Rules that enforce themselves.
Define your organization's AI governance policies once. The Policy Engine evaluates every request against your rules — automatically, deterministically, with a full decision trace.
The Policy Engine powers all four stages of the Arbitex Gateway pipeline.
Rules determine which provider and model a request is routed to, including fallback chains.
DLP inspection rules are policy rules — they define what to scan, what to flag, and what action to take on detection.
The core of the Policy Engine. Access control, content policies, cost caps, and compliance rules are all evaluated here.
Every policy evaluation produces a decision trace that feeds the audit log and dashboards.
The Control stage is where the Policy Engine is most visible. Routing and Protection are governed by the Policy Engine but have their own dedicated pages. Visibility is the evidence layer for everything the Policy Engine enforces.
Capabilities
Ordered Rules, Full Control
You control the order. The first rule that matches decides the outcome — allow, block, redact, or ROUTE_TO an alternative model. This is the same first-match model used in next-generation firewalls: specific rules at the top, broad catch-alls at the bottom. No hidden conflict resolution, no silent overrides. Every enforcement decision is traceable to the exact rule that triggered it.
Policy Packs and Compliance Bundles
A Policy Pack is an ordered set of policy rules that can be applied as a unit — the building block of the Policy Engine. Compliance Bundles are Policy Packs pre-configured for regulatory frameworks: HIPAA, PCI-DSS, GDPR, and more. Apply a Compliance Bundle and your policies align to the framework immediately. Build your own Policy Packs to encode organization-specific governance rules and share them across teams.
Group-Based Conditions
Target rules by team, department, or role. "Finance group + OpenAI destination = Block" is a single rule. Conditions combine user identity, destination model, and content pattern — organization-level governance with team-level precision.
Combined Detection — Pattern + ML
Policy conditions can combine multiple detection methods in a single rule: pattern matching (80+ regex patterns for PHI, PCI, PII), ML-based entity recognition, and content classifiers — evaluated together. A rule can require both pattern and ML signal to trigger, reducing false positives in ambiguous cases while maintaining strict enforcement on clear violations.
Prompt Governance
Apply policy rules to system prompts and prompt templates — not just user input. Governance rules can inspect, transform, or enforce controls on the complete prompt context before it reaches any model. PROMPT-level rules allow organizations to enforce content standards, inject compliance context, or block unsafe prompt patterns at the governance layer rather than the application layer.
Modality Governance
Control which content modalities your organization permits. Text and tool-use are enabled by default; image, audio, and realtime modalities are admin-enabled per modality and enforced at the API. Unapproved content types are stopped at the gateway before they reach a model — governance over not just what content says, but what form it takes.
Simulation Mode
Test policy changes before enforcing them. Simulation mode evaluates requests — including against simulated user groups — and logs what would have happened: which requests would be blocked, which would be redacted, which would pass — without affecting production behavior. Review the simulation report, confirm the outcome, then promote to enforcement with one action.
Full Decision Trace
Every request logs which rules were evaluated, which rule matched, and what action was taken. When audit asks "why was this request blocked?" — the answer is in the trace, not in someone's memory. Compliance evidence is produced at enforcement time, not assembled afterward.
How it works
Define rules at the organization level
Author governance rules in the policy editor or via the API. Set matching conditions — user group, destination model, content pattern — and the enforcement action: allow, block, redact, or ROUTE_TO a specific alternative model. Build reusable Policy Packs for your own governance standards, or apply a Compliance Bundle (a pre-configured Policy Pack) to align with HIPAA, PCI-DSS, GDPR, and other frameworks immediately. Customize from there.
Simulate before enforcing
Activate simulation mode on any new or modified policy. Arbitex Gateway evaluates every matching request against the proposed rules and logs the projected outcome — which requests would be blocked, redacted, or passed. Review the simulation report to verify coverage, then promote to enforcement.
Every decision is traced and logged
Each enforcement action writes to the Immutable, tamper-proof audit log: which rules were evaluated, which rule matched, what action was taken, and the full request context. The decision trace is available for real-time review in the admin console and for export during compliance reviews.
AI deployed across the organization. Governance enforced by nobody.
You have AI running across teams. Each team configures its own controls — or does not. When compliance asks for proof of enforcement, you assemble it manually. The answer is different every time, and it is always late.
Define once. Enforce everywhere. Demonstrate on demand.
Define rules once at the organizational level. The Policy Engine enforces them on every AI request — deterministically, with a complete audit trail. Compliance Bundles map your policies to named regulatory frameworks so you can demonstrate alignment, not just claim it.
Related Resources
Governance enforced, not suggested.
Every AI request evaluated against your rules. Every decision traced. Every enforcement action logged.