The AI gateway for Australian organisations

Use every AI model, safely, with one firewall in front

LyfeAI Firewall sits between your people, your apps and AI providers. It protects sensitive data, cuts waste and gives you control, without rewriting a line of application code.

  • Australian identifiers built in
  • OpenAI and Anthropic compatible
  • Provider keys never leave the gateway

Illustrative mock-up with placeholder values. Not real customer data.

4 modesMonitor, redact, tokenise, block
4 APIsChat, responses, embeddings, messages
7 presetsEvery feature an on/off switch
1 keyPer app. Provider keys stay inside
One endpoint, every major provider
  • OpenAI
  • Anthropic
  • Azure AI Foundry
  • AWS Bedrock
  • Google Gemini
  • Mistral
  • Self-hosted models
The problem

AI is already in your organisation. Is anyone watching?

Staff paste client files into chat tools. Developers embed provider keys in code. Bills arrive with no owner. Each model and vendor has its own rules, or none.

  • Personal and client data leaves your control
  • Provider keys scattered across apps and laptops
  • No budget, no attribution, no audit trail
The solution

One gateway. One policy. Every model.

Route all AI traffic through LyfeAI Firewall. Apps use a gateway key against one familiar API. The firewall enforces policy, optimises the request and records what happened.

  • Sensitive data detected before it leaves
  • Provider keys held in one place
  • Every request attributed, budgeted and logged
Three pillars

Secure. Optimise. Control.

Everything the gateway does falls into one of three jobs.

Secure

Stop sensitive data, secrets and attacks before they reach a model, and scan what comes back.

  • PII: monitor, redact, tokenise or block
  • Secrets and credential detection
  • Prompt-injection detection
  • Response DLP scanning

Optimise

Spend less per answer and stay up when providers do not.

  • Safe prompt optimisation
  • Exact and opt-in semantic caching
  • Smart routing with explanations
  • Retries and failover

Control

Know who uses which model, for what, and at what cost.

  • Virtual keys, teams and budgets
  • Per-key model permissions
  • Audit logs and OpenTelemetry
  • Microsoft Entra single sign-on
Features

Everything between your apps and the model

Each capability is a switch. Turn on what you need, monitor before you enforce.

One API for every model

OpenAI-compatible and Anthropic-compatible, across providers.

Virtual keys, teams and budgets

Per-app keys, model permissions, budgets and rate limits.

PII protection, tuned for Australia

Detect Medicare, TFN, ABN, licence and passport numbers.

Secrets and credential detection

Catch API keys, tokens and passwords before they leave.

Prompt-injection detection

Flag and stop instruction-override attempts.

Response DLP scanning

Scan what comes back, not just what goes out.

Safe prompt optimisation

Trim wasted tokens without changing meaning.

Response caching

Exact caching by default. Semantic caching is opt-in.

Smart model routing

Right model for the task, with a reason you can read.

Retries and failover

Keep working when a provider does not.

Spend tracking and alerts

See cost by app, team, user, model and provider.

Audit logs and OpenTelemetry

A record you can stand behind, and export.

Policy presets, every feature a switch

Start from a preset. Every control is on or off.

Microsoft Entra single sign-on

Admin console sign-in with your existing identities.

How it works

A request, from app to answer

Every request passes through the same checks, in the same order, whichever model it is bound for.

How a request flows through LyfeAI Firewall Applications send requests to LyfeAI Firewall, which authenticates, scans, optimises and routes them to AI providers. Responses return through the same firewall where they are scanned, restored and logged. YOUR APPS Copilots and chatInternal toolsAI agentsScripts and SDKs LyfeAI Firewall llmfw.peritusdigital.com.au/v1 1 Authenticate, policy, budget2 Scan: PII, secrets, injection3 Optimise, cache, route4 Scan response, restore, log Audit log, spend tracking and OpenTelemetry export AI PROVIDERS OpenAIAnthropicAzure AI FoundryAWS BedrockGoogle GeminiMistral and self-hosted request response
  1. Your app sends a request

    Any OpenAI or Anthropic SDK, with a gateway key instead of a provider key.

  2. Authenticate and apply policy

    Key, team, model permissions, budget and rate limit are checked first.

  3. Scan the request

    PII, secrets and prompt-injection checks run. Content is redacted, tokenised, blocked or just monitored.

  4. Optimise and route

    Safe prompt clean-up, cache lookup, then the best model for the job, with failover ready.

  5. Provider responds

    The gateway holds the provider keys. Your apps never do.

  6. Scan the response and restore

    Response DLP runs, tokens are restored, and spend and audit records are written.

Use cases

Built for sectors that cannot be casual with data

Healthcare

Keep patient identifiers such as Medicare numbers out of prompts while clinicians and admin staff get the benefit of AI.

Healthcare preset

Finance

Tokenise account and tax identifiers, cap spend by desk, and keep an audit trail for review.

Finance preset

Government

Enforce approved models only, with strict blocking and region controls for sensitive information.

Government preset

Legal

Protect client confidences, restrict models per matter team and record every use.

High Security preset

Education

Give staff and students safe access with budgets per faculty and guard rails on personal data.

Default preset

Accounting

Handle TFNs and ABNs safely, with usage attributed to clients and teams for recharging.

Finance preset

Presets are starting points. They support, but do not by themselves ensure, your compliance obligations.

Integration

Change the base URL. Keep your code.

Use the official OpenAI SDK as you do now. Point it at the gateway and use a gateway key. Anthropic-style clients can use the same gateway.

  • Chat, responses, embeddings and messages endpoints
  • Streaming supported
  • Works with Python, Node, curl and any HTTP client
Read the quickstart
from openai import OpenAI

client = OpenAI(
    base_url="https://llmfw.peritusdigital.com.au/v1",
    api_key="sk-your-gateway-key",   # a gateway key, not a provider key
)

resp = client.chat.completions.create(
    model="gpt-4o",
    messages=[{"role": "user", "content": "Summarise this client file"}],
)
print(resp.choices[0].message.content)
FAQ

Questions we hear often

Do I have to change my application code?

Almost never. LyfeAI Firewall speaks the OpenAI and Anthropic APIs. In most cases you change the base URL and swap your provider key for a gateway key.

Which models and providers are supported?

OpenAI, Anthropic, Azure AI Foundry, AWS Bedrock, Google Gemini, Mistral and self-hosted models, all behind one endpoint. Your administrator chooses which are enabled.

What happens to sensitive data in a prompt?

You choose per policy: monitor it, redact it, replace it with a reversible token that is restored in the response, or block the request. Australian identifiers such as Medicare, TFN, ABN, driver licence and passport numbers are covered.

Do my applications still need provider API keys?

No. Provider keys live inside the gateway. Applications get gateway keys that you can limit, budget and revoke.

Will optimisation change what my prompts mean?

No. Optimisation is limited to safe changes such as whitespace, JSON compaction and duplicated context, and you can see the before and after token counts. It does not remove punctuation blindly.

Does semantic caching come on by default?

No. Exact caching is available by default and semantic caching is opt-in, because similar is not the same as identical.

Does it replace a security review?

No. It is a control layer that helps you enforce policy and gain visibility. Detection is probabilistic, so test it against your own data and keep your other safeguards.

How much does it cost?

Plans are Starter, Business and Enterprise. Pricing depends on your usage and requirements, so please contact us for a quote. Prices are quoted in AUD ex-GST.

Put a firewall between your people and AI

Request access and we will help you set up your first policy, key and budget.