The platform

One control plane for every AI you run.

Kapālins sits between your enterprise and every model, copilot and agent it touches — inspecting, governing, attributing cost and generating evidence. Bring any AI; we add the trust.

Whole-estate coverage

Three observation modes.

A gateway is one mode. Kapālins runs three, so the estate your staff actually use is governed — not just your API traffic.

MODE 01Ships v1.0
AppLLMK200 allow446 block

Proxy

Inline gateway. Full payload visibility and real-time enforcement on every API call — allow, flag or block.

MODE 02Ships v1.0
CopilotProbescheduled scan · sweep

Probe

Scheduled scanning of SaaS-embedded AI — Copilot, Agentforce, Gemini in Workspace — behaviour a gateway never sees.

MODE 03Ships v1.0
audit-log ingestion

Connector

Audit-log ingestion from admin APIs — inventories what is authorised, configured and drifting across the estate.

Policy & runtime

A 23-rule Policy Shield on every call.

Prompt filtering, cross-tenant blocking and agent guardrails — every request resolved to one of three runtime outcomes. Detect and shadow modes are GA; block mode is rolling out rule-by-rule.

200allow246flag / shadow446block
policy-shield · runtimelive
prompt-injection guard
200
cross-tenant isolation
200
PII egress filter
246
agent tool-call policy
446
finops · cost attributionmonthly
Engineering · Cursor
$18k
Support · Agentforce
$11k
Marketing · Copilot
$7k
Data · OpenAI API
$6k
AI FinOps

The CFO’s question, answered.

Attribute AI spend per tool, team and tenant; set token budgets; report unit economics to the board. An adjacency no AI-security vendor has claimed. (Roadmap Q3 2026.)