Security & trust
Know exactly where your keys and prompts go.
Airelay sits between your applications and the providers, agents and APIs they call. Here's how we handle what passes through — stated plainly, without claims we can't back up.
Provider keys: yours, and kept out of the engine
Airelay is bring-your-own-key. Each provider bills your own account; we never pool your traffic onto a shared key or resell tokens.
Two ways to store a key
Injected per request
Write-only in the dashboard
Tenant isolation
Every organisation's gateway configuration is tagged and scoped to that organisation, and enforced on every request.
- Your routes live under your own path (/gw/<your-org>/) and can't claim another organisation's paths or hostnames.
- A consumer credential from one organisation is rejected on another organisation's routes, even if it's otherwise valid.
- Plugins you configure can only attach to your own services, routes and consumers — never globally.
- URLs and hosts you configure are checked so they can't point the gateway at internal or private network addresses.
- The gateway's own admin interface is on an internal network only and never exposed publicly.
Your data in flight
Prompts pass through Airelay on their way to the provider you chose, with your own key.
Redact before it leaves
Guard both directions
Content storage is opt-in
Team access and accountability
Invite your team with the least access they need, and see who changed what.
Role-based access
Audit log
Account security
Data residency
The gateway itself runs on Noviqent's UK-hosted infrastructure. Where your prompt goes next depends on the provider you route it to.
Region-pinnable providers
EU-based providers
Everyone else, labelled honestly
Provider residency options change. Always confirm against the provider's own current documentation before relying on a region for compliance purposes.
Questions about security?
We're happy to walk through how Airelay handles your data before you connect anything. Email hello@noviqent.co.uk.