coming soon Cardea is in early access and this site is a preview. Details may change before launch.

Early access · Self-hosted or hosted in the EU

See everything your AI agents do. Stop what they shouldn't.

Cardea sits between your agents and the models they call. It identifies every agent, records every tool call, and stops risky calls before they leave your network.

Opens what is shut · Shuts what is open

how it works
How Cardea worksFive agents, including Claude Code, send calls to one Cardea gateway, which checks every call. Allowed calls go on to Anthropic, OpenAI or DeepSeek, and their responses come back. Denied calls are stopped inside the gateway and never reach a provider. AGENTS · IN YOUR SANDBOXES Claude Codecoding agent · dev laptops review-botopencode support-botAnthropic SDK claims-triageOpenAI SDK unknown10.4.2.19 · no credential Cardea Gateway one endpoint · keys held here ● fail-closed ✕ ✕ ✕ ✕ ✕ ✕ AUDIT · EVERY CALL LLM PROVIDERS Anthropicapi.anthropic.com OpenAIapi.openai.com DeepSeekapi.deepseek.com
call, allowed response denied by a check Illustrative.

01 — The problem

The sandbox protects the host. Nothing protects your data.

Agents no longer just answer prompts. They call tools, read and write files, and use credentials on their own. Docker, gVisor or Firecracker stop an agent from escaping to the kernel. They do not stop it from sending a customer record to a third-party model.

FAILURE MODE A

Leakage

There is no gate between your agents and the LLM provider. Secrets, API keys and personal data go straight through in prompts and tool results.

FAILURE MODE B

No audit trail

In healthcare, legal and finance you need a record of what the agent did: which tools, which data, in what order. API logs only show that a model was called.

sandbox → protects the host

  • ✕ crashing the host
  • ✕ reading /etc/passwd
  • ✕ unbounded RAM and CPU
  • ✕ escaping to the kernel

cardea → protects the system and data

  • ✓ anonymous callers
  • ✓ calls to models or tools it may not use
  • ✓ secrets and PII leaving in a payload
  • ✓ ten thousand calls a second
  • ✓ leaving no trace

You need both. Cardea does not replace your sandbox; it works with whichever one you already run.

02 — The governance pipeline

Six layers of control on every call.

Every call from an agent is checked before it reaches the model. Any layer can stop it, and a stopped call never leaves your network.

  1. 01

    Identification

    Every call is tied to a known, registered agent. Unknown or misconfigured callers are turned away before they reach a model.

  2. 02

    Policies

    Decide which models, tools and data each agent may use, and when. Policies are reviewable and versioned, and they change without downtime.

  3. 03

    Monitoring

    Call frequency, token volume, latency and error rates per agent, with alerts on anomalous behaviour.

  4. 04

    Filtering

    Catches secrets, API keys, personal data and prompt injection before they leave your network.

  5. 05

    Rate limiting

    Limits per agent and per model. A runaway loop hits a ceiling before it runs up your bill.

  6. 06

    Audit

    A record of who called, what they did, when, and what was decided, for every call, allowed or denied.

  • Fails safe

    If something goes wrong inside Cardea, calls are blocked, never waved through.

  • Keeps your keys

    Agents never hold your model provider keys, so they have none to leak.

  • Discreet refusals

    A refused caller gets a clear answer, not a map of your rules. The details go to your team.

  • Invisible when allowed

    Allowed calls work exactly as before, with no noticeable delay.

03 — The platform

Every agent, every call, as it happens.

The optional platform collects records from all your gateways. It shows a live feed of allowed and denied calls and a map of every host and agent your gateways have seen. It is hosted in the EU.

app.cardeahq.com / acme-health / production

Loading…

The Cardea platform, shown with sample data.

04 — Session traces

A record of what the agent did. Nothing it said.

