decision and then passes the request through byte for byte.

API

Both dialects

Anthropic dialect (for example Claude Code through a base URL) and OpenAI dialect (Cursor, SDKs, any software with a configurable base URL). Your own agents and automations assign runs through a header.

KEY

Virtual keys per workplace

Every workplace gets its own key, stored only as SHA-256, revocable per key and per workplace, with its own rate limit. The provider keys live in the vault and never leave it.

A·F·D

Decision engine: allow, ask, deny

Rules, model allowlist, data classes and token caps. Default is deny, the strictest rule wins. Every result names the rule and the policy hash. The record exists before a single byte reaches the provider.

BUD

Budget in micro-euros

Reservation before the call, exact settlement afterwards. Cost centers, warning thresholds, periods. When the budget is exhausted the call is rejected, not delayed.

OK

Approvals by people

Requests with ask are held, owners are notified (Teams compatible) and decide with role and right. Approvals apply to one request or to one run.

LOG

Runs and subtasks

Every request is assigned to a run, subtasks appear under their parent. Tool calls and results are observed without altering the stream.

The flight recorder

Three layers of protection. Verifiable offline, without the vendor.

The trail format is openly specified. Verifier and format library are public under MIT/Apache licenses. Auditors build them themselves and verify without seeing the commercial gateway code.

1 · Chain

Changes are detected

Every entry hashes its predecessor and its own content including the time. A change anywhere breaks the chain from that point.

2 · Anchor

Recomputation is detected

The chain head is regularly recorded with an RFC 3161 timestamp service and in a WORM sink. Anyone who recomputes everything is caught at the anchor. Qualified under eIDAS for finance and GxP.

3 · Run receipt

A single job is proven

Merkle root over the entries of a run, signed with Ed25519. Proves a single job without disclosing the rest of the trail.

What the open verifier reports for the sample exports.
ExportWhat was changedResult
Unchangednothing0 findings, chain intact. Note: entries after the last anchor are not yet anchored.
Content tampered"denied" rewritten to "allowed" in one entry1 finding: content at that entry, run receipt no longer matches.
Recomputedthe same, with all hashes recomputed from there1 finding: anchor does not match, run receipt does not match.
Eight use cases

What only a gateway with a flight recorder can deliver.

Developer teams with Claude Code, Cursor and SDKs

One virtual key per workplace, one budget per team. No provider key leaves the vault. Setup at the workplace: one base URL and one key.

Evidence: consumption per workplace and team in the admin console, reconciled with the provider invoice.

Confidential data stays local

The data class "strict" automatically routes to the model inside your own network or in the BrainQubes data center. Plain text never reaches an external provider.

Evidence: rule ID and target provider are recorded with every entry in the trail.

Audit and regulation

Banks, insurers, GxP environments: export one day or one job, the verifier runs offline at the auditor. Timestamps qualified under eIDAS, WORM anchors against recomputation.

Evidence: auditable evidence for the AI Act, DORA and GDPR, not just an assurance.

Approval of sensitive requests

An ask rule holds the request. Owners receive a message and decide with role and right. The decision is recorded in the trail together with the rule.

Evidence: who approved or rejected what and when, for every run.

Cost control per workplace and cost center

Settlement in micro-euros. The reservation before the call prevents overspending, even with many parallel requests. Reconciliation with the provider invoice finds foreign calls.

Evidence: sum of settlements equals consumption, per period.

Agents and automations

n8n, your own agents, nightly jobs: every run with its subtasks is traceable. The run receipt is the signed proof per job. Idle time closes the run automatically.

Evidence: one receipt per job, independently verifiable.

Controlling tools (MCP)

A forbidden tool call is rejected and recorded before execution. A permitted one runs in the sandbox. Observed and enforced appear as a pair.

Evidence: an "enforced" entry with tool, rule and result.

Data protection with probative value

Contents are not stored by default, only metadata and hashes. Optionally encrypted storage with a run key and deletion by destroying the key. Pseudonyms, disclosure only under the four-eyes principle.

Evidence: the chain stays intact, the content is gone.

One model call, step by step

The guiding principle: decide, record, then execute.

  1. Request

    The workplace sends its request with the virtual key.

  2. Ingress

    TLS, size limit, rate per key. Unknown or revoked: rejection and record.

  3. Assign run

    By header, otherwise traceparent, otherwise fingerprint. A new run creates the "job" entry.

  4. Decision engine

    Model allowed? Data class matches the provider? Token cap? Does a rule require a human check?

  5. Budget

    Reserve a conservative estimate. If the budget is insufficient, the call is rejected.

  6. Record first

    Reservation and record in one transaction, before a single byte reaches the provider.

  1. Pass through

    Same path at the provider, body byte for byte, provider key from the vault.

  2. Observe

    Every chunk goes to the client immediately and in parallel into the decoder. Nothing is buffered.

  3. Settlement

    Tokens, cost, duration, provider ID, model version. Release the reservation.

  4. Abort

    If the client closes, the gateway aborts the provider call and settles what it has seen.

  5. Run receipt

    When the run ends, the signed receipt is created.

  6. Anchor

    Every 15 minutes or 1,000 entries the chain head is anchored.

Security rules

Eight rules written into the code.

The server decides on approvals

Never the client, never the model.

Provider keys never in log, trail or export

They live encrypted in the vault.

The record exists before the call leaves the gateway

Write first, then execute.

Administration and proxy are separated

Own port, own login, every change in the trail.

Provider errors pass unchanged

Nothing is reshaped or hidden.

Contents are not stored by default

Only metadata and hashes, contents only on request and encrypted.

Virtual keys only as SHA-256

The plain text is shown exactly once.

Outputs are not instructions

Model responses do not steer the gateway.

Foundation: proven building blocks from sepp mini (policy core, provider wiring, signatures), included as a dependency. Format and verifier are open, the gateway is commercial.

Compute from Europe, controlled all the way to the workplace.

KIONOVA gateway is part of the joint solution with BrainQubes. We will show you a call, its trail and the verification.