Compliance control plane for AI

Every AI request,
accounted for.

SignalVault sits between your application and the model provider. It records each prompt and response, removes sensitive data before it leaves, and keeps an audit trail you can hand to anyone who asks.

v0.13.3 Starter Environments & Integration Fixes →
EncryptionAES-256-GCM at rest
CompatibilityOpenAI-compatible APIs
Added latencyNone in mirror mode
Operated fromStockholm, Sweden
production-api Live · last 30 days
Export CSV Export JSON
Requests
1,247
Violation rate
2.4%
Cost
$48.32
Top violation
PII detected · 18
14:23:08 Summarize the customer feedback from the Q4 report gpt-6-astra 1,204 allowed
14:22:51 Update the account for John, SSN 423-91-8812 gpt-6-astra 342 blocked
14:22:34 Generate a marketing email for the spring launch claude-sonnet-5 2,891 allowed
14:21:12 Analyze user metrics for account acct_38… gpt-6-astra 1,823 flagged
14:21:57 Translate this support ticket to Spanish gpt-6-astra 567 allowed
14:20:45 Write unit tests for the payment module claude-sonnet-5 3,412 allowed

AI moved into production faster than the controls around it. SignalVault puts them back in place.

Detection

Sensitive data never leaves your boundary.

Emails, social security numbers, card numbers, API keys and tokens are identified on every request. You decide per application whether to redact, block or flag.

Received from application

Update the account for John, SSN 423-91-8812, using key sk-prod-8f2a…

Forwarded to provider

Update the account for John, SSN 423-91-8812, using key sk-prod-8f2a…

Findings
1 PII · 1 secret
Action
Redacted
Notified
Webhook · email
Audit record req_7Hk2…9fQa
Recorded2026-09-25 14:22:51 UTC
Applicationproduction-api
Modelgpt-6-astra
Tool callslookup_account · update_record
RulePII · US Social Security number
DecisionBlocked
PayloadEncrypted, AES-256-GCM
Tokens · cost342 · $0.0021

Audit trail

The answer is ready before anyone asks.

Every prompt, response and tool call your agents make is stored, encrypted, with the rule decisions that applied. When a customer, auditor or your own security team asks what the AI did, export the record as CSV or JSON — evidence ready for SOC 2 and GDPR reviews.

About compliance exports

Integration

Minutes to install. Nothing to rewrite.

Wrap your existing OpenAI client with the Python or Node SDK, or point any OpenAI-compatible provider at the proxy. Mirror mode records without sitting in the request path.

Quickstart→ Python SDK→ Node.js SDK→
import OpenAI from 'openai';

// Point at SignalVault's proxy — no SDK needed.
const client = new OpenAI({
    apiKey: process.env.OPENAI_API_KEY,
    baseURL: 'https://api.signalvault.io/proxy/openai/v1',
    defaultHeaders: {
        'X-SignalVault-Key': 'sk_live_...',
    },
});

const response = await client.chat.completions.create({
    model: 'gpt-6-astra',
    messages: [{ role: 'user', content: 'Hello!' }],
});

Data handling

A trust layer has to earn trust itself.

This is exactly how we handle what passes through SignalVault. No marketing language.

Full security documentation
Storage
Prompts and responses encrypted at rest with AES-256-GCM
API keys
Hashed with HMAC-SHA256, never stored in plaintext
Transport
TLS on every external connection; internal traffic over an encrypted private network
Data region
Stockholm, Sweden
Retention
30 days on Starter, 90 on Growth, up to 365 on Enterprise
Operator
Elvar, Stockholm, Sweden

Questions

Before you route production traffic.

Anything else? Contact us — you'll hear back from the person who builds it.

Rule evaluation adds minimal latency. If you need zero added latency, mirror mode logs requests asynchronously without sitting in the request path.

Know what your AI
is sending.

100 free requests, no card required. Plans from $49 per application per month.