Skip to content

AI transformation · Control plane

AI and MCP Gateway

Put every model call and every agent tool call behind one governed endpoint. Silex designs, deploys, and operates Kong AI Gateway and Kong Konnect so your teams can use any model provider under one set of controls.

At the gateway

  • AI proxying and failover
  • Prompt guards
  • PII sanitization
  • Semantic caching
  • Token rate limits and budgets
  • MCP authorization with OAuth 2.0

The problem

AI adoption moved faster than AI controls.

When each team connects to model providers on its own, nobody can answer basic questions about spend, safety, or what the AI systems did.

No cost visibility

Token spend is tracked per application, if at all, so no one can see total spend or which teams drive it.

Inconsistent guardrails

Prompt injection checks and PII handling vary by application, and some applications have none.

No audit trail

There is no central record of prompts, identities, models, and responses for an audit or an incident review.

Agents widen the surface

Agents that call internal tools need per-tool access control, credential isolation, and a log of every call.

What we deliver

One endpoint, one set of controls.

Routing

Multi-provider routing and failover

Route requests to Anthropic, Amazon Bedrock, Azure OpenAI, and self-hosted models from one endpoint, with automatic failover when a provider goes down.

Guardrails

Guardrails at the gateway

Prompt injection detection, PII redaction, and provider guardrails such as Amazon Bedrock Guardrails, applied to every application without code changes.

Agents

MCP gateway

OAuth, token exchange, per-tool access control, rate limits, and audit logging for every MCP tool call. Existing REST APIs become MCP tools with no backend code.

Cost

Token budgets and semantic caching

Budgets by team stop spend at the limit you set, and repeated questions are served from cache.

Developers

Developer portal

A governed path to AI services with documentation and self-service onboarding, so teams choose the controlled route.

Operations

Configuration as code

Gateway configuration in Git, deployed through CI/CD, with metrics and logs sent to Prometheus, Grafana, OpenTelemetry, and your SIEM.

Architecture

Your data plane, a hosted control plane.

The Kong data plane runs in your infrastructure and processes all AI traffic. Kong Konnect manages configuration, access, and analytics from the cloud, and the data plane keeps running if that connection drops.

Kong Konnect · hosted control planeConfiguration, role-based access, developer portal, analytics, policy distribution

Outbound TLS only · no inbound ports

Consumers
Applications
Agents and MCP clients
Claude Code and developer tools
Kong data plane · your infrastructure

Processes every request, runs every plugin, caches configuration locally. Sensitive data stays inside your environment.

AI ProxyRouting and failover
Prompt GuardInjection detection
AI SanitizerPII redaction
Semantic CacheCost and latency
Rate LimitingToken budgets
MCP ProxyAgent governance
Models and tools
Anthropic API
Amazon Bedrock
Azure OpenAI
Self-hosted models on vLLM
MCP servers and internal APIs

Frameworks

Mapped to the frameworks your auditors use.

  • NIST AI Risk Management Framework
  • OWASP Top 10 for LLM Applications
  • OWASP guidance for agentic applications
  • HIPAA safeguards for PHI in prompts and responses

Build or buy

An internal gateway becomes a product to maintain.

Teams with strong engineers often start building their own gateway. Routing, authentication, failover, caching, logging, and security plugins turn it into an open-ended platform project. Silex runs a structured evaluation of commercial gateways against your requirements and recommends the one that fits.

How we engage

From inventory to managed platform.

  1. 01

    Assess

    Workshops with your AI, security, and platform teams produce an inventory of every current and planned AI integration.

  2. 02

    Design

    A deployment blueprint covers topology, plugin priorities, consumer groups, CI/CD, and observability, reviewed before anything is installed.

  3. 03

    Build

    Control plane first, then data planes, then plugins in priority order, all managed as code.

  4. 04

    Operate

    Forward Deployed Engineers onboard new AI and MCP use cases, build custom plugins, and run quarterly governance reviews.

  5. 05

    Transfer

    Structured knowledge transfer moves day-to-day operation to your team.

Platforms

What we build with.

Certified Delivery Partner

Select Tier Services Partner

Premier Partner

Kong AI Gateway · Kong Konnect · Anthropic Claude · Amazon Bedrock · Azure OpenAI · vLLM · Redis · PGVector · Keycloak · Prometheus · Grafana · OpenTelemetry

Questions buyers ask

Questions

Why not connect applications to the model providers directly?

Direct connections leave each team to solve credentials, guardrails, cost tracking, and failover on its own. The gateway applies those controls once, for every application, and gives you one audit trail.

Does the gateway add latency?

Kong reports under 5 ms of added latency per request. Semantic caching often shortens the end-to-end response for repeated questions.

Does sensitive data leave our environment?

No. The data plane runs in your infrastructure and processes prompts and responses there. The hosted control plane manages configuration and analytics.

Can we use models from more than one provider?

Yes. Applications call one endpoint, and the gateway routes to Anthropic, Amazon Bedrock, Azure OpenAI, or self-hosted models. Adding a provider does not require changes to your applications.

How do you govern MCP servers we did not build?

Third-party MCP servers sit behind the same gateway, with tool-level access lists mapped to roles and the same audit logging as your own servers.

Next step

Book an AI Governance Readiness Review.

We inventory your current and planned AI integrations, assess them against NIST AI RMF and OWASP guidance, and deliver a gateway reference architecture.