Changelog
Updates from the Arbitex team — features shipped, improvements made, and what's next.
SIEM direct sink for Hybrid Outpost deployments
Hybrid Outpost nodes can now forward audit events directly to your SIEM without routing through the cloud data plane. Three native formats: Splunk HEC (OCSF sourcetype), Microsoft Sentinel (DCR ingestion), and Elasticsearch (Bulk API). Configuration lives in the policy bundle — no environment variable changes required.
Learn more →Signed policy bundle verification
Policy bundles distributed to Hybrid Outpost nodes are now cryptographically signed and timestamp-verified. Outpost nodes reject tampered or expired bundles by default. Bundle signature status and last verified timestamp are visible in the admin dashboard.
Credential intelligence — privacy-preserving online verification
Credential intelligence lookups can now use a privacy-preserving partial-hash scheme for online verification against external breach APIs. Only a short hash prefix is transmitted — the full credential is never sent. Local dataset detection remains the default; online verification provides an optional second layer for higher-confidence results.
Learn more →OAuth scope enforcement for Hybrid Outpost
Hybrid Outpost now enforces OAuth scope policies defined in the policy bundle. Each API path can require specific scopes — requests with insufficient scope receive a 403 with an X-Scope-Required header. Scope enforcement is opt-in and configurable per deployment.
Learn more →OpenTelemetry metrics and traces export
Arbitex Gateway now emits structured telemetry in OpenTelemetry format — request latency, token throughput, policy event rates, and provider health metrics. Connect to your existing Grafana stack, Datadog, or any OpenTelemetry-compatible collector to correlate AI governance events with application observability.
Learn more →Production deployment templates and health validation
Docker Compose production templates now include health check endpoints, startup dependency ordering, and configuration validation scripts. Environment validation catches misconfigured secrets, missing policy bundles, and unreachable SIEM endpoints before traffic is served.
Admin portal — provisioning and policy management improvements
User provisioning workflows now support bulk import from SCIM directories. Policy bundle management adds clone and copy operations to accelerate multi-tenant configuration. Audit log filtering extended to cover enforcement action type, compliance framework, and originating OAuth client.
Healthcare compliance documentation package
A downloadable compliance summary is now available for healthcare organizations evaluating Arbitex against HIPAA and HITECH requirements. The package covers the AI model boundary enforcement architecture, Hybrid Outpost PHI residency guarantees, and audit log structure mapped to OCR examination requirements.
Connect your existing identity provider
Arbitex now works with the identity system you already use — Okta, Azure AD, Google Workspace, and others. Users sign in with their company credentials. IT teams control access through their existing directory, with no separate account management required.
Learn more →Hybrid Outpost — run the data plane in your VPC
For organizations that need AI traffic to stay inside their environment, Arbitex Hybrid Outpost runs the inspection and enforcement layer inside your VPC. Prompts and responses are inspected and logged entirely on your network. Policy management and administration remain SaaS-hosted by Arbitex.
Learn more →Route AI requests across multiple providers
Arbitex connects to the major AI providers through a single integration point. You can send requests to one model, compare results from two side-by-side, or fan out across multiple providers and synthesize the results — all without changing your application code.
Learn more →Set spending limits per team and project
Budget caps and usage limits can now be enforced per team or per project. When a team reaches its limit, requests are blocked at the gateway before the model call is made — no overruns, no surprises on the bill.
Learn more →Automatic provider health monitoring
When a provider starts returning errors or slows down, Arbitex detects the problem and reroutes traffic to a healthy alternative automatically. Your users stay unaffected. You can also block any provider immediately from the admin console.
Learn more →Inspect every AI request for sensitive data
We built a 3-tier inspection system that checks every AI request for sensitive data before it leaves your environment. It catches structured data like card numbers and government IDs, identifies people and organizations mentioned in free text, and uses a context-aware model to confirm ambiguous matches before blocking or redacting.
Learn more →Compliance framework support out of the box
Activate a compliance bundle and the inspection pipeline automatically enforces the right rules for your industry. PCI-DSS, HIPAA, SOX, and GDPR are pre-mapped — no manual rule configuration required.
Learn more →Want to see the platform in action?Book a demoand we'll walk you through the latest capabilities.