Glass box, not black box
Self-hostable in your own cloud. Your prompts and data never leave your tenant. Detection is transparent and auditable — no opaque vendor magic.
Sluice redacts sensitive data before it ever leaves your tenant, governs every MCP agent and tool call, and proves compliance — all self-hosted on your infrastructure. The modern alternative to $150k black boxes, for about $10k a year.
Self-hostable in your own cloud. Your prompts and data never leave your tenant. Detection is transparent and auditable — no opaque vendor magic.
Built for the MCP/agent era. Govern tool calls, not just prompts — discover, score, and block MCP servers and individual capabilities.
A LiteLLM-compatible gateway, a clean SDK, and well-documented APIs. Drop it in front of Claude Code, Cursor, or any app in minutes.
Employees paste customer data into ChatGPT. Coding agents exfiltrate secrets through MCP servers nobody approved. And the only "governance" on offer costs a fortune and ships as a black box you have to trust blindly.
Dozens of unmanaged AI tools in use across the org. No inventory, no policy, no idea what's leaving.
PII, PHI, financial records, and source code flow to third-party models — irreversibly, with no redaction at the edge.
Autonomous agents call tools and external MCP servers with standing access. One poisoned tool and your data walks.
Legacy AI-security suites quote $100–150k/yr — opaque SaaS that wants your traffic routed through their cloud.
Every prompt, response, and tool call — wherever it originates — flows through a single scanning and policy engine. Meet your traffic where it already lives with three interchangeable ingress adapters.
LiteLLM proxy for Claude Code, Cursor & apps
Intercepts chatgpt.com, claude.ai & more
Native calls from your own services
PII, PHI, financial data, and secrets are tokenized out of prompts before they reach any provider. Reversible only inside your deployment.
Author Cedar policies in plain English with an NL→Cedar compiler. Ship 18 built-in, toggleable packs and version everything in git.
Every event scored 0–100 on data sensitivity, intent, and context — rolled up per user and per tool to surface the riskiest activity.
Discover MCP tools across endpoints, allow only marketplace-vetted servers, and block an entire server — or a single tool call — in real time.
An immutable, hash-chained log of every event. Inspect the exact redacted prompt and response — with an admin-gated "reveal original".
Map AI usage to SOC 2, HIPAA, GDPR, the EU AI Act, ISO 42001, and PCI — and export audit-ready reports on demand.
SSO/SCIM, alerting to Slack, email, and SIEM (Splunk/Sentinel), streaming scan, redaction-map encryption, and FinOps spend tracking.
Runs entirely in your own cloud or on-prem. No telemetry, no phone-home, no traffic routed through a vendor. Your tenant, your keys.
Detect prompt injection, jailbreak attempts, and hidden markers in both directions — inbound prompts and model output alike.
Prompt scanning is table stakes. The real exposure in 2026 is autonomous agents wielding tools through MCP servers nobody vetted. Sluice is built for exactly this frontier — it treats every tool call as a governed event.
unknown-fetch-mcp.exec — payload matched secret-exfil pattern. Call denied.
Three views from the Sluice console — audit, policy, and risk — all rendered live in your browser, no screenshots.
API_KEY ▮▮▮▮ redacted61
SSN ▮▮▮-▮▮-▮▮▮▮ redacted88
PHI ▮▮▮▮▮▮ redacted79
permit(principal, action, resource)
when {
resource.contains_pii == false
&& resource.risk < 75
};
| Capability | Sluice | Legacy AI-security SaaS | Cloud DLP proxy |
|---|---|---|---|
| Self-hostable in your tenant | Yes | SaaS | SaaS |
| Data never leaves your cloud | Yes | No | No |
| Transparent / auditable detection | Yes | Partial | Black box |
| MCP & agent tool-call governance | Native | Limited | Limited |
| Policy-as-code (NL→Cedar) | Yes | UI only | UI only |
| Gateway + Extension + SDK ingress | All three | Proxy | Proxy |
| Immutable hash-chained audit | Yes | Logs | Logs |
| No telemetry / phone-home | Yes | No | No |
| Typical annual cost | ~$10k | $100–150k | $100–150k |
$0self-host, forever
For teams that want to see everything.
$10k/ year
Everything, governed and compliant — at 10x less.
Customair-gapped
For regulated & classified environments.
Map every AI interaction to the frameworks your auditors ask about.
We'll stand up Sluice in your environment, point your traffic at it, and show you exactly what's leaving — and how to stop it. No traffic routed through us, ever.
Self-hosted. No telemetry. Your tenant, your keys.