Now in Private Beta

Stop Sensitive Data from Reaching AI Providers

Secure, compliance-first AI gateway with PII protection, cost controls, and full audit trails. Deploy in minutes, not months.

Crafted for healthcare, insurtech and fintech companies.

SOC 2 Type II GDPR HIPAA Ready
Try Tractii AI

Ask about AI governance & compliance

Ask about AI governance, PII protection, or compliance features.

20+
PII/PHI Patterns
<25ms
Latency Overhead
99.9%
Uptime SLA
7 Years
Audit Retention

Production-Ready in Three Steps

No infrastructure changes. No lengthy implementation. Just point your API calls to Tractii.

1

Point

Change one line of code to route AI calls through Tractii. Works with any OpenAI or Anthropic integration.

// Before
const client = new OpenAI();

// After
const client = new OpenAI({
  baseURL: "https://gateway.tractii.com/v1"
});
2

Protect

Tractii automatically scans requests for 20+ PII patterns, enforces your policies, and logs everything.

  • SSN, credit cards, medical records
  • Block, redact, or log-only modes
  • Custom patterns for your data
3

Prove

When auditors ask, you're ready. Export compliance reports with cryptographic integrity verification.

  • HIPAA-mapped audit trails
  • SOC 2 evidence packages
  • 7+ year immutable retention
Your App
Contains PII
Tractii Gateway
PII Scan Audit Log Policies
PII Redacted
OpenAI Anthropic, etc.
Audit logs stored inyour S3 bucket

AI Governance Platform

Policy controls, PII detection, compliance audit trails, and cost management for enterprise AI deployments.

Core Feature

PII Detection

Real-time masking for SSN, email, phone, credit card, and 15+ additional data types with custom pattern support.

Core Feature

Compliance Audit

Immutable request/response logging with 7+ year retention. Export to S3, BigQuery, or your SIEM.

AI Governance

Configure role-based access controls, model restrictions, and usage quotas per user and team.

Cost Control

Per-model token pricing, team budgets, and threshold alerts. Real-time usage analytics dashboard.

Multi-Provider

Route to OpenAI, Anthropic, Google, Azure, or custom endpoints. Single API, no vendor lock-in.

Bring Your Own Storage

Audit logs write directly to your S3 bucket. Your encryption keys, your data residency, full sovereignty.

Full compliance from $299/month · View pricing →

Built for Regulated Industries

Purpose-built for teams where compliance isn't optional

Healthcare

HIPAA

Protect PHI in clinical AI workflows, scribes, and patient communications

  • AI medical scribes
  • Prior authorization
  • Clinical documentation

Insurance

State Audits

Audit trails for claims processing, underwriting, and customer service AI

  • Claims automation
  • Underwriting assistance
  • Policyholder support

Financial Services

SEC/FINRA

Compliant AI for trading, advisory, and customer communications

  • Research analysis
  • Client communications
  • Risk assessment

Legal

Privilege

Protect attorney-client privilege in contract review and legal research

  • Contract analysis
  • Legal research
  • Document review

Enterprise-Ready Compliance

Meet regulatory requirements without slowing down your team. Tractii automatically detects and masks PII before it reaches your AI providers.

SOC 2 Type II
GDPR
HIPAA Ready
  • Automatic PII/PHI detection for 20+ data types
  • Immutable audit logs with 7+ year retention
  • Role-based access controls with SSO
  • Data residency controls for EU, US, APAC
What you send
What reaches the AI
{
  "messages": [{
"role": "user",
"content": "Summarize the visit notes for Maria Garcia, DOB 03/15/1985, MRN 847293. Diagnosis: Type 2 diabetes, prescribed Metformin."
}] }
{
  "messages": [{
"role": "user",
"content": "Summarize the visit notes for [NAME], DOB [DOB], MRN [MRN]. Diagnosis: Type 2 diabetes, prescribed Metformin."
}] }
✓ Full audit log preserved in your environment · Original data never reaches AI provider

Bring Your Own Storage

Audit logs write directly to your S3 bucket. We never store your data.

Your Keys, Your Control

Use your own KMS encryption keys. Full data sovereignty guaranteed.

Data Residency

Store in any region. Meet EU, US, or APAC compliance requirements.

Enterprise compliance without enterprise pricing

HIPAA and SOC 2 included from day one. No "contact sales" gates, no $2,000/month enterprise tiers.

Free

$0 /month

For evaluation and proof of concept

  • 10,000 requests/month
  • 7-day log retention
  • 2 team seats
  • PII detection (log mode)
  • PII blocking & redaction
  • SOC 2 report access
  • HIPAA + BAA

See it in action first

Private Beta

Pro

$299 /month

Production workloads with full compliance

  • 250,000 requests/month
  • 90-day log retention
  • Unlimited seats
  • Full PII detection + redaction
  • SOC 2 report access
  • HIPAA + BAA included
  • Email support (48h SLO)

Beta customers lock in pricing for 12 months

Need more than 250k requests? Overages billed at $12/100k. No hard cutoffs—we never break production traffic.

For comparison: HIPAA-compliant AI observability typically starts at $800–2,500/month elsewhere.

Frequently Asked Questions

One API call proxied through Tractii equals one request. Streaming responses count as a single request, regardless of the number of chunks.

We notify you at 80% and 100% of your limit. Overages are billed at $12 per 100k requests. We never cut off production traffic—compliance workflows shouldn't break because of billing.

Yes. The HIPAA Business Associate Agreement is included in Pro at no additional cost. No enterprise upgrade required, no extra legal fees.

Three modes: Block rejects requests containing PII (returns 400 error). Redact replaces PII with tokens like [SSN] before forwarding. Log allows requests through but records detections for your audit trail.

20+ patterns including SSN, credit cards, emails, phone numbers, dates of birth, and healthcare-specific identifiers like MRN, NPI, Medicare IDs, and ICD-10 codes. You can also add custom patterns.

Yes. Beta customers lock in $299/month for 12 months after general availability, even if published pricing increases.

Most teams can be production-ready in under an hour. It's a one-line code change. Just point your API base URL to Tractii's gateway.

Proxied requests can be stored by Tractii by default but Bring Your Own Storage (BYOS) configuration is offered for all plans. Proxied requests and audit logs write directly to your S3 compatibale bucket. We never store your request or response bodies on our infrastructure with BYOS configured.

Deploy AI governance in your environment

Schedule a technical demo and be production-ready in under an hour.

Free pilot available for qualified teams · No credit card required