00° · Self-hosted AI control point

The line between your apps and every AI model.

Every team ships data to AI providers and pulls untrusted content back, and almost no one can see what crosses that line. Meridian is a self-hosted gateway in front of every model you use, the major cloud providers and the private, open-weight models you run yourself: point your applications at it, no code change, and see, secure, govern, and prove every request from one place. Provide secure, resilient, observable access to all the models you use on your infrastructure or in the cloud.

  • self-hosted
  • no outbound telemetry
  • air-gap capable
  • no code change

01° · What it does

Six controls at one crossing.

Applications point at Meridian instead of the provider. These controls apply to every request and every response, across every provider and every key at once.

Policy firewall

Ordered INGRESS and EGRESS rules decide what crosses, with a hit count on every rule. Test changes in the simulator before they enforce anything.

ordered rules · hit counts · dry-run simulator

Guardrails & detection

Screening for PII, secrets, and exfiltration, plus model-backed prompt-injection detection. Both directions: what leaves, and what comes back.

pii · secrets · exfiltration · injection

Routing & resilience

One endpoint in front of every provider. Failover when one degrades, model mapping when names differ, content-based routing when policy says so.

failover · model map · content routing

Cost governance

Per-token pricing on every request, budgets per team and per key that enforce at the gateway. Spend stops at the door, not on the invoice.

live pricing · per-team · per-key caps

Observability & evidence

Live traffic as it crosses, a searchable request log, SIEM and metrics feeds, and an append-only, tamper-evident audit trail.

live view · request log · audit chain · siem

Self-hosted by design

Runs on your own infrastructure, in your cloud or data center. Secrets encrypted at rest, no outbound telemetry, and a fail-closed air-gap mode for disconnected environments.

self-hosted · encrypted at rest · air-gap

02° · How it works

Point your apps at the line.

Meridian speaks the provider APIs your applications already use. Swap one base URL and the whole transaction becomes visible, governable, and provable.

  1. Step 01

    Deploy

    Runs on your own infrastructure: a container in your cloud, a VM, or an air-gapped enclave. Secrets stay encrypted at rest.

  2. Step 02

    Repoint

    Swap the provider base URL for Meridian's endpoint. No SDK change, no code change.

    base_url = https://meridian.internal/v1
  3. Step 03

    Govern

    Author policies, budgets, and guardrails in one console. Simulate against real traffic first, then enforce.

03° · Who it is for

Four teams, one line of sight.

The same chokepoint answers a different question for each of them.

Security · CISO

Authorize AI use, then prove you did.

One place to enforce which models can be used and what data can leave, with injection detection on everything that comes back. Screening runs in both directions, on every key at once.

Platform · Infrastructure

One endpoint. Every provider behind it.

Failover, model mapping, and content-based routing without teaching your applications a second SDK. Add or retire providers behind the line, and nothing upstream changes.

Compliance · Legal · Risk

Evidence, not assurances.

A tamper-evident record of every request: who sent what, to which model, under which policy, with what verdict. Feed it to your SIEM or hand it to the auditor as is.

Finance · FinOps

Budgets that enforce, not report.

Per-token pricing on every request, caps per team and per key that stop spend at the gateway. The overrun ends at the cap, not at month end.

04° · The position

A model vendor sees one call. An in-app guard sees one agent. Meridian sees the whole transaction.

Point controls each watch a fragment. The durable value is the position: the one place that can authorize, protect, and prove enterprise AI use, self-hosted so the data and the evidence never leave your infrastructure.

  • Both directions

    What your data looks like leaving, and what untrusted content looks like coming back. Half the risk arrives in the response.

  • Every key at once

    One control point sees every team and every provider key in a single view, not one integration at a time. What each point tool sees as its own slice, you see as one stream.

  • Every request over time

    Patterns, drift, and evidence accumulate in one append-only trail. Point solutions forget; the position remembers.

05° · Pricing

Flat, capacity-based pricing. Never per token.

Metered control planes bill more as your AI use grows, a tax on the exact behavior you are trying to enable. Meridian is licensed by capacity: size it once, budget it once, and the marginal request costs nothing to govern.

  • Priced by deployment capacity, not by tokens or requests
  • Predictable line item, no month-end surprises
  • Governance you never have to ration

Talk to us about sizing

06° · Next

Draw the line.

See your own traffic cross it: policies, guardrails, budgets, and the audit trail, running on your infrastructure within the hour.