01 / Unprotected request
Before Tamga
curl -X POST https://api.provider.com/v1/messages {"prompt":"My card 4111 1111 1111 1111"}Potential leak: raw PII reaches provider.
The example payload still contains the card number before inspection.
Tamga intercepts every app-to-model request, seals PII and secrets, and enforces policy before a single token reaches the provider.
One Docker Compose command. Zero architecture changes. Your existing LLM SDK calls route through Tamga transparently.
Change your base_url. That's the only code modification required. No SDK wrappers, no middleware.
import openai client = openai.OpenAI( api_key = "sk-...", base_url = "https://proxy.tamga.dev/v1",) # Every request now passes through Tamgaresponse = client.chat.completions.create( model = "gpt-4", messages = [{"role": "user", "content": "Hello"}])Unprotected prompt vs. Tamga-protected request. PII redacted, injection blocked, audit logged.
01 / Unprotected request
curl -X POST https://api.provider.com/v1/messages {"prompt":"My card 4111 1111 1111 1111"}Potential leak: raw PII reaches provider.
The example payload still contains the card number before inspection.
02 / Redacted request
curl -X POST https://proxy.tamga.dev/v1/messages {"prompt":"My card [REDACTED_CC]"}Redacted before forwarding.
The forwarded request contains a redaction token in place of the card number.
Author a policy, inspect a payload, and verify the resulting decision and redaction record.
POLICY AUTHORING / EVALUATION
Politikayı YAML ile yazın, örnek prompt'a canlı aksiyon ve maskeleme sonucunu görün.
Policy editor
YAML → finding eşleşmesi; LOG/REDACT/BLOCK önceliğine göre nihai aksiyon belirlenir.
Rules are evaluated from top to bottom. The first matching rule is used.
EVALUATION RECORD
4 rules / 4 findings / 100% risk
FINAL ACTION
REDACT| Type | Category | Matched rule | Action |
|---|---|---|---|
| pii | credit_card | redact-pii-tr | REDACT |
| pii | redact-pii-tr | REDACT | |
| pii | tc_kimlik | redact-pii-tr | REDACT |
| pii | phone_tr | redact-pii-tr | REDACT |
PAYLOAD INSPECTION / RESULTS
Threat-hunting sandbox: payload inspector, analysis meter, and findings table.
Threat hunting sandbox
Patterns: tc_kimlik, phone_tr, email, credit_card, aws_access_key, prompt_injection
Paste a request or load a sample, then inspect the result.
The sample is evaluated in this page so you can inspect matching patterns before and after redaction.
Load a sample
Plain text request · JSON preview becomes available for valid JSON.
req_59b1eac4 snapshot
Risk level · CRITICAL
100/100
| Severity | Finding type | Data (redacted/key) | Risk | Action | Confidence | Details |
|---|---|---|---|---|---|---|
| CRİTİCAL | pii:credit_card | 4532…0366 | 96% | BLOCK | 0.95 | |
| DETAIL RECORDcategory=credit_card · match=4532…0366 · severity=critical · confidence=0.95 | ||||||
| HİGH | pii:email | ayse….com | 84% | REDACT | 0.89 | |
| DETAIL RECORDcategory=email · match=ayse….com · severity=high · confidence=0.89 | ||||||
| CRİTİCAL | pii:tc_kimlik | 1000…0146 | 96% | BLOCK | 0.95 | |
| DETAIL RECORDcategory=tc_kimlik · match=1000…0146 · severity=critical · confidence=0.95 | ||||||
| HİGH | pii:phone_tr | +90 …4567 | 84% | REDACT | 0.89 | |
| DETAIL RECORDcategory=phone_tr · match=+90 …4567 · severity=high · confidence=0.89 | ||||||
Horizontal scroll reveals all columns on narrow screens.
{
"redacted_payload": "Customer: [REDACTED_EMAIL]\nTC: [REDACTED_TCKN]\nCall me at [REDACTED_PHONE]\nCard: [REDACTED_CC]"
}Benchmark record / 01
Published figures from Tamga's adversarial test corpus. Review the method and source data in the benchmark report.
0.52ms
0.58ms
96.9%
Corpus reference
309 prompts
Public adversarial test corpus
go run ./cmd/redteamPrecision 0.969 / Recall 0.484 / F1 0.646
Open benchmark reportTamga detects and mitigates every category in the OWASP LLM Application Security framework.
Event routing / 02
Send Tamga security events to the SIEM, alerting, and logging systems your team already operates.
Tamga
Policy decision → event record
Splunk HEC
SIEMJSON / CEF
Microsoft Sentinel
SIEMLog Analytics
IBM QRadar
SIEMLEEF
Datadog
ObservabilityJSON
Slack
AlertingWebhook
PagerDuty
AlertingEvents API v2
Generic Webhook
CustomJSON POST
Syslog
LoggingRFC 5424
Control register / 03
Keep sensitive data and outbound model traffic under policy control, with an audit record for each decision.
Data boundary
Local processing with zero data retention. Redaction happens inline before an external API call.
Credit card detection uses Modulus 10 (Luhn) validation; PAN data is redacted before provider ingress.
Cryptographically verifiable event logging to PostgreSQL. Policy decisions are timestamped and queryable via SQL.
Control outbound LLM traffic and block shadow AI providers by default; policies decide what may pass.
09 / Commercial register
From self-hosted open-source to air-gapped enterprise — one pricing model that scales with your AI security maturity.
Self-hosted, open source
For individuals and small teams getting started with LLM security.
per month
Not included
Managed cloud for teams
Managed Tamga cloud for development teams up to 50 engineers.
per developer / month
Not included
Production workloads
For production AI workloads with compliance and SLA requirements.
per month, starting at
Regulated industries
Air-gapped deployment, custom compliance, dedicated engineering.
tailored to your requirements
02 / Capability record
11 CAPABILITIES · 4 PLANS
| Capability | Community | Team | Business | Enterprise |
|---|---|---|---|---|
| 01Self-hosted | Included | — | — | Included |
| 02Managed cloud | — | Included | Included | Included |
| 03PII + Secret + Injection | Included | Included | Included | Included |
| 04YAML policy engine | Included | Included | Included | Included |
| 05Custom entity patterns | — | Included | Included | Included |
| 06SSO / SAML | — | — | Included | Included |
| 07SSE streaming audit log | Included | Included | Included | Included |
| 08OWASP LLM compliance reports | Included | Included | Included | Included |
| 09Prioritized support SLA | — | 24h | 4h | 1h |
| 10Air-gapped deployment | — | — | — | Included |
| 11Custom compliance framework | — | — | — | Included |
All prices in USD. Volume discounts available for 50+ developers. Contact sales for custom pricing.
Next action / 04
Inspect application traffic before provider ingress. Start with the live policy simulator or talk with the Tamga team about deployment.