Skip to main content

AI gateways

One policy for every model behind the proxy. Configure once, every application inherits it.

LiteLLM

LiteLLM Proxy ships an Alice guardrail. It forwards each prompt before the model call and each completion after it; Alice returns ALLOW, BLOCK, MASK or DETECT and the proxy enforces it. Which policies apply is decided per virtual key, so one proxy serves many applications.

Portkey AI GatewayBeta

A Portkey guardrail plugin. Add your Alice API key once under Integrations, create an Evaluate check with your application id, and attach it as an input or output guardrail in any Portkey config. Portkey enforces the verdict: block, mask the flagged spans, or record and pass.

Databricks Unity AI Gateway

Register Alice once as a Unity Catalog HTTP Connection, then attach it as an External policy to a governed model. The gateway calls Alice before the model (modelcall) and after it (modelresult), receives ALLOW or DENY, and enforces inline. Start in Log mode, flip to Enforce when the verdicts match your intent.

Kong AI GatewayBeta

Alice runs on a Kong AI Gateway through Kong's built-in ai-custom-guardrail plugin, a declarative HTTP callout: Kong sends the text it selected to Alice and enforces the verdict that comes back. Nothing custom runs in the gateway, so the whole integration is one decK config block. With request_body sent, Alice reads the conversation itself and screens the newest turn together with its tool calls and tool results.

Databricks OmnigentPreview

Omnigent governs agents built on Claude Code, Codex, Pi or custom harnesses through a policy layer. This policy adapts the Alice client into that contract: every request, response, tool call and tool result is evaluated at runtime and the verdict is enforced by the runner. Omnigent secures what the agent does; Alice secures what it is told and what it says.

Amazon Bedrock AgentCore GatewayPreview

AgentCore Gateway runs a Lambda interceptor around every MCP call it proxies to a tool server: once on the request (tool arguments) and once on the response (tool result). The interceptor below is the scaffold that receives both hooks, holds the Alice client, and returns the transformed body the gateway forwards. Prompts and model responses never pass through the gateway, so they are out of scope here.