AI security proxy / evidence no. 001

Inspect
before
ingress.

Tamga intercepts every app-to-model request, seals PII and secrets, and enforces policy before a single token reaches the provider.

0.52ms scan p95
309 prompt corpus
self-hosted air-gap ready
Evidence intake
REQ_81A4F2 / SIMULATED TRACE
inline
inspection recordtrace: demo_9d43
01"email": "[REDACTED_EMAIL]"
02"card": "[REDACTED_CC]"
03"action": "REDACT"
04"latency_ms": 0.52
Policy precedence
BLOCK > REDACT > LOG > PASS
REDACT

Deploy in minutes, not weeks

One Docker Compose command. Zero architecture changes. Your existing LLM SDK calls route through Tamga transparently.

Deploy in 5 minutes
$git clone https://github.com/tamga/tamga.git
$cd tamga && docker compose up -d
>[SUCCESS] Tamga Proxy running on :8443
>[INFO] Admin API listening on :9090
>[READY] Accepting LLM traffic — 0ms cold start

One line changes everything

Change your base_url. That's the only code modification required. No SDK wrappers, no middleware.

Endpoint change / 01
OpenAI-compatible · 12 lines
import openai client = openai.OpenAI(    api_key = "sk-...",    base_url = "https://proxy.tamga.dev/v1",) # Every request now passes through Tamgaresponse = client.chat.completions.create(    model = "gpt-4",    messages = [{"role": "user", "content": "Hello"}])

See the engine work

Unprotected prompt vs. Tamga-protected request. PII redacted, injection blocked, audit logged.

01 / Unprotected request

Before Tamga

Unprotected
RequestPOST · JSON
curl -X POST https://api.provider.com/v1/messages {"prompt":"My card 4111 1111 1111 1111"}

Potential leak: raw PII reaches provider.

The example payload still contains the card number before inspection.

02 / Redacted request

Through Tamga

Protected
RequestPOST · JSON
curl -X POST https://proxy.tamga.dev/v1/messages {"prompt":"My card [REDACTED_CC]"}

Redacted before forwarding.

The forwarded request contains a redaction token in place of the card number.

Evaluated in your browser

Test the full policy path

Author a policy, inspect a payload, and verify the resulting decision and redaction record.

POLICY AUTHORING / EVALUATION

Policy Simulator

Politikayı YAML ile yazın, örnek prompt'a canlı aksiyon ve maskeleme sonucunu görün.

Policy editor

YAML → finding eşleşmesi; LOG/REDACT/BLOCK önceliğine göre nihai aksiyon belirlenir.

LIVE EVALUATION

Rules are evaluated from top to bottom. The first matching rule is used.

99 characters

EVALUATION RECORD

4 rules / 4 findings / 100% risk

FINAL ACTION

REDACT
TypeCategoryMatched ruleAction
piicredit_cardredact-pii-trREDACT
piiemailredact-pii-trREDACT
piitc_kimlikredact-pii-trREDACT
piiphone_trredact-pii-trREDACT
Policy precedenceBLOCK > REDACT > LOG > PASS

PAYLOAD INSPECTION / RESULTS

Try Tamga Live

Threat-hunting sandbox: payload inspector, analysis meter, and findings table.

Threat hunting sandbox

Patterns: tc_kimlik, phone_tr, email, credit_card, aws_access_key, prompt_injection

LOCAL DEMO

Payload inspector

Paste a request or load a sample, then inspect the result.

99 chars

The sample is evaluated in this page so you can inspect matching patterns before and after redaction.

Load a sample

Plain text request · JSON preview becomes available for valid JSON.

Inspection result

req_59b1eac4 snapshot

REDACT

Risk level · CRITICAL

100/100

Findings
4 detected
SeverityFinding typeData (redacted/key)RiskActionConfidenceDetails
CRİTİCALpii:credit_card4532…0366
96%
BLOCK0.95
HİGHpii:emailayse….com
84%
REDACT0.89
CRİTİCALpii:tc_kimlik1000…0146
96%
BLOCK0.95
HİGHpii:phone_tr+90 …4567
84%
REDACT0.89

Horizontal scroll reveals all columns on narrow screens.

Redacted payload
{
  "redacted_payload": "Customer: [REDACTED_EMAIL]\nTC: [REDACTED_TCKN]\nCall me at [REDACTED_PHONE]\nCard: [REDACTED_CC]"
}

Benchmark record / 01

Policy scanning, measured

Published figures from Tamga's adversarial test corpus. Review the method and source data in the benchmark report.

