Skip to main content
Nirmata AIControls · Documentation

Every AI call, governed.

AIControls sits between your team's AI tools and the models they call. One endpoint gives you identity, budgets, policy enforcement, and a complete audit trail — with zero changes to how developers work.

Your AI tools
Claude Code
Cursor
Codex
Copilot
AIControls
identity
policy
budget
audit
allowdenyapprove
Model providers
Anthropic
OpenAI
Azure OpenAI
Bedrock

Why teams run AIControls

See everything

Every prompt, tool call, model, token, and policy decision — attributed to a person and recorded in one audit log you can search, export, and hand to an auditor.

Audit Log
Spend with intent

Budgets per organization, team, or developer, enforced at request time. Warnings before the limit; hard stops, approvals, or model downgrades at it.

Cost Governance
Enforce, don’t hope

CEL policies allow, deny, rewrite, or route a request to a human approver — evaluated inline, before anything reaches the model or an MCP server.

Policies

How it works

  1. Point your tools at one endpoint. Two lines of configuration per tool. No agents to install, no SDKs to integrate, no API keys on developer machines.
  2. Every call is evaluated inline. Identity, policy, budget, and content safety checks run before the request is forwarded — for LLM calls and MCP tool calls alike.
  3. Govern from one dashboard. Audit log, cost intelligence, approval queue, risk scores, and NIST AI RMF compliance posture — live, in one place.
~/.claude/settings.json
{
  "env": {
    "ANTHROPIC_BASE_URL":
      "https://YOUR_ORG.aicontrols.dev",
    "ANTHROPIC_AUTH_TOKEN":
      "YOUR_ACCESS_TOKEN"
  }
}
That's the whole client setup for Claude Code. See the guide →

The full governance surface

One proxy, every control you need between your developers and their models.

Routes to Anthropic, OpenAI, Azure OpenAI, and Amazon Bedrock — how upstream routing works.

Explore the docs

Governance in place before lunch.

Most teams finish onboarding in under ten minutes — one endpoint, workspace tokens, done.

Get started →