Leakage
There is no gate between your agents and the LLM provider. Secrets, API keys and personal data go straight through in prompts and tool results.
coming soon Cardea is in early access and this site is a preview. Details may change before launch.
Early access · Self-hosted or hosted in the EU
Cardea sits between your agents and the models they call. It identifies every agent, records every tool call, and stops risky calls before they leave your network.
Opens what is shut · Shuts what is open
01 — The problem
Agents no longer just answer prompts. They call tools, read and write files, and use credentials on their own. Docker, gVisor or Firecracker stop an agent from escaping to the kernel. They do not stop it from sending a customer record to a third-party model.
There is no gate between your agents and the LLM provider. Secrets, API keys and personal data go straight through in prompts and tool results.
In healthcare, legal and finance you need a record of what the agent did: which tools, which data, in what order. API logs only show that a model was called.
sandbox → protects the host
cardea → protects the system and data
You need both. Cardea does not replace your sandbox; it works with whichever one you already run.
02 — The governance pipeline
Every call from an agent is checked before it reaches the model. Any layer can stop it, and a stopped call never leaves your network.
Every call is tied to a known, registered agent. Unknown or misconfigured callers are turned away before they reach a model.
Decide which models, tools and data each agent may use, and when. Policies are reviewable and versioned, and they change without downtime.
Call frequency, token volume, latency and error rates per agent, with alerts on anomalous behaviour.
Catches secrets, API keys, personal data and prompt injection before they leave your network.
Limits per agent and per model. A runaway loop hits a ceiling before it runs up your bill.
A record of who called, what they did, when, and what was decided, for every call, allowed or denied.
Fails safe
If something goes wrong inside Cardea, calls are blocked, never waved through.
Keeps your keys
Agents never hold your model provider keys, so they have none to leak.
Discreet refusals
A refused caller gets a clear answer, not a map of your rules. The details go to your team.
Invisible when allowed
Allowed calls work exactly as before, with no noticeable delay.
03 — The platform
The optional platform collects records from all your gateways. It shows a live feed of allowed and denied calls and a map of every host and agent your gateways have seen. It is hosted in the EU.
Loading…
The Cardea platform, shown with sample data.
04 — Session traces
Each model call, each tool the model asked for, and each result sent back, in order and on one timeline. When something goes wrong, you can see which step caused it without reading a single prompt.
05 — Adoption
Point your agents at Cardea instead of the model provider. There's no SDK to add and no agent code to change. Claude Code, opencode and any Anthropic SDK work as they are.
In your cloud, on-prem or next to the agent, or use our EU-hosted service. Your provider keys stay with Cardea.
Give each agent its own credential. Agents never hold a real provider key, so there's nothing for them to leak.
Point your agents at Cardea. From then on, every call and every tool they use is identified and traced.
Enforces policy and records activity in real time, as the calls happen. Run it yourself, or let us host it in the EU.
Collects records from all your gateways and shows the live feed, the agent map and session traces. It is hosted in the EU. You can use your own observability stack instead.
platform, or export to your SIEM
06 — Sovereignty
Governance should not require sending your traffic to yet another third party. Cardea is designed so that you choose where the data goes, and it stays there.
deploy
Self-hosted or hosted in the EU
Run it on your own cloud or on-prem. If you prefer SaaS, it is hosted in Europe so data stays in the region.
intercept
No TLS interception
Agents route to Cardea explicitly. We do not spoof DNS or decrypt traffic; that approach is a GDPR grey area and we avoid it.
standards
Open formats, no lock-in
Built on open standards, with your data exportable at any time. Bring your own observability stack.
minimise
Data minimisation by default
Traces hold metadata only, never payload content. This page itself makes no third-party requests, except the pilot form when you submit it.
| Framework | What it asks for | What Cardea records or enforces |
|---|---|---|
| EU AI Act | Traceability and record-keeping for AI systems | A record for every call, with agent, action, model, decision and the policy that took it |
| DORA | Monitoring, anomaly detection, incident reconstruction | Timings and an ordered trace of every agent session |
| GDPR | Data minimisation, control over where data is processed | Traces without content, self-hosting or EU hosting, no traffic decryption |
| ACPR · SOC 2 | Access control and a log of external calls | Authenticated agent identities, policy decisions and an audit log that includes denied calls |
Cardea supplies evidence and controls. It does not make a system compliant by itself; compliance is still a property of your whole organisation.
07 — Why Cardea
LLM gateways control access to the model: routing, spend and rate limits. Cardea also sees what the agent does with the tools, files and credentials it has been given.
Audit trails and controls are designed around healthcare, legal and financial requirements. They are part of the core, not a set of third-party plugins.
Many tools offer a free, ungoverned base and charge for audit logs and PII controls. For a security buyer that is the wrong way round, so these are included.
Being explicit about scope matters. A governance tool that claims to do everything is harder to audit and to trust.
08 — Start a pilot
We are looking for a small number of design partners in healthcare, legal, finance and software.
One agent, one workflow, deployed on your infrastructure. You get a complete trace of what that agent does.
Integration, policy design and rollout support, fitted to your stack and your compliance requirements.