Security & Trust

Security and trust start with the boundary

Infegate centralises policy, identity, destination and evidence at the point where an AI request crosses between applications and models.

Control register

Shipped

Default-deny routing

A workload leaves only when policy explicitly permits a destination.

Shipped

Per-key attribution

Consumer metadata identifies the caller in the audit record.

Shipped

Selectable body logging

Each consumer can retain full bodies or record metadata only, according to its policy.

Shipped

Offline operation

Installation and licence validation do not require an outbound control-plane call.

Planned

Turkish PII enforcement

Detection and redaction are planned. No shipping claim is made for them.

Data processing by deployment

Self-hosted Infegate runs inside the customer environment and does not send prompts to DemirTech. Public routes send only the traffic that policy permits to the selected provider. Managed Infegate makes DemirTech a processor and is limited accordingly.

Vendor identity

Infegate is developed and operated by DemirTech. DemirTech is the product owner and operator brand, but is not yet an incorporated legal entity. The site does not present corporate identifiers that do not exist.

Report a security issue

Send security reports to info@infegate.com. Do not include live credentials or regulated production data in the first message.