Skip to main content
Four Pillars · One Correlation ID · End-to-End Traceability

The AI Security Layer
Your Apps Need

API Security · MCP Security · AI Gateway · Verification Engine — unified by a single correlation ID propagated end-to-end.

Most stacks bolt four separate vendors together and lose the thread between them. G8KEPR is one platform with one correlation ID — a threat detected at the MCP layer traces back to the originating user request and forward to the API response. That is architecturally impossible without shared infrastructure.

Multi-Tier Detection
MCP Rug-Pull Detection
Auto Prompt Caching
4-Layer Verification
Tamper-Evident Audit
4
Pillars
1 correlation ID
94,000+
Training samples
24 categories
14
LLM providers
wired adapters + BYOI custom
Multi-tier
Detection pipeline
LLM tier off by default
4-layer
Output verification
integrity → constraint
11
Compliance frameworks
auto evidence
2,952
API endpoints
v1 / v2 / v3
21-layer
Middleware pipeline
on every request

4 Products. 1 Platform.

Everything you need to secure APIs and AI applications

API Security

Multi-tier detection · 94,000+ labeled attack samples · OWASP 10/10/10

A multi-tier detection pipeline (regex and ML classifier on every request; embeddings and NLI when their models load; LLM escalation off by default) with 0.788 recall and 0.857 precision on a 2,580-sample held-out set it was never trained on (3.12% false-positive rate).

ML detection across 24 attack categories (94,000+ labeled attack samples)
Shadow API auto-block · TLS / JA3 fingerprinting
7 evasion vectors handled (base64, NFKC, fragmentation)
Explore API Security

MCP Security

7-step pipeline · default-deny · rug-pull detect

MCP security with SHA-256 rug-pull detection on every tool definition and a default-deny tool-call path.

7-step security pipeline per tools/call
IndirectInjectionScanner · per-tool rate limits · MFA gating
Session replay · cross-session correlation analyzer
Explore MCP Security

AI Gateway

14 providers · auto prompt caching · adaptive breaker

One API across 14 providers (incl. BYOI custom). Auto-injects Anthropic prompt caching for 88% savings at 10 calls. Adaptive Z-score circuit breaker (opt-in). BYOK with AES-256-GCM.

Multi-factor adaptive routing · 8 guardrail policies
EU AI Act risk-class header on every completion
Hard 16,384 token cap · SSRF-protected transport
Explore AI Gateway

Verification Engine

4 layers · BLOCK-capable · SUGGEST action

Most AI guardrails detect-and-alert after bad output ships. G8KEPR is BLOCK-capable at middleware position 14 — four independent layers, six explicit failure modes, and a SUGGEST action that returns a compliant alternative instead of just an error.

Conversation Integrity · Source Grounding · Tool · Constraint
Two-pass schema enforcement (inject + validate)
Citation grounding · hash-chain drift detection
Explore Verification Engine
MarketplaceComing Soon

Plugin marketplace for extending G8KEPR with community-contributed integrations — not yet shipped. The four pillars above are live today.

Architecturally Impossible Without A Unified Platform

One Correlation ID. All Four Pillars.

A single AI-assisted request traverses every pillar in sequence, sharing one correlation ID end-to-end. A threat detected at the MCP layer traces back to the originating user request and forward to the API response.

API Security
WAF · rate limit · ML detector
AI Gateway
14 providers · cache · guardrails
MCP Interceptor
7-step · default-deny · rug-pull
Verification
4 layers · grounding · BLOCK
Audit Chain
SHA-256 hash · 3 verify levels
Single Correlation ID Propagated End-to-End
User Request LLM Provider Selected tools/call Intercepted
Tool Call Checked Output Verified (4 layers) Hash-Chain Entry Written
correlation_id ="a3f2-bee4-...-9c01" (shared across all rows above)
One query answers:
"Show me everything that happened as a result of request X — across all four pillars, in order."
Four-vendor stacks can't do this:
Each vendor has its own ID space. Stitching across them after-the-fact is forensic guesswork, not a single query.
What Each Capability Does by Default

Novel Technical Capabilities

Four capabilities in the platform, each marked with what it does on a default install.

Tool Definition Hash Registry

Rug-pull detection. Tool definitions hashed at tools/list time, re-verified on every tools/call. Mid-session mutation blocked with a CRITICAL event.

ENFORCINGSHA-256modules/mcp/tool_registry.py

Adaptive Z-Score Breaker

Statistical baselines per provider per hour-of-day, not static thresholds. Progressive recovery 10/25/50/100%. Off by default; enable with ADAPTIVE_CB_ENABLED.

OPT-IN3σ · 4 windowsgateway/router.py

Cross-Pillar Correlation

All four pillars publish findings to one internal threat event bus, and a correlator scores the ones that occur together into incidents. Today it joins findings that share a correlation ID.

ADVISORYone bus · 4 pillarsmodules/compound_correlator/

Tamper-Evident Audit System

Every security event written to append-only audit storage with SHA-256 integrity verification. Three verification levels (full, single, last-N). Evidence for SOC 2 CC7.2, HIPAA §164.312(b), FedRAMP AU-9.

ADVISORY7 modules · 3,866 LOCSHA-256 integrity

Platform FAQs

Common questions about the G8KEPR platform

G8KEPR runs alongside the API gateway you already use: your gateway handles routing, G8KEPR handles AI-specific threats and output verification. It brings an ML detector trained on 94,000+ labeled attack samples plus ~165 live regex rules, MCP security with SHA-256 rug-pull detection and a default-deny tool-call path, multi-LLM routing across 14 providers, and 4-layer output verification with a BLOCK-capable SUGGEST action.

Need help choosing the right features?

Talk to our solutions team →
Tamper-Evident Audit · 2,000+ Mapped Controls · 14 Frameworks

Auditors Get Exports, Not Spreadsheets

Every pillar writes per-request evidence into an HMAC-SHA256 hash chain. Control mappings are pre-built for the 14 frameworks listed above — a broader set than the 12 with automated assessment engines. Subject to independent audit and attestation — G8KEPR provides the technical controls and evidence; your auditor issues the certification.

115 controls
NIST 800-53 Rev5
55 controls
PCI DSS v4
197
CSA CCM v4
153
CIS Controls v8
110+
CMMC 2.0
106
NIST CSF 2.0
93
ISO 27001:2022
84
FedRAMP
72
NIST AI RMF
64
SOC 2
48
HIPAA
27
ISO 42001
23
EU AI Act
22
MITRE ATLAS
4 Products in 1 Platform

Start Securing Your APIs
And AI Agents Today

Four pillars, one correlation ID, hash-chain audit, and 2,000+ mapped controls across 14 compliance frameworks — without changing a line of your application code.

API + MCP security
14 LLM providers
4-layer verification
Cross-pillar correlation ID

No credit card required • 30-day free trial (extend to 90 days free) • Cancel anytime