GatewayEnforcer

Gateway Sessions

Gateway Sessions is a policy gateway that stands in front of the generative AI applications your organization already uses — same models, same prompts, same apps, pointed at the providers you approve. It changes nothing about how people work. It changes three facts about what can happen: no session outlives its mandate, no data outlives its session, and no compliance claim outlives its proof. Each of those is enforced by architecture and closed with an Ed25519-signed Certificate of Incineration™ you can verify without us.

Layer system-facing policy Deadlines non-negotiable Receipt Ed25519 Certificate of Incineration Latency zero added
The screening room · two minutes · no audio · you drive

Watch the problem. Then watch it burn.

What follows is not a video. It is the demonstration we give a boardroom, running live inside this page. One sentence of client data — names, balances, positions — typed into a consumer AI on a personal phone, and the only honest answer anyone on earth can give about where that sentence lives now. Then the same sentence, the same employee, the same job to do — behind Gateway Sessions. It ends in ash, and the ash comes with a signature.

Click inside to advance · space bar works · R restarts

The hinge of those two minutes is a shrug. Who knows is the real, current answer to where your organization’s data goes when it walks out through shadow AI — and it is an answer a general counsel can survive giving exactly once. Every browser control, every acceptable-use policy, every ban you’ve already tried leaves that answer standing, because none of them can attest what happened to the data after it left.

Gateway Sessions was built so the answer is never a shrug again. Not because a policy forbids it — because the session that held the data no longer exists, the deadline that killed it was set by an identity the application provably cannot reach, and the Certificate of Incineration™ proving all of it was signed inside your own tenant. The demonstration above is not a dramatization of a feature. It is the product’s job description, performed.

What It Is

The market calls it BYOAI: employees bringing their own AI tools to work, sanctioned or not. Bans drive it underground; browser controls can mask a prompt but cannot attest what happened to the data server-side. Gateway Sessions takes the other path — it lets your people keep the AI they already use and puts enforcement at the execution layer, where custody can actually be proven. It deploys into your own Azure tenant. Heaviside AI operates no servers in the data path, holds none of the keys it asks you to trust, and cannot see a session’s content — structurally, not contractually.

Performance

Because enforcement adds no per-request network overhead, the per-seat cost of enforcement is identical at 5,000 seats and at 50,000.

Verification

Gateway Sessions makes no accreditation claims of its own — it inherits your accredited enclave. What it ships instead is the means for your security team to re-prove the deployment whenever it chooses. The claim is designed to be re-proven, not remembered.

The call record, on Pro

On the Financial, Federal, EU and AU plans the prompt and the response are left out on purpose. Gateway Sessions Pro keeps them, as a call record written to storage in your own subscription and tied to the same signed trail.

KeptEvery call, where you say

The prompt and the response of every governed call are written to storage in your subscription: the account the gateway creates for you, or one you already own. Personal data is removed before the record is written unless you choose to keep it. Records are retained for six months by default; you set the period.

TiedA record that cannot be quietly altered

Each record’s fingerprint is signed into the call’s trail event and into the session’s certificate. A record changed after the fact fails against its own line.

YoursNobody at Heaviside can read it

The storage sits in your subscription, under your keys. Heaviside AI holds no access to it, and the plan is published without any publisher access into your deployment.

Plans

One gateway, five plans. Every plan is the same gateway, the same trail and the same certificate; they differ in where they sell, which providers they admit, and whether the call record is kept. Sold on Azure Marketplace or as a private offer through your channel partner. There is no trial edition.

ProGateway Sessions Pro

For any enterprise, regulated or not, in 61 markets. Your choice of provider. Keeps the call record. Unlimited governed calls, unlimited applications, one deployment.

FinancialGateway Sessions Financial

The posture financial-sector buyers require. American-hosted providers only. The trail carries no content and no record is kept.

FederalGateway Sessions Federal

The posture public-sector buyers require. American-hosted providers only. The trail carries no content and no record is kept.

EUGateway Sessions EU

Deploys only into EU and EEA regions, enforced by the template and the install screen. Your choice of provider. The trail carries no content and no record is kept.

AUGateway Sessions AU

Deploys only into Australian regions, enforced by the template and the install screen. Your choice of provider. The trail carries no content and no record is kept.

Procurement

Transactable on Azure Marketplace, including via Multiparty Private Offer through your Microsoft Professional or Cloud Partner. Deploys into your own Azure subscription; nothing runs on Heaviside AI infrastructure. Private offers: steve@heavisideai.com — Steve McKim, Founder & CEO.