Enterprise AI control plane

Every AI request.One governed route.

Hormuz sits between the AI tools your teams already use and the model providers you already buy—enforcing policy, protecting credentials, and producing evidence for every governed request.

Works with existing clientsCodexClaude CodeOpenAI + Anthropic
Illustrative policy decision

Request hmx_4f81

Live
Actoralice@engineering
Clientcodex
Modelgpt-5.5
1
IdentityVerified
2
PolicyMatched
3
DLPClear
4
BudgetReserved
DecisionForward to provider
18 ms
Prompt retained0 bytes
Policy versionhpv_v1_8ab…
EvidenceRecorded
PROVIDER-NEUTRALBRING YOUR OWN KEYSCONTENT-FREE EVIDENCEFAIL-CLOSED CONTROLS

Your AI stack already has models. It needs a governed route.

Teams adopt AI one client and one provider at a time. Access fragments. Provider keys spread. Policy becomes a document instead of an enforcement point.

Hormuz turns the request path itself into the control plane—without asking employees to abandon the tools that make them productive.

Employee tools

C
CodexOpenAI protocol
C
Claude CodeAnthropic protocol
CONTROL PLANE

Hormuz

IdentityPolicyDLPBudgets

Model providers

OpenAICompany account
AnthropicCompany account
Content-free evidence
IdentityAttributed
PolicyVersion-pinned
UsageMeasured
CostEstimated + reconciled
PayloadNot retained

Control that travels with every request.

A single enforcement boundary for who can use AI, what they can access, what may leave, and how the organization proves it later.

01Fail closed

Policy that only gets tighter

Layer organization, team, and person rules without letting a lower scope weaken the controls above it.

02BYOK custody

Provider keys stay put

Employees authenticate to Hormuz. Company provider credentials remain on the controlled server boundary.

03Pre-provider

Budgets before egress

Check model access, token ceilings, and spend allowances before a request reaches a provider.

04Exact-request approval

DLP with a human path

Detect, redact, deny, or require a bounded approval—without turning routine evidence into a content archive.

05OIDC + sessions

Identity you can revoke

Map existing OIDC identities into short-lived Hormuz sessions with scoped administrative control.

06Content-free

Evidence without the payload

Attribute governed usage, cost, policy version, and security outcomes while keeping prompts and responses out of the ledger.

Hormuz governs AI traffic. It does not pretend to be everything else.

The product owns the runtime gateway and its evidence. Document ingestion, knowledge quality, memory lifecycle, and accounting remain separate systems with separate responsibilities.

Narrow enough to trust.
Strong enough to enforce.
Hormuz ownsThe enforced question
Identity & accessWho is making the request and which controls apply
Policy & budgetsWhich models, limits, and spend envelopes are allowed
Egress controlsWhat may leave the organization and when approval is required
EvidenceWhat happened, under which policy, without retaining the conversation
Current stageAlpha · executable proof

Proof is not production readiness.

Hormuz has executable evidence for its gateway control path. High availability, deployment-specific custody and recovery, external review, and customer-environment certification remain explicit release gates—not marketing footnotes.

Inspect the public evidence

Find the gaps in your AI control path.

Map one real workflow across identity, provider credentials, policy, egress, budgets, and evidence. Leave with a concrete control plan—whether or not Hormuz is the right next step.

Book an AI Governance ReviewFounder-led · 45 minutes · No generic demo