Access control, spend limits, PII screening and audit logs for every model your teams use, on a control plane hosted in Singapore.
Set access, budgets, and model limits once. They apply on the next request.
Owners manage billing and org settings. Admins set policy. Members build within their limits. Permissions are explicit not inherited from whoever created the API key.
Group people by department or project. Set budget, approved models, and rate limits once. New members inherit them on day one.
Policy edits, access changes, and screening events timestamped and tied to a person, so reviews start from evidence.
Every request screened before it reaches a model. Personal data handled at the gateway, not after the fact.
Detect personal data and apply content rules before requests leave your control. Per key: block, redact, or flag.
NRIC style numbers (checksum validated), Singapore phone formats, and postal codes detected and handled at the gateway before storage or upstream dispatch.
Block, redact, or flag — configured per API key. Dev teams can flag; customer-facing keys can block. No separate deployment.
We separate what ships today from what's on the roadmap so diligence doesn't become a treasure hunt.
Aramm's control plane is hosted in Singapore. Each model's route is labelled in the dashboard so you know whether a call stays in region or reaches a provider's own infrastructure.
TLS on every connection. API keys and secrets in managed secret storage not config files. Access follows least privilege.
Request and response bodies aren't stored unless you enable logging for a specific key. When you do, personal data is redacted before storage and you set retention.
We'd rather you read this column by column than discover gaps in diligence.
No procurement theatre. No "contact sales for security." A clear ledger and founders who'll answer what isn't done yet.
Every call ties to a model, a key, and a workspace so finance and engineering share the same numbers.
See which workspace and which model drove spend before month end.
p50, p95, and p99 latency beside error rates, so you know whether to tune the model or your code.
Which workspaces and models drive the bill visible before the invoice lands.
Export from the dashboard today. Streaming to observability tools is on the roadmap with design partners.
Point your existing OpenAI compatible client at Aramm.
Policies, limits, and screening apply from the next request.
# Before client = OpenAI(api_key="sk-...") # After client = OpenAI( api_key="sk-arm-v1-...", base_url="https://gateway.aramm.ai/v1", )
Twenty minutes on your models, compliance context, and timeline. You leave knowing what's ready today and what isn't.
We configure workspaces, policies, and approved models with your team. As a design partner, your feedback shapes the next quarter.
Traffic moves over gradually. We stay on the thread through rollout, not just signup.
Control plane and governance data are in Singapore. Inference routes depend on the model you choose; we label each model's path so you're not guessing.
Not unless you enable it per key. When enabled, personal data is redacted before storage and you set retention.
Yes. Approved model lists, workspace budget caps, and rate limits are available today.
Usage, cost, and access events are logged today. Structured audit export is in build. Tell us which fields your reviewers need.
Not yet. SSO is on the roadmap. Tell us your provider and timeline; design partner needs set priority.
Not yet. We won't imply certification we don't have. We'll tell you where readiness stands when you ask.
Scoped to your volume and the features you need, sized from real usage, not a generic tier table.
It's often the best moment. Rules are cheaper to set before usage spreads across a dozen keys.
You'll find them in diligence anyway. Better from us first.
A short call with the people building it and a clear picture of what's live today.
Talk to the Founders