Each model call, each tool the model asked for, and each result sent back, in order and on one timeline. When something goes wrong, you can see which step caused it without reading a single prompt.

session 2a1457d7… agent build-bot host ci-runner-03 4 calls · 3 tool calls · 17.4 s
sample data
step
0s5s10s15s20s
tokens / size
LLM claude-opus-5
58.1k → 141
└ tool Read
1.2 kB
LLM claude-opus-5
59.3k → 212
└ tool Bash
542 B
LLM claude-opus-5
60.1k → 96
└ tool Read
311 B
LLM claude-opus-5
✕blocked before reaching the provider · secret in tool result
not sent
model call time to first byte tool run by the agent What the prompts, arguments and results said is never stored.
Metadata, never content
Tool names, sizes and timings are recorded. What the prompt, arguments or results said is not.
Private by design
Spot repeated or suspicious content without anyone being able to read it back.
Scales with you
Add gateways as your agent fleet grows. Traces stay complete and consistent.
Your data, your tools
Use our platform, or export to the observability stack you already run.

05 — Adoption

Change one URL. Your agents keep working.

Point your agents at Cardea instead of the model provider. There's no SDK to add and no agent code to change. Claude Code, opencode and any Anthropic SDK work as they are.

  1. step 1

    Run the gateway

    In your cloud, on-prem or next to the agent, or use our EU-hosted service. Your provider keys stay with Cardea.

  2. step 2

    Register your agents

    Give each agent its own credential. Agents never hold a real provider key, so there's nothing for them to leak.

  3. step 3

    Point your agents at it

    Point your agents at Cardea. From then on, every call and every tool they use is identified and traced.

The gateway

required

Enforces policy and records activity in real time, as the calls happen. Run it yourself, or let us host it in the EU.

  • sidecar
    one per pod
  • central
    one per fleet
  • edge
    no cloud at all

The platform

optional

Collects records from all your gateways and shows the live feed, the agent map and session traces. It is hosted in the EU. You can use your own observability stack instead.

platform, or export to your SIEM

06 — Sovereignty

Your agents, your infrastructure, your jurisdiction.

Governance should not require sending your traffic to yet another third party. Cardea is designed so that you choose where the data goes, and it stays there.

deploy

Self-hosted or hosted in the EU

Run it on your own cloud or on-prem. If you prefer SaaS, it is hosted in Europe so data stays in the region.

intercept

No TLS interception

Agents route to Cardea explicitly. We do not spoof DNS or decrypt traffic; that approach is a GDPR grey area and we avoid it.

standards

Open formats, no lock-in

Built on open standards, with your data exportable at any time. Bring your own observability stack.

minimise

Data minimisation by default

Traces hold metadata only, never payload content. This page itself makes no third-party requests, except the pilot form when you submit it.

Built for regulated work
Framework What it asks for What Cardea records or enforces
EU AI Act Traceability and record-keeping for AI systems A record for every call, with agent, action, model, decision and the policy that took it
DORA Monitoring, anomaly detection, incident reconstruction Timings and an ordered trace of every agent session
GDPR Data minimisation, control over where data is processed Traces without content, self-hosting or EU hosting, no traffic decryption
ACPR · SOC 2 Access control and a log of external calls Authenticated agent identities, policy decisions and an audit log that includes denied calls

Cardea supplies evidence and controls. It does not make a system compliant by itself; compliance is still a property of your whole organisation.

07 — Why Cardea

Security is the product, not the upsell.

  1. i.

    Governs actions, not only model calls

    LLM gateways control access to the model: routing, spend and rate limits. Cardea also sees what the agent does with the tools, files and credentials it has been given.

  2. ii.

    Designed for compliance from the start

    Audit trails and controls are designed around healthcare, legal and financial requirements. They are part of the core, not a set of third-party plugins.

  3. iii.

    No paywall on safety

    Many tools offer a free, ungoverned base and charge for audit logs and PII controls. For a security buyer that is the wrong way round, so these are included.

What Cardea is not

A multi-provider LLM router
see LiteLLM, OpenRouter
A sandbox
use Docker, gVisor, Firecracker
A firewall or service mesh
network isolation is the sandbox's job
A secret manager
keep your existing vault
A cost optimiser
we govern; we don't route

Being explicit about scope matters. A governance tool that claims to do everything is harder to audit and to trust.

08 — Start a pilot

What do you need to see before you give an agent production credentials?

We are looking for a small number of design partners in healthcare, legal, finance and software.

→

30-day pilot

One agent, one workflow, deployed on your infrastructure. You get a complete trace of what that agent does.

→

Professional services

Integration, policy design and rollout support, fitted to your stack and your compliance requirements.

We use this only to reply to you. No newsletter, no resale.