Aramm
Aramm Enterprise

AI gateway
for Production Teams

Access control, spend limits, PII screening and audit logs for every model your teams use, on a control plane hosted in Singapore.

01 — Governance

Policy on every request

Set access, budgets, and model limits once. They apply on the next request.

01

Who can do what

Owners manage billing and org settings. Admins set policy. Members build within their limits. Permissions are explicit not inherited from whoever created the API key.

02

Workspaces

Group people by department or project. Set budget, approved models, and rate limits once. New members inherit them on day one.

03

The record

Policy edits, access changes, and screening events timestamped and tied to a person, so reviews start from evidence.

REQUESTarrives from
your app
01Who can do what
Ownerbilling, org
Adminpolicy
Memberbuild
02Workspaces
Budgetset once
Approved modelsset once
Rate limitsset once
NEW MEMBER → INHERITS ALL
ENFORCEDlimits apply
before forward
03The record
POLICY EDITSACCESS CHANGESSCREENING EVENTS
timestamped, tied to a person
02 — Guardrails

Compliance on the hot path

Every request screened before it reaches a model. Personal data handled at the gateway, not after the fact.

01

Screening on the way in

Detect personal data and apply content rules before requests leave your control. Per key: block, redact, or flag.

02

Tuned for local identifiers

NRIC style numbers (checksum validated), Singapore phone formats, and postal codes detected and handled at the gateway before storage or upstream dispatch.

03

One policy, three outcomes

Block, redact, or flag — configured per API key. Dev teams can flag; customer-facing keys can block. No separate deployment.

REQUESTenters the
gateway
01Screening
Personal data detectionContent rulesLocal identifier patterns
BLOCKREDACTFLAG
MODELsees only
what passed
03 — Security

Proof, not promises

We separate what ships today from what's on the roadmap so diligence doesn't become a treasure hunt.

Where your data sits

Aramm's control plane is hosted in Singapore. Each model's route is labelled in the dashboard so you know whether a call stays in region or reaches a provider's own infrastructure.

How we hold your credentials

TLS on every connection. API keys and secrets in managed secret storage not config files. Access follows least privilege.

We don't keep your prompts

Request and response bodies aren't stored unless you enable logging for a specific key. When you do, personal data is redacted before storage and you set retention.

Security ledger

Live now

Singapore hosted control planePDPA aware screeningRole based access controlOpt in content logging with retention controls

In progress

Structured audit exportOpenTelemetry streamingWebhook destinations

Not yet

SOC 2 Type IIISO 27001SSO via Okta, Azure AD, Google Workspace

We'd rather you read this column by column than discover gaps in diligence.

Why we publish gaps

No procurement theatre. No "contact sales for security." A clear ledger and founders who'll answer what isn't done yet.

04 — Observability

Where spend and latency actually go

Every call ties to a model, a key, and a workspace so finance and engineering share the same numbers.

Spend, attributed

See which workspace and which model drove spend before month end.

Provider performance

p50, p95, and p99 latency beside error rates, so you know whether to tune the model or your code.

Consumption patterns

Which workspaces and models drive the bill visible before the invoice lands.

Getting the data out

Export from the dashboard today. Streaming to observability tools is on the roadmap with design partners.

Spend by workspace
Engineering
Support
Marketing
Finance
Latency per provider
p50p95p99schematic
05 — Adoption

Adoption cost: one line

Point your existing OpenAI compatible client at Aramm.

Policies, limits, and screening apply from the next request.

# Before
client = OpenAI(api_key="sk-...")

# After
client = OpenAI(
    api_key="sk-arm-v1-...",
    base_url="https://gateway.aramm.ai/v1",
)
06 — Onboarding

Your first month with us

1

Week 1: A conversation

Twenty minutes on your models, compliance context, and timeline. You leave knowing what's ready today and what isn't.

2

Week 2: Setup, together

We configure workspaces, policies, and approved models with your team. As a design partner, your feedback shapes the next quarter.

3

Weeks 3 and 4: Into production

Traffic moves over gradually. We stay on the thread through rollout, not just signup.

07 — FAQ

FAQ

Where does inference actually happen?+

Control plane and governance data are in Singapore. Inference routes depend on the model you choose; we label each model's path so you're not guessing.

Do you store our prompts or responses?+

Not unless you enable it per key. When enabled, personal data is redacted before storage and you set retention.

Can we limit which models our teams reach?+

Yes. Approved model lists, workspace budget caps, and rate limits are available today.

Can we audit usage across the organisation?+

Usage, cost, and access events are logged today. Structured audit export is in build. Tell us which fields your reviewers need.

Do you support SSO?+

Not yet. SSO is on the roadmap. Tell us your provider and timeline; design partner needs set priority.

Are you SOC 2 or ISO 27001 certified?+

Not yet. We won't imply certification we don't have. We'll tell you where readiness stands when you ask.

How does pricing work?+

Scoped to your volume and the features you need, sized from real usage, not a generic tier table.

We're still piloting, not in production. Too early?+

It's often the best moment. Rules are cheaper to set before usage spreads across a dozen keys.

Why publish the roadmap gaps at all?+

You'll find them in diligence anyway. Better from us first.

Let's talk about where you actually are

A short call with the people building it and a clear picture of what's live today.

Talk to the Founders