Private Gateway

The Same Governance Engine, Running Inside Your VPC

Cloptima's private edge gateway enforces guardrails, budget decisions, and audit logging locally — it's self-sufficient by design, not a thin proxy back to a hosted SaaS path.

customer-vpc · cloptima-edge-gateway
Private edge gateway
Runs in your VPC · local enforcement
Enterprise
Signed policy snapshot
synced from control plane
Current
Local reservation ledger
durable budget checks offline
Healthy
BYOK secrets
stored in your VPC
Local
Usage outbox
buffered to control plane
0 pending

Govern access before spend happens

Some teams cannot send all AI traffic through a hosted SaaS path. They still need spend controls, attribution, and usage finalization for workloads running in private networks.

One policy layer across model usage

The private gateway runs the same policy engine as the cloud gateway locally in your VPC: guardrail evaluation, budget decisions, and audit logging all execute on-site from signed policy snapshots. Provider credentials stay locally encrypted, and enforcement keeps working even if connectivity back to Cloptima is briefly unavailable.

  • Guardrails, policy decisions, and budget enforcement run locally
  • Provider credentials stay locally encrypted — never uploaded in plaintext
  • Full audit trail generated on-site, synced back for central reporting
  • Local reservation ledger keeps enforcement running through connectivity gaps

Start with one app, then expand

Start with hosted gateway or telemetry, then evaluate private gateway deployment for regulated apps, high-volume workloads, or network-constrained environments.

Built for private production AI

The architecture uses signed policy snapshots, locally encrypted credentials, local budget decisions, resilient usage delivery, and central reporting so teams can combine private execution with centralized AI FinOps without uploading plaintext provider credentials to Cloptima cloud.

Cloud Gateway vs. Private Edge Gateway

The private gateway runs the same governance engine as the hosted gateway — the difference is where it executes.

CapabilityCloud GatewayPrivate Edge Gateway
Guardrail enforcementIncludedRuns locally in your VPC
Budget & policy decisionsIncludedRuns locally in your VPC
Audit loggingIncludedGenerated locally, synced for reporting
Provider credentialsManaged by CloptimaStay locally encrypted in your environment
Exact response cacheIncludedIncluded
Semantic response cache & searchIncludedComing soon
Deployment modelHosted SaaSRuns inside your VPC or on-prem

Launch path

Private gateway deployment is available through enterprise onboarding. Cloptima reviews workload topology, provider connectivity, and governance requirements as part of rollout.

FAQ

Operationalize LLM FinOps Across Your Apps

Start with telemetry, gateway governance, or provider bill matching workflows. Keep model spend connected to engineering ownership and finance reporting.

No credit card required
5-minute setup
Free trial