Update cookies preferences
AI Orchestration

Deploy agents faster. Optimize performance.

Cross-provider AI routing, inline policy enforcement, and cost-aware model selection under one control plane.

Get a demo
Illustration of a planet resembling Saturn with textured yarn-like swirling patterns in blue and purple and a yellow knitted ring around it.
Securing AI by the world's top providers

The Onyx Approach

Production agents need infrastructure that's secure by design. Agent-building platforms like Copilot Studio, Bedrock, and Agentforce deploy agents at scale, but they don't inspect prompts, enforce data controls, or catch when an agent acts outside its intended scope. Coding agents, custom applications, and internal LLM traffic face the same gap. Onyx is designed as the routing and enforcement layer for production agents: cross-provider routing, cost-aware model selection, and inline policy inspection on every request, alongside gateways teams already run like LiteLLM or Portkey.

Onyx adds the inline inspection that turns cross-provider routing into governed routing, and aligns cost-and-model selection with the security policy in one pass.

Starship model crafted entirely from knitted yarn in blue, purple, and gold colors.

The Onyx Difference

Diagram showing AI Gateway connecting to four AI models with monthly costs and a safety check.

Cost and security in one place

Route across LLMs to automate failover, minimize latency, and load-balance based on task complexity and cost. Every request is inspected against the same policy your security team already enforces, so cost-aware model selection and governance run through one path instead of one for cost and another for security.

Onyx MCP Gateway interface showing evaluations: Scope, Identity, and Data class approved; Policy blocked.

Extends to the MCP Ecosystem

Every tool call an agent makes to an MCP server is evaluated against scope, identity, data class, and policy before the call lands. Coverage spans the MCP ecosystem, including servers using dynamic client registration and popular servers like GitHub, so new agents operate under policy from the first call.

Diagram showing AI Gateway linking user prompt to Alert, Secure, Mask, Ask, and Steer functions.

Consistent Policy Enforcement

The same policy that governs a Copilot Studio agent governs a Bedrock agent, a coding agent, and a call to an MCP server. Security teams write policy once and see it enforced consistently across every path an agent takes, keeping the enforcement surface consistent as the agent stack keeps changing.

See Onyx Connect to Your Stack

Onyx drops in next to the identity, cloud, network, and endpoint tools your team already runs. Most environments produce a working AI inventory within 24 hours and an enforced governance policy on day one. To see real-time AI security across your stack...

schedule a demo

Connects to the Tools You Already Run

Onyx fits into the AI infrastructure your team already runs: existing LLM gateways, model providers, agent-building platforms, and identity systems stay in place.

  • Every request aligns with identity, platform, and model context in a single pass, giving security, cost, and governance teams one shared view
  • The Onyx AI Gateway layers on top of your existing gateway to add inline policy inspection, or handles routing directly for teams that want a unified path.
Illustration of a planet resembling Saturn with textured yarn-like swirling patterns in blue and purple and a yellow knitted ring around it.

Frequently Asked Questions

What makes the Onyx AI Gateway different from LiteLLM or Portkey?

The Onyx AI Gateway is built for teams evaluating LiteLLM Enterprise or Portkey for production agent traffic. What ships by default: inline prompt inspection, tool-call policy enforcement, data-class controls, and agent-behavior guardrails on every request. Routing, cost-aware model selection, and cross-provider failover run through the same path, so security policy stays inside the request loop instead of alongside it. LiteLLM and Portkey handle routing; Onyx adds the enterprise guardrails that routing-only gateways don't.

Does the MCP Gateway cover agent-to-agent traffic?

The MCP Gateway governs the agent-to-tool surface. Every tool call an agent makes to an MCP server gets inspected and policy-enforced. Coverage spans the MCP ecosystem, including servers using dynamic client registration and popular servers like GitHub.

What enforcement modes does Onyx apply?

Five modes at the action layer: alert, block, mask, steer, or ask. Steer redirects the risky action toward a safe alternative without stopping the workflow. Ask routes the decision to a human in the loop when policy demands review.