Bind identity
Validate the bearer JWT against configured JWKS. Production identity mode rejects anonymous requests and development identity headers.
Aiveris sits between AI agents and company systems. It binds each request to an identity, limits visible tools, applies policy, collects approval when needed, and records the decision.
Control plane simulator
Interactive simulation. Sample data. No network calls.
Policy decision
Select a request and run it through the control plane.
Sample evidence
Sample request ready.
Request lifecycle
Agent sends intent. Gateway decides which authority the request earns before any company system receives it.
Validate the bearer JWT against configured JWKS. Production identity mode rejects anonymous requests and development identity headers.
Resolve the approved route or tool namespace. MCP preview surfaces strip unsafe description text and quarantine tools that fail sanitization.
Cedar or database rules return allow, deny, or require approval. A missing evaluator or policy error fails closed.
Queue sensitive requests for a named reviewer. Slack can deliver the notice. Pending requests expire after a configured time limit.
Forward allowed requests with bounded authority. Exchange tokens carry audience, scope, and expiry. Raw upstream credentials stay inside the gateway.
Capture the decision, reason, timing, and configured argument record. SHA-256 links each event to the previous event for later integrity checks.
Security boundary
Teams control identity, policy, credentials, and evidence at one boundary. Each upstream keeps its existing API and permission model.
Requesters
Aiveris boundary
Upstreams
Current product boundary
Current claims follow the platform repository and launch evidence. Preview surfaces stay labeled until they reach the same control coverage.
Control plane for design partners with policy before dispatch, approval handling, identity binding, durable state, and configured audit sinks.
Gate: machine checks plus a live environment smoke before customer use.
Local protocol bridge with policy enforcement and an audit file required by default. HTTP remains the customer boundary.
Use: controlled local evaluation.
Inbound transport bound to loopback and guarded by an admin token. It does not yet match HTTP policy, audit, and inventory coverage.
Use: protocol testing only.
Access review sign-off and customer evidence remain required. Software checks cannot close those decisions.
Owner: customer and designated reviewers.
Policy choices
Rules can use caller identity, groups, route or tool, environment, and request context. Policy errors stop execution.
Evidence controls
Argument capture supports hashed, redacted, full, or omitted modes. Exchange credentials are fingerprinted without storing raw token values.
Customer control
Deploy the Go gateway with your identity provider, rules, databases, object storage, and upstream credentials.
Design partner path
Choose a risky tool call. Define identities and approval rules. Inspect the audit trail with your security team before adding another system.