Trust & deployment

Trust starts with customer control.

Skris is designed to run inside your environment. You choose the providers and models, own the policies and keys, and decide what interaction data is retained.

Your environment
01

Customer-controlled infrastructure

02

Raw prompt capture off by default

03

Policy enforcement before provider egress

Control before egressApproved external destination →

Your environment

The control plane stays inside your trust boundary.

Requests enter Skris from approved people, applications, and agents. Policy is applied before an approved request is routed to a selected cloud, private, or local destination.

Deployment

Run the gateway on-premises or in a customer-controlled VPC.

Credentials

Encrypt provider credentials centrally and store user API keys as hashes.

Policy

Keep access, routing, data, usage, and retention decisions under organizational control.

Data handling

Collect only what the operating model requires.

Skris separates request processing from optional content retention. The organization configures capture and retention according to its own requirements.

Prompt and response content Not captured by default Bounded, encrypted, and retention-controlled when explicitly enabled
Provider credentials Stored encrypted Managed by administrators; not distributed to end-user tools
User API keys Stored as hashes Scoped access and central revocation
Usage and policy events Recorded for operations and audit Customer-owned retention and export

Evidence without overclaiming

Controls and records that support your governance program.

Skris can record policy outcomes, routes, usage, cost, and operational events. Hash-chained exports help make changes detectable and provide a defensible record for internal review.

Policy evidence

Show which rule and decision applied to a governed request.

Operational evidence

Review provider validation, model routes, usage, budgets, and revocation events.

Data protection

Apply inline text actions including allow, warn, redact, and deny before upstream routing.

A control layer, not a certification

Skris provides technical controls and evidence that can support GDPR, EU AI Act, ISO 42001, and other governance programs. It does not certify an organization or guarantee compliance.

Private architecture discussion

Review Skris against your trust boundary.

Bring your deployment, provider, retention, and evidence requirements. We will map the points that need technical validation.

Helpful details

Common questions

Does customer data pass through Skris?

Requests follow a Skris route inside the customer-controlled environment, where policy is applied before approved provider egress. Retention and content capture remain customer decisions.

Who controls provider credentials?

Provider credentials and access keys remain within the customer-controlled deployment rather than being distributed to end-user tools.

Does Skris guarantee GDPR or EU AI Act compliance?

No product can guarantee organizational compliance. Skris provides technical control points and evidence that can support a wider governance and compliance program.