Revocable virtual keys
Give each application a broker-issued credential that can expire, suspend, or revoke without rotating a vendor master key.
USE CASE / AI AGENT APPLICATIONS
CONTROL OUTCOMES
Give each application a broker-issued credential that can expire, suspend, or revoke without rotating a vendor master key.
Attach the key to an organization, team, or project and govern the model aliases and deployments it can use.
Apply token or currency budgets, RPM/TPM limits, and request/response guardrail policy in one request path.
Record the key, provider, upstream model, tokens, spend, guardrail decisions, latency, and outcome.
REFERENCE ARCHITECTURE
Issue a virtual key for the agent application under its organization, team, or project scope.
Point the existing SDK at the on-prem OpenAI-compatible gateway and request a stable model alias.
Apply limits and guardrails, then load-balance or fail over across configured vendor deployments.
Accrue scoped usage and write the complete provider and model call record to Postgres.
TRUST ARCHITECTURE
Map virtual-key access, encrypted provider credentials, guardrail decisions, and audit evidence to the controls your enterprise already operates.
Architecture supports evidence collection for access, change, and monitoring controls.
Map credential, access, policy, and audit practices to ISMS control objectives.
Operational visibility across governed model access, guardrails, usage, and provider outcomes.
Control-alignment statements describe product architecture and are not claims of EnvisionAI certification.
TECHNICAL EVALUATION
Map the architecture to your providers, application clients, governance scopes, data boundaries, and operating requirements.