AI Security

Decide what reaches a model. Before it leaves.

Classic DLP was built for files leaving the network. A prompt is an authorised request to an authorised service, with the data in the body. MERIDVAR inspects that request on your network and can refuse it.

Admission control

A gateway that is allowed to say no.

Seventeen checks run on every routed request. If one refuses, the request does not reach the provider. Nothing is sent. The refusal is recorded, with the reason.

  • Refusal means zero calls. Tested against a provider that logs every request it receives.
  • The whole request is read. Prose, content blocks, system messages, tool call arguments and tool results.
  • Findings are masked. A raw identifier is never stored.
ADMISSION GATEWAY · YOUR NETWORKNO VENDOR CLOUD
How MERIDVAR controls an AI requestRequests from people, applications, agents and MCP servers pass through the MERIDVAR admission gateway on the customer network. An admitted request reaches the model provider. A refused request stops at the gateway and the provider is never contacted. Every decision is written to a hash chained evidence log.CUSTOMER INFRASTRUCTUREMODEL PROVIDERSPeopleApplicationsAI agentsMCP serversMERIDVARSeventeen stage admission pipelineidentityPASSshadow-aiPASSprompt-dlpREFUSEthreatSKIPPEDresidencySKIPPEDvendor-riskSKIPPEDbudgetSKIPPED+ 10 MORE STAGESAnthropicOpenAIAzure OpenAIxAIADMITTED: ONE CALLREFUSED: ZERO CALLSGOVERNANCE EVIDENCE LOG · APPEND ONLY · HASH CHAINEDCLASSIFIED9f2c…a71eREVIEWEDa71e…03bdAPPROVED03bd…c45aREFUSEDc45a…e210Every decision names who made it, when and on what basis.
Illustration of documented behaviour. A refused request never contacts the model provider.

Controls

Policy you edit in the console, enforced by the same records.

Shadow AI discovery

Sanctioned providers, and a mode of off, observe or enforce. Upload proxy or DNS logs to see services that never touched the gateway.

Prompt DLP

Ten categories of structured identifiers, including national identification numbers, payment cards, email addresses, phone numbers, keys and tokens. Each set to block, redact or allow with logging.

Threat detection

A threat detection policy applied by severity at the gateway.

Data residency

Declared regions and policies per team. Fails closed when the region is unknown.

Vendor risk requirements

Data processing agreements, assessment age and training on customer data, enforced at the call.

Identity at the gate

A bearer token from your identity provider can be required for admission. Each monitored person has a token that can be rotated and revoked.

Agent identity

Agents sign requests with Ed25519 keys, so a machine caller proves possession of a registered key.

MCP inventory

MCP servers and their tools declared and risk rated. A tool that can delete or run commands raises the risk of every AI system linked to it.

Endpoint agents

Installers for Linux, macOS and Windows detect local AI tools and report presence. Presence can be required for admission.

Security records

Every refusal leaves a trail you can check.

  • Findings from every scan, with masked samples.
  • An audit trail with a hash per entry chained to the one before, and a button to verify it has not been altered.
  • Log shipping to a webhook you control, and Prometheus metrics.
  • Sign in lockout after repeated failed attempts, per account and per address.

How it fits

Precise by design. Built to sit beside the stack you have.

Deterministic detection

Prompt DLP is rules based and matches structured identifiers. The same request always gives the same decision, and every refusal names the rule behind it.

Enforcement where traffic is routed

Controls apply to requests that pass through the gateway. Uploaded logs, endpoint agents and declarations extend visibility to the rest.

Cryptographic agent identity

A machine caller signs with a registered Ed25519 key, so every agent request is attributable to a known identity.

Complements EDR and SSE

MERIDVAR adds AI specific admission control and governance at the point of the request, alongside your endpoint and network security.

Watch a request get refused. On your own network.

A working session with the founder. We install the appliance with you, route a test request and walk through the evidence it leaves behind.