API Security · MCP Security · AI Gateway · Verification Engine — unified by a single correlation ID propagated end-to-end.
Most stacks bolt four separate vendors together and lose the thread between them. G8KEPR is one platform with one correlation ID — a threat detected at the MCP layer traces back to the originating user request and forward to the API response. That is architecturally impossible without shared infrastructure.
Everything you need to secure APIs and AI applications
Multi-tier detection · 94,000+ labeled attack samples · OWASP 10/10/10
A multi-tier detection pipeline (regex and ML classifier on every request; embeddings and NLI when their models load; LLM escalation off by default) with 0.788 recall and 0.857 precision on a 2,580-sample held-out set it was never trained on (3.12% false-positive rate).
7-step pipeline · default-deny · rug-pull detect
MCP security with SHA-256 rug-pull detection on every tool definition and a default-deny tool-call path.
14 providers · auto prompt caching · adaptive breaker
One API across 14 providers (incl. BYOI custom). Auto-injects Anthropic prompt caching for 88% savings at 10 calls. Adaptive Z-score circuit breaker (opt-in). BYOK with AES-256-GCM.
4 layers · BLOCK-capable · SUGGEST action
Most AI guardrails detect-and-alert after bad output ships. G8KEPR is BLOCK-capable at middleware position 14 — four independent layers, six explicit failure modes, and a SUGGEST action that returns a compliant alternative instead of just an error.
Plugin marketplace for extending G8KEPR with community-contributed integrations — not yet shipped. The four pillars above are live today.
A single AI-assisted request traverses every pillar in sequence, sharing one correlation ID end-to-end. A threat detected at the MCP layer traces back to the originating user request and forward to the API response.
Four capabilities in the platform, each marked with what it does on a default install.
Rug-pull detection. Tool definitions hashed at tools/list time, re-verified on every tools/call. Mid-session mutation blocked with a CRITICAL event.
modules/mcp/tool_registry.pyStatistical baselines per provider per hour-of-day, not static thresholds. Progressive recovery 10/25/50/100%. Off by default; enable with ADAPTIVE_CB_ENABLED.
gateway/router.pyAll four pillars publish findings to one internal threat event bus, and a correlator scores the ones that occur together into incidents. Today it joins findings that share a correlation ID.
modules/compound_correlator/Every security event written to append-only audit storage with SHA-256 integrity verification. Three verification levels (full, single, last-N). Evidence for SOC 2 CC7.2, HIPAA §164.312(b), FedRAMP AU-9.
SHA-256 integrityCommon questions about the G8KEPR platform
Need help choosing the right features?
Talk to our solutions team →Every pillar writes per-request evidence into an HMAC-SHA256 hash chain. Control mappings are pre-built for the 14 frameworks listed above — a broader set than the 12 with automated assessment engines. Subject to independent audit and attestation — G8KEPR provides the technical controls and evidence; your auditor issues the certification.
Four pillars, one correlation ID, hash-chain audit, and 2,000+ mapped controls across 14 compliance frameworks — without changing a line of your application code.
No credit card required • 30-day free trial (extend to 90 days free) • Cancel anytime