Enterprise AI governance.
In your infrastructure.
Run the Axemere gateway on your own servers, cloud VMs, or Kubernetes cluster. Get the full enterprise feature set (centralized policy management, fleet analytics, approval workflows) with AI requests routed through infrastructure you own and operate.
Requires Core Platform: from $1,299/mo. See pricing →
How it works
The gateway runs on your infrastructure and connects to Axemere's control plane over an encrypted, authenticated channel. The control plane distributes policy and credential configuration to your gateway fleet. Your AI traffic never touches Axemere; it routes from your server directly to the AI provider.
Deploy the binary
Run the gateway on your VM, container, or bare-metal server. A single binary, no dependencies beyond PostgreSQL.
Connect to the control plane
Enroll the node with a bootstrap token. The control plane distributes policy bundles and credentials to your fleet.
Manage from the console
Set policies, rotate credentials, monitor analytics, and set budgets for all your nodes from console.axemere.ai.
Enterprise features. Your infrastructure.
The self-hosted gateway delivers the same enterprise capabilities as the Axemere-hosted fleet, without your data ever leaving your network.
AI traffic never transits Axemere
AI requests route from your infrastructure directly to AI providers. No AI traffic passes through Axemere's servers. Execution records flow to the console for visibility and audit.
Centralized policy, local enforcement
Policies are distributed from the control plane and enforced locally by the gateway. Policy decisions are made inside your perimeter, not in a SaaS call path.
Centrally managed credentials
Rotate an AI provider key once in the console and every gateway in your fleet picks it up automatically: no deployments, no application changes. For regulated deployments, local credential storage is also supported.
Tamper-evident audit trail
Every AI request generates a cryptographically signed execution record: provider, model, token counts, cost attribution, policy decision, workload, attribution, and more. Cryptographically signed records are independently verifiable: no blind trust required.
Private VPC and air-gap compatible
Deploy in a private subnet with no inbound ports. Works in air-gapped environments and supports on-premise AI model servers: no network re-architecture required. Runs on RHEL, Debian, or in a container.
Full fleet management from the console
The control plane distributes configuration and aggregates analytics across all your nodes. Manage policy, credentials, and workloads for your entire gateway fleet from a single console.
Self-managed vs. Managed gateway
Both deliver the same enterprise feature set. The difference is who operates the infrastructure.
| Self-managed | Managed (Axemere-hosted) | |
|---|---|---|
| Infrastructure | You provision and operate | Axemere operates |
| AI request path | Your infra → AI provider (Axemere not in path) | Axemere infra → AI provider |
| Enterprise features | Full (policy, analytics, approvals, audit) | Full (policy, analytics, approvals, audit) |
| Scaling & availability | You manage replicas and uptime | Axemere manages auto-scaling |
| Best for | Air-gapped environments, data sovereignty, compliance mandates, existing infrastructure | Teams that want enterprise features without operating infrastructure |
Looking for a fully-managed option? See the Managed Gateway →
Ready to deploy?
Create your account to get a bootstrap token, then connect your gateway to the control plane.
Deployment guides
Step-by-step guides for deploying the gateway on your infrastructure and connecting it to the control plane.