← Back to site
Product Datasheet

Opsta AI Gateway

One governed control point for every LLM and AI-agent request — running entirely on infrastructure you own. Govern cost, access, and safety; keep your data in your environment.
The AI Platform Engineering
Self-hosted on Kubernetes OpenAI-compatible API Air-gappable Multi-tenant Hierarchical USD budgets

What it is

Opsta AI Gateway puts every large-language-model request and every AI-agent (MCP) tool call behind one governed gateway that runs in your own Kubernetes cluster. Teams keep using the OpenAI-compatible API they already know; the organization gains a single point to control spend, enforce access and safety policy, see usage, and keep an audit trail — without sending data to a third-party cloud.

Capabilities

Cost governance

Hierarchical USD budgets — organization → project → group → user. The tightest applicable cap wins; spend is priced per token per model.

Access & identity

API-key authentication, role-based access (platform / org admin / member), and SSO with per-organization IdP brokering (OIDC / SAML).

Safety guardrails

Prompt-injection detection (pattern and embedding-based), optional PII masking, and per-project tuning — with a visible block trail.

Model routing

Stable logical model names mapped to any OpenAI-compatible provider or self-hosted model, configured per project — no app changes to switch providers.

Semantic cache

Reuse answers for semantically similar prompts to cut latency and upstream spend, with cache-aware cost accounting.

MCP gateway

Give AI agents governed access to tools: register remote MCP servers per project, fronted with the same identity, isolation, and audit as LLM traffic.

Observability

Self-hosted usage, cost, and health dashboards with per-organization isolation — no telemetry leaves your environment.

Audit & compliance

Every administrative action — including denied attempts — is recorded with actor, target, outcome, and status.

Architecture & deployment

A control plane you own (backed by PostgreSQL, the single source of truth) continuously reconciles a data plane — the gateway that handles live traffic. Administrators change configuration in the web console or API; the gateway holds no configuration of its own, so there is no YAML to hand-edit and no configuration drift. The whole platform is one Helm chart, reproducible from code, and deploys standalone for pilots or highly available for production with a single toggle.

Security & data sovereignty

Your data stays put

Request content, telemetry, identity, configuration, and audit all live in your cluster. The only egress is to the providers you explicitly configure.

Runs air-gapped

Mirror every image into your registry; issue TLS from an internal CA; broker identity in-cluster. No internet egress required.

Verified-identity RBAC

Authorization is enforced on a verified token, not a trust-me header; org admins are scoped to their own organization.

Hardened supply chain

Pinned, vulnerability-scanned images; build-once / promote-by-retag, so the exact tested artifact is the one that ships.

At a glance

PlatformKubernetes ≥ 1.28 (Gateway API); on-prem, private cloud, or air-gapped
Client interfaceOpenAI-compatible /v1 REST API; Model Context Protocol (MCP) for agent tools
ProvidersOpenAI-compatible, DeepSeek, Anthropic, and self-hosted models (vLLM / Ollama / internal)
IdentityOIDC / SAML via an in-cluster identity broker; per-organization SSO with just-in-time provisioning
TenancyOrganization → Project → Group → User; isolation across keys, budgets, routing, telemetry, and tools
ObservabilitySelf-hosted metrics, logs, and traces; per-organization dashboards
DeploymentSingle Helm chart; standalone or high-availability; air-gap image mirroring; backup & DR
ConsoleWeb console for admins and developers

Editions

Self-managed

You run Opsta AI Gateway in your own environment under an Enterprise Product License.

  • Full product, deployed from one Helm chart
  • Runs on your Kubernetes, including air-gapped
  • Your team operates it

Opsta Managed Service

Opsta operates the gateway in your environment with professional, trusted support.

  • 24×7 operations and monitoring
  • Banking-grade SLA, trusted in regulated industries
  • Upgrades, hardening, and incident response handled for you
Available self-managed under an Enterprise Product License, or fully operated for you as Opsta Managed Service.