Bosphorus

Every AI request your company makes should pass through one governed strait.

Bosphorus puts a single governed passage between your people, agents, IDEs and scripts and every model you run or buy — your own GPU and Mac nodes inside your network, and five external providers outside it. Authentication, policy, quota, rate limit, fair-share admission and audit are the passage, not middleware bolted beside it. There is no second route.

Request a PoCTalk to us

In daily production use since July 2026 · Turkish and EU data-residency routing built in · Deploys on your Kubernetes, on your hardware.

How one request crosses BosphorusFive kinds of caller — people, agents, IDEs, API clients and desktop tools — converge into a single channel that speaks three API dialects. The channel is a narrow strait crossed by six gates in order: auth, policy, quota, rate limit, fair-share admission and audit. A return path carries rate-limit headers, a request id, usage and cost back to the caller. On the far side, inference nodes and company documents sit inside your own network and dial outward to the strait, so nothing routes inward; document context is blocked from reaching the external providers, which are Anthropic, Hugging Face, OpenRouter, Bulutistan and Microsoft Foundry.Everyone who asksPeopleAgentsIDEsAPI clientsDesktop tools/v1 · /v1/messages · /api/*three dialects, one channelOne passage. No bypass.authwho is askingpolicymay this content passquotais there budgetrate limitis this too fastfair-share admissionwhose turn is itauditwrite it downrate-limit headers · request id · usage · costyour network — no inbound routeMac nodesNVIDIA nodesCompany documentsnodes dial outdocument context cannot leaveExternal providersAnthropicHugging FaceOpenRouterBulutistanprocessed in TürkiyeMicrosoft FoundryEU data boundary

Why now

Four problems, one missing chokepoint.

Shadow AI, ungoverned keys, idle hardware and per-vendor lock-in look like four separate projects. They are one architectural gap: there is nowhere that every AI request can be identified, judged and written down. Build that one place and all four close at once.

Shadow AI

Employees paste customer data, contracts, and source code into public chatbots on personal accounts. You have no visibility, no audit trail, and no way to answer a regulator.

Ungoverned LLM use

Teams that do use approved APIs use them with shared keys, no content controls, and no per-user accountability. One leaked key or one pasted card number is an incident.

Idle on-prem GPU capacity

The GPU workstations and Macs you already bought sit idle most of the day, while the company simultaneously pays per-token for external inference.

Per-provider lock-in

Every tool is wired to one vendor's API and one vendor's keys. Switching or mixing providers means rewriting integrations and re-doing governance per provider.

Shadow AI gets a sanctioned alternative that is genuinely better. Sensitive data is stopped before it reaches any model. Your own hardware carries the base load. Providers become interchangeable capacity behind one stable API.

What ships in the box

Governance you can count, and check.

3API dialects, one enforcement path
23policy modules in the box
20EU governance instruments — 13 enforcing by default, 7 opt-in
337policy assertions run before any rule change ships
48alert rules ship with the platform, including a disk-fill prediction 24 hours ahead

Bring us your hardest governance requirement.

We will stand a proof of concept up on your cluster, with your identity provider, your rules and hardware you already own — and hand you the evidence at the end of it.

Request a PoCTalk to us

A PoC needs a small Kubernetes cluster, one or two GPU or Mac nodes you already own, an identity tenant, and five to twenty pilot users. Everything else ships with the product.