Skip to main content
TrustGate is a gateway your applications call instead of calling model providers and MCP servers directly. The provider keys stay in the gateway, the rules are applied there, and every call leaves a trace there. An application keeps speaking the API it already speaks; only the URL changes. Before-and-after diagram showing separate controls in each application consolidated into TrustGate, which applies shared controls and routes several applications to multiple LLMs.

What happens to a request

  1. Authenticate. The caller proves which application it is — with the application’s API key, or a token from an identity provider you trust.
  2. Apply policies. Every policy whose scope covers this application runs: rate limits, budgets, prompt changes, guardrails. A policy in Enforce mode can refuse the call here.
  3. Route. The gateway picks a registry entry — a model provider or an MCP server — using the application’s routing, and calls it with that entry’s credential. The application never holds the provider key.
  4. Record. The call, its decision, its cost and its latency become a trace in Activity, and roll up in Analytics.

What you operate

Five objects, each answering one question.

Two planes

One gateway serves both. An application can use either or both.

LLM Gateway

Fourteen providers behind one API. Route by cost, by load, or by how hard the prompt is. Chat, embeddings, images, audio, files, rerank.

MCP Gateway

One endpoint in front of every MCP server. Each person as themselves upstream, an Employee portal people install from, and any OpenAPI document as tools.

What you see

Every request is a trace in Activity: who called, what policy decided, which provider answered, what it cost, how long it took. Analytics aggregates the same data by application, model and time. A chat front-end that serves many people behind one key can name the person on each request — see End-user attribution.

Where it runs

SaaS hosts everything. Private keeps the data plane — and every prompt — inside your network while the console still manages it. The choice is made per gateway, at creation. Deployment covers running a private plane.

Start

Quickstart

A gateway, a provider, a request and its trace, in a few minutes.

Integrations

Claude Code, Cursor, Codex, Copilot, LangChain, and the rest.