Keys, identity, isolation, and audit evidence – all in your boundary.
One trust boundary every key, identity, tenant, and control you can prove.
Governing AI means controlling who can use which model, with what budget, under which policy and proving it to an auditor. DeepintShield unifies all of that: virtual keys that carry budget, limits, model allowlists, and agent identity; database-enforced tenant isolation; enterprise SSO and directory sync; and standards-mapped evidence on every decision – all self-hosted, with no data egress.
Key Features
Unified Virtual Keys
One credential carries budget, rate limits, model allowlists, guardrail/cache bindings, and agent identity - AES-256-GCM at rest with scheduled rotation.
Enforced Tenant Isolation
Database-level scoping makes cross-tenant reads or writes structurally impossible, backed by layered org / workspace / system RBAC.
Enterprise Identity
Self-hosted SAML 2.0 and multi-IdP OIDC SSO, SCIM 2.0 provisioning, and TOTP MFA - the old “Identity & Access,” done right.
Relationship-based Authorization
OpenFGA / ReBAC composed with ABAC in a
single verdict answers “can this principal reach this specific record?” (Business+).
Compliance evidence on every Decision
NIST AI RMF, ISO/IEC 42001, EU AI Act, and
MITRE ATLAS references emitted as columns on each export, plus a CycloneDX AIBOM.
Attestations
SOC 2 Type II evidence (held through hosted tiers, customer-managed when self-hosted) and a HIPAA BAA at Business and above.
AI governance multi-tenancy, LLM gateway virtual keys, RBAC for LLM API access, SCIM 2.0 provisioning, SAML/OIDC SSO, OpenFGA ReBAC, NIST AI RMF / ISO 42001 / EU AI Act evidence