Drop a gateway in front. Traffic runs through policy.
A Swiftward gateway sits in front of what you want to control, and every request passes through your policy on the way.
Where it sits, and why your agent never notices
You already have an agent that calls an LLM, an MCP server, or the network. Change one thing — the base URL it points at, or a line in how it is deployed — and every call runs through your policy. The other way in is your application calling our API before each decision: more flexible, but you write that integration.
The gateways
An OpenAI- and Anthropic-compatible proxy. Point your SDK at a new base URL and every prompt and response runs through policy.
Proxies MCP tool calls: allow or deny each tool, add parameters the caller never sees, and keep two identities apart — who is calling, and which credential the gateway sends to the MCP server behind it.
Sits in front of an agent's outbound calls and decides which destinations it may reach, using the rules you write.
Every order on the FIX protocol passes through policy before it reaches the venue: position and notional limits, price collars, restricted instruments, per-desk controls.
Takes GitHub and GitLab webhooks, runs the change through policy, and writes back a check or status.
A JSON-RPC proxy in front of your node. Reads pass through; a submission is decoded out of the signed bytes — the asset, the recipient, the amount — and decided before it reaches the network.
What an agent can reach
Put the LLM, MCP, and network gateways in front of the same agent and one set of rules decides what it can reach: which models it may call, which tools it may invoke, and which destinations it may open a connection to. For an autonomous coding agent, that is the difference between hoping it behaves and setting a limit on what it can do.
Identity and keys, handled
The gateway owns authentication, so your agents never hold credentials they should not.
Bring your own provider key and the gateway forwards it. Or let the gateway hold a pool of provider keys and choose one per request, and the caller never sees which key answered.
Sensitive content goes only to a provider you trust with it. You give each provider a risk level, a rule or an agent sets the level a request needs, and the stricter of the two wins.
Sensitive data is detected and redacted before the prompt leaves. How redaction works.
One engine behind all of them
Every gateway sends its events to the same engine, so one versioned policy and one audit trail cover your LLM calls, your agents' tool use, your order flow and your code changes, instead of a separate tool for each.
What happens when Swiftward is unreachable
You declare it per endpoint, and every change to that setting is recorded in the changes audit. A call that moves money or takes an action is normally set to fail closed, and a model call is normally set to fail open and let traffic through.
A rule that fails during evaluation follows the same setting, unless the rule declares its own answer for that failure.