HIPAA compliance for AI, from first prototype to production scale

The LLM Gateway enforces HIPAA compliance controls across your AI systems, no matter how many providers you add or how much PHI moves through them.

HIPAA compliance for AI, from first prototype to production scale

The LLM Gateway enforces HIPAA compliance controls across your AI systems, no matter how many providers you add or how much PHI moves through them.

HIPAA compliance for AI, from first prototype to production scale

The LLM Gateway enforces HIPAA compliance controls across your AI systems, no matter how many providers you add or how much PHI moves through them.

“Our view: AI in healthcare must be trustworthy, traceable, and controllable, and we won’t compromise security for speed.”

A BAA is just the start of what it takes to safely run the AI your team is already using.

Audit logging, PHI de-identification, and detection for prompt injection or harmful outputs are still your responsibility, whether you're building AI products or internal workflows. With LLM Gateway, you get all those controls under one BAA.

Audit logging, PHI de-identification, and detection for prompt injection or harmful outputs are still your responsibility, whether you're building AI products or internal workflows. With LLM Gateway, you get all those controls under one BAA.

BAA coverage, audit logging, and access control

BAA coverage across every model you use, with every prompt and response logged automatically. Admins control alerts, restrict which models are allowed through the gateway, and can control access by provider, model, or version.

BAA coverage across every model you use, with every prompt and response logged automatically. Admins control alerts, restrict which models are allowed through the gateway, and can control access by provider, model, or version.

Cost and usage controls

Set budget limits per scope and automatically stop excess spend so a runaway agent loop doesn't become an incident. Usage is tracked by model, so you can monitor which models are driving the most spend.

Set budget limits per scope and automatically stop excess spend so a runaway agent loop doesn't become an incident. Usage is tracked by model, so you can monitor which models are driving the most spend.

Coming soon

De-identification and safety guardrails, defined in your code

Aptible's AI SDK gives you the same protections as other SDKs, but it's tuned specifically for HIPAA and other regulated use cases. Use it to de-identify PHI before it reaches the model, catch prompt injection and jailbreak attempts, and block harmful, hallucinated, or unsafe outputs.

Aptible's AI SDK gives you the same protections as other SDKs, but it's tuned specifically for HIPAA and other regulated use cases. Use it to de-identify PHI before it reaches the model, catch prompt injection and jailbreak attempts, and block harmful, hallucinated, or unsafe outputs.

View docs

Building for the AI-native era

AI is raising the bar on what attackers can do and what regulated buyers expect from their infrastructure. Some of LLM Gateway's highest-usage accounts already run Claude Code and other coding agents against regulated data, often without governance built specifically for that pattern. Here's what's coming soon to close that gap.

Budget alerts & usage reporting

Get alerted before a key hits its spend limit, with usage broken down by key, model, and scope.

Secure cloud-hosted agents

Run agents in a sandboxed environment with no open network access, routing every request through the Gateway.

Data residency

Keep all gateway infrastructure within a required region. Keys are automatically restricted to in-region models.

Product roadmap

Without a gateway, you’re building and maintaining all of this yourself.

With separate platforms and diy

Compliance controls

BAA coverage

One BAA covers AI Gateway usage

Separate BAAs per provider

Audit logging

Prompts, responses, and metadata logged automatically

Build and maintain your own logging pipeline

Log retention

Aptible provides long-term log storage and search

Design and maintain your own export process to meet HIPAA retention requirements

Model access

Every provider under one BAA, including open-weight models

Separate BAA and integration per provider

No model training on PHI

Enforced at infrastructure layer

Rely on provider policy and configuration

Breach investigation

Logs and activity history available immediately for audits or incident investigation

Reconstruct activity across systems during audits or breach reviews

Accesss management & governance

Model access controls

Restrict models per scope

Manage access separately per provider and integration

Cost attribution

Usage tracked per scope and model

Aggregate bill with limited breakdown and across cost dashboards from different providers

Data protection

De-identification (coming soon)

Scrub PHI before sending to a model or logs, re-identifying before responding to application

Build and maintain your own PHI de-identification pipeline

Prompt injection and harmful output detection (coming soon)

Configurable guards, with best practices on by default

Build and maintain your own detection

Consistency across models

Same controls regardless of provider

Re-implement safeguards per integration

Observability

Request inspection

View actual prompts and responses

Build dashboards or search raw logs

Audit readiness

Evidence available immediately

Reconstruct activity during audits

Cost and operations

Budget enforcement

Set hard stops for requests to limit spend

Monitor spending manually

Protocol translation

Same keys work across supported providers

Maintain separate integrations

Capacity management

Managed within the LLM Gateway

Manage rate limits and availability yourself

Provider failover

Requests fail over automatically when another provider serves the same model

Detect the outage and build your own retry and fallback logic

Time to safe usage

Immediate

Weeks to months

Use Cases

Why teams choose Aptible

From a team's first AI feature to an advanced builder's full production stack, the LLM Gateway covers the compliance and safety controls regulated teams actually need.

Use Cases

Why teams choose Aptible

From a team's first AI feature to an advanced builder's full production stack, the LLM Gateway covers the compliance and safety controls regulated teams actually need.

Get through health system security reviews faster

Security review evidence is available for all model usage instantly, so you can turn a conversation that used to kill deals into a non-issue.

Protect PHI from model training

Training on PHI is disabled at the infrastructure layer; that protection holds regardless of any provider's own data-use policy or default settings.

Separate keys for internal tools and production AI

Give internal automations and agent harnesses their own keys so usage is attributable, with an org-wide spend limit that stops runaway loops before they become an incident.

Stay online when a model provider goes down

When a model is served by more than one provider, the gateway fails over automatically; you can also name backup models in the request and the gateway tries each in order.

FAQs

How much does LLM Gateway cost?

What happens when I hit my spend limit?

How do I stay in the loop on new features?

Which model providers are covered?

Does integrating LLM Gateway require any changes to my existing applications?

Can't find an answer to your question? Contact us for help

Can't find an answer to your question? Contact us for help

Built for teams shipping AI in regulated environments

One gateway. One BAA. Every model you need.

Built for teams shipping AI in regulated environments

One gateway. One BAA. Every model you need.

Built for teams shipping AI in regulated environments

One gateway. One BAA. Every model you need.