Enterprise AI gateway

Govern every model, tool, and AI agent

Tygress is a self-hosted enterprise AI gateway in Rust. Route across LLM providers, secure prompts and data, control tokens and spend, govern MCP tools and A2A agents, and apply the same enterprise policy to every API.

Tygress is currently in development. Product capabilities describe the planned launch scope.

ProvidersOpenAIAnthropicGeminiAzure OpenAIAWS BedrockMistralGroqOpenAI-compatible

Every workload

REST/api/v1/orders
gRPCpayments.Charge
LLM/v1/chat/completions
MCPtools/call

One Rust data plane

Tygress

One route model and one policy chain for API, model, tool, and agent traffic.

IdentityRate limitsAI guardrailsCost budgetsAuditOpenTelemetry

Every upstream

APIs & microservices
OpenAI & Anthropic
Bedrock & Gemini
MCP & A2A agents
Tygress applies the same enterprise controls before traffic reaches APIs, model providers, tools, or agents.

One enforcement point

AI governance belongs in the request path

Dashboards can report what happened. Tygress enforces what is allowed before the request reaches a provider, tool, or agent: who can call it, what data may leave, how much it may cost, and whether a human must approve it.

01

Unified model access

Expose one OpenAI-compatible endpoint for OpenAI, Anthropic, Gemini, Azure OpenAI, AWS Bedrock, Mistral, Groq, and compatible providers.

02

Keys and model policy

Issue virtual keys, keep provider credentials server-side, rotate across key pools, and enforce per-consumer model and tool access.

03

Cost and quota control

Track prompt, completion, cached, and reasoning tokens. Enforce token windows and USD budgets by consumer, route, tenant, provider, or model.

04

AI security and DLP

Detect prompt injection and jailbreaks, redact PII and secrets in requests or streamed responses, and keep matched data away from providers.

05

Reliability and caching

Fail over across providers and keys, route by priority or weight, use upstream quota signals, and replay semantically similar answers from cache.

06

MCP and agent governance

Aggregate MCP servers, enforce tool allowlists, route A2A calls by skill, and hold sensitive actions in a gateway approval queue with audit and webhooks.

Shared operating model

One gateway, four teams, one source of truth

Developers

Use one OpenAI-compatible contract and stable model aliases instead of provider-specific credentials and SDK logic.

Platform teams

Operate model, API, MCP, and A2A traffic through the same route model, deployment topology, and telemetry stack.

Security teams

Enforce identity, data handling, tool access, prompt policy, approvals, and audit before a request leaves the network.

FinOps teams

Attribute tokens and spend to consumers, cap budgets in USD, track cache savings, and observe provider failover and quota state.

More than an LLM proxy

Use the same controls for REST and gRPC

Tygress includes the traffic management, authentication, protocol support, resilience, and extensibility expected from an enterprise API gateway.

Explore enterprise API gateway

FAQ

Enterprise AI gateway questions

What is an enterprise AI gateway?

An enterprise AI gateway is the policy and operations layer between applications and AI systems. It centralizes model access, provider credentials, routing, failover, token and cost controls, prompt security, data-loss prevention, observability, MCP tool access, and agent governance. Tygress combines those controls with a full enterprise API gateway.

How is an AI gateway different from an LLM proxy?

An LLM proxy primarily normalizes model APIs and routes model requests. An enterprise AI gateway adds organizational identity, tenant policy, security controls, audit, cost governance, high availability, and agent protocols. Tygress also carries REST, gRPC, and WebSocket traffic, reducing the need for a separate API gateway.

Which AI providers does Tygress support?

Tygress supports OpenAI, Anthropic, Google Gemini, Azure OpenAI, AWS Bedrock, Mistral, Groq, and any OpenAI-compatible endpoint. Bedrock supports both OpenAI-compatible access and the native Converse API with AWS SigV4.

Can Tygress govern MCP servers and AI agents?

Yes. Tygress can aggregate MCP servers behind one endpoint, generate toolsets from OpenAPI, apply per-consumer tool allowlists, and serve REST upstreams as MCP tools. Its A2A gateway federates agents and can require human approval for sensitive MCP or A2A calls.

Can the AI gateway be self-hosted or air-gapped?

Yes. Tygress is designed to run in a private VPC, on-premises, Kubernetes, or a fully air-gapped environment. Provider credentials, prompts, responses, identity, and policy remain inside the infrastructure you control.

Is Tygress a LiteLLM alternative?

Yes, for teams evaluating a deployed LLM gateway. Tygress provides an OpenAI-compatible model layer with routing, failover, keys, budgets, guardrails, and observability, then adds enterprise API gateway and agent-governance capabilities. Tygress is still pre-launch; LiteLLM is available today.

Control AI before it leaves your network

Build on one enterprise AI gateway

Join the waitlist for early access, deployment guidance, and launch updates.