01 / Scan latency · p95

0.52ms

02 / Scan latency · p99

0.58ms

03 / Precision

96.9%

Corpus reference

309 prompts

Public adversarial test corpus

go run ./cmd/redteam
Recall
0.484
F1 score
0.646
Adversarial corpus
309 prompts
Inline scanners
7
Total overhead
< 2 ms

Precision 0.969 / Recall 0.484 / F1 0.646

Open benchmark report

OWASP LLM Top 10 Coverage

Tamga detects and mitigates every category in the OWASP LLM Application Security framework.

Event routing / 02

Evidence reaches your SOC

Send Tamga security events to the SIEM, alerting, and logging systems your team already operates.

Event source

Tamga

Policy decision → event record

Route to configured destination
Available destinations08 records
  • Splunk HEC

    SIEM

    JSON / CEF

  • Microsoft Sentinel

    SIEM

    Log Analytics

  • IBM QRadar

    SIEM

    LEEF

  • Datadog

    Observability

    JSON

  • Slack

    Alerting

    Webhook

  • PagerDuty

    Alerting

    Events API v2

  • Generic Webhook

    Custom

    JSON POST

  • Syslog

    Logging

    RFC 5424

Integration documentation

Control register / 03

Controls before ingress

Keep sensitive data and outbound model traffic under policy control, with an audit record for each decision.

Data boundary

Inspect.
Decide.
Record.

POLICY ENGINEINLINE
  1. 01

    KVKK & GDPR

    REG / 01

    Local processing with zero data retention. Redaction happens inline before an external API call.

    Data minimization
  2. 02

    PCI-DSS masking

    PAY / 02

    Credit card detection uses Modulus 10 (Luhn) validation; PAN data is redacted before provider ingress.

    PAN redaction
  3. 03

    Immutable audit trail

    LOG / 03

    Cryptographically verifiable event logging to PostgreSQL. Policy decisions are timestamped and queryable via SQL.

    Queryable record
  4. 04

    Zero-trust egress

    NET / 04

    Control outbound LLM traffic and block shadow AI providers by default; policies decide what may pass.

    Policy controlled

09 / Commercial register

Start free. Scale with confidence.

From self-hosted open-source to air-gapped enterprise — one pricing model that scales with your AI security maturity.

Billing interval
PLAN / 01TAMGA

Community

Self-hosted, open source

For individuals and small teams getting started with LLM security.

$0

per month

  • Unlimited self-hosted requests
  • PII + Secret + Injection scanners
  • YAML policy engine
  • Dashboard (single tenant)
  • Community support (GitHub)
  • 7/10 OWASP LLM coverage

Not included

  • No managed cloud
  • No SSO/SAML
  • No SLA
PLAN / 02Most popular

Team

Managed cloud for teams

Managed Tamga cloud for development teams up to 50 engineers.

$25

per developer / month

  • Everything in Community
  • Managed cloud (EU/US regions)
  • 10M requests / month
  • Custom entity patterns
  • Slack + email alerts
  • Email support (24h SLA)
  • 14-day audit log retention

Not included

  • No SSO/SAML
  • No custom contract
PLAN / 03TAMGA

Business

Production workloads

For production AI workloads with compliance and SLA requirements.

$500

per month, starting at

  • Everything in Team
  • Unlimited requests
  • SSO/SAML (Okta, Entra)
  • 90-day audit log retention
  • Priority support (4h SLA)
  • Quarterly security review
  • Dedicated Slack channel
  • Custom MSA/DPA
Contact sales
PLAN / 04TAMGA

Enterprise

Regulated industries

Air-gapped deployment, custom compliance, dedicated engineering.

Custom

tailored to your requirements

  • Everything in Business
  • Air-gapped / on-premise deployment
  • BYOK encryption
  • Custom compliance frameworks
  • Dedicated account engineer
  • 1-year+ audit retention
  • 99.99% uptime SLA
  • Custom integration support
Build your quote

02 / Capability record

Compare the controls

11 CAPABILITIES · 4 PLANS

Tamga plan comparison for self-hosted, managed cloud, security controls, support, and deployment capabilities.
CapabilityCommunityTeamBusinessEnterprise
01Self-hosted Included — — Included
02Managed cloud — Included Included Included
03PII + Secret + Injection Included Included Included Included
04YAML policy engine Included Included Included Included
05Custom entity patterns — Included Included Included
06SSO / SAML — — Included Included
07SSE streaming audit log Included Included Included Included
08OWASP LLM compliance reports Included Included Included Included
09Prioritized support SLA —24h4h1h
10Air-gapped deployment — — — Included
11Custom compliance framework — — — Included

All prices in USD. Volume discounts available for 50+ developers. Contact sales for custom pricing.

Next action / 04

Put policy in the request path.

Inspect application traffic before provider ingress. Start with the live policy simulator or talk with the Tamga team about deployment.