Skip to content

KYZON Gateway

Govern every prompt that leaves your organisation.

Gateway is the sovereign boundary between your organisation and every major AI model. One endpoint, logged, governed and policy-checked on Australian infrastructure, before anything crosses to a model.

The exposure

The liability crosses the border with your data.

Every prompt your organisation sends to a model provider crosses into another legal jurisdiction. Your data residency contract has no force on the other side of that line. Under CPS 234, CPS 230 and the Privacy Act automated-decision rules, the obligation to control where that data goes, and to show it, stays with you. Not the model provider.

If you operate in a regulated industry, this exposure is already yours:

  • APRA-regulated financial services
  • Government and the public sector
  • Healthcare and health services
  • Professional services holding client-confidential data

This is not a deadline you can wait out. The exposure accrues now, with every agentic call that crosses the boundary ungoverned, and it grows as your AI use grows. The Privacy Act automated-decision amendments on 10 December 2026 are the point the bill comes due, not the moment the risk begins.

prompts →the APIyour data residency contractYOUR ORGANISATION · AUSTRALIAMODEL PROVIDER · OFFSHORE

The governed boundary

One endpoint. Every model. Under your control.

Gateway sits on the boundary as the checkpoint every request passes through. Point your application at one endpoint and Gateway routes to every major model provider, logging each request, enforcing your policies, and keeping the record on Australian infrastructure before anything crosses.

What happens to every request:

  • Logged. Every request and response captured to your audit trail on AWS Sydney.
  • Governed. Your organisation's policies enforced before the request leaves.
  • Policy-checked. Requests evaluated against the controls your compliance team sets.

Adoption is a base-URL change. Gateway is compatible with the OpenAI SDK, so your engineers point at Gateway instead of the provider and keep their existing code.

All of this runs today. A demo shows live policy enforcement on real inference, the request logs and admin view, and routing through AWS Sydney, in your regulatory context.

YOUR ORGANISATIONAustraliaKYZON GATEWAYLoggedGovernedPolicy-checkedAWS SYDNEY · ap-southeast-2JURISDICTION BOUNDARYMODEL PROVIDERSoffshore

Why not the alternatives

The two options regulated teams weigh, and where each falls short.

A foreign hosted gateway

Routing through an offshore gateway solves latency and convenience. It does not solve sovereignty. Your data still leaves the jurisdiction, and the same contract-stops-at-the-border problem applies one layer down. Foreign infrastructure cannot give you Australian data residency.

Building it in-house

You can build the proxy. Then you own the governance layer, the audit logging, the policy engine, and a multi-year certification calendar, SOC 2, ISO 27001, IRAP, on your own roadmap, while the exposure keeps accruing. Gateway is that layer, built and on a certification path, so you do not start from zero.

Why trust this now

Built to clear your procurement process, not just your technical review.

An early vendor is hard to onboard. We know that is the real blocker. Here is what makes Gateway clearable.

It is real, and you can see it

Gateway runs today. The demo is live inference through Australian infrastructure, not a deck. Unproven is the easiest objection to answer when you can watch it work.

Named advisers, on the record

Gateway is advised by Jim Cooper, Co-Managing Director of Unfinished Ventures.

Regulated organisations are testing it now

Design partners in regulated industries are running Gateway in evaluation today.

Contractual audit rights

Standard in our enterprise agreements. Your auditor can examine us directly, which is what your risk function will ask for first.

A dated certification roadmap

SOC 2 Type II in progress, then ISO 27001 and APRA-aligned documentation, then IRAP assessment. Honest status, not badges we have not earned.

A brief built for your risk team

The compliance brief is structured for legal, risk and procurement to evaluate, framework by framework. The document your champion forwards internally.

Read the compliance brief

The calendar time these certifications take is also why the Australian regulated segment has roughly 18 to 24 months of near-zero sovereign competition. The work that makes a vendor hard to clear is the same work that keeps the field empty.

See it run in infrastructure that looks like yours.

A 30-minute Gateway walkthrough. Live policy enforcement, the audit log, routing through AWS Sydney. Your regulatory context. No slides.

Read the compliance brief