Skip to main content
POLICY ENGINE

Rules that enforce themselves.

Define your organization's AI governance policies once. The Policy Engine evaluates every request against your rules — automatically, deterministically, with a full decision trace.

The Policy Engine powers all four stages of the Arbitex Gateway pipeline.

Routing

Rules determine which provider and model a request is routed to, including fallback chains.

Protection

DLP inspection rules are policy rules — they define what to scan, what to flag, and what action to take on detection.

Control

The core of the Policy Engine. Access control, content policies, cost caps, and compliance rules are all evaluated here.

Visibility

Every policy evaluation produces a decision trace that feeds the audit log and dashboards.

The Control stage is where the Policy Engine is most visible. Routing and Protection are governed by the Policy Engine but have their own dedicated pages. Visibility is the evidence layer for everything the Policy Engine enforces.

Capabilities

Ordered Rules, Full Control

You control the order. The first rule that matches decides the outcome — allow, block, redact, or ROUTE_TO an alternative model. This is the same first-match model used in next-generation firewalls: specific rules at the top, broad catch-alls at the bottom. No hidden conflict resolution, no silent overrides. Every enforcement decision is traceable to the exact rule that triggered it.

Policy Packs and Compliance Bundles

A Policy Pack is an ordered set of policy rules that can be applied as a unit — the building block of the Policy Engine. Compliance Bundles are Policy Packs pre-configured for regulatory frameworks: HIPAA, PCI-DSS, GDPR, and more. Apply a Compliance Bundle and your policies align to the framework immediately. Build your own Policy Packs to encode organization-specific governance rules and share them across teams.

Group-Based Conditions

Target rules by team, department, or role. "Finance group + OpenAI destination = Block" is a single rule. Conditions combine user identity, destination model, and content pattern — organization-level governance with team-level precision.

Combined Detection — Pattern + ML

Policy conditions can combine multiple detection methods in a single rule: pattern matching (80+ regex patterns for PHI, PCI, PII), ML-based entity recognition, and content classifiers — evaluated together. A rule can require both pattern and ML signal to trigger, reducing false positives in ambiguous cases while maintaining strict enforcement on clear violations.

Prompt Governance

Apply policy rules to system prompts and prompt templates — not just user input. Governance rules can inspect, transform, or enforce controls on the complete prompt context before it reaches any model. PROMPT-level rules allow organizations to enforce content standards, inject compliance context, or block unsafe prompt patterns at the governance layer rather than the application layer.

Modality Governance

Control which content modalities your organization permits. Text and tool-use are enabled by default; image, audio, and realtime modalities are admin-enabled per modality and enforced at the API. Unapproved content types are stopped at the gateway before they reach a model — governance over not just what content says, but what form it takes.

Simulation Mode

Test policy changes before enforcing them. Simulation mode evaluates requests — including against simulated user groups — and logs what would have happened: which requests would be blocked, which would be redacted, which would pass — without affecting production behavior. Review the simulation report, confirm the outcome, then promote to enforcement with one action.

Full Decision Trace

Every request logs which rules were evaluated, which rule matched, and what action was taken. When audit asks "why was this request blocked?" — the answer is in the trace, not in someone's memory. Compliance evidence is produced at enforcement time, not assembled afterward.

How it works

01

Define rules at the organization level

Author governance rules in the policy editor or via the API. Set matching conditions — user group, destination model, content pattern — and the enforcement action: allow, block, redact, or ROUTE_TO a specific alternative model. Build reusable Policy Packs for your own governance standards, or apply a Compliance Bundle (a pre-configured Policy Pack) to align with HIPAA, PCI-DSS, GDPR, and other frameworks immediately. Customize from there.

02

Simulate before enforcing

Activate simulation mode on any new or modified policy. Arbitex Gateway evaluates every matching request against the proposed rules and logs the projected outcome — which requests would be blocked, redacted, or passed. Review the simulation report to verify coverage, then promote to enforcement.

03

Every decision is traced and logged

Each enforcement action writes to the Immutable, tamper-proof audit log: which rules were evaluated, which rule matched, what action was taken, and the full request context. The decision trace is available for real-time review in the admin console and for export during compliance reviews.

The Problem

AI deployed across the organization. Governance enforced by nobody.

You have AI running across teams. Each team configures its own controls — or does not. When compliance asks for proof of enforcement, you assemble it manually. The answer is different every time, and it is always late.

The Answer

Define once. Enforce everywhere. Demonstrate on demand.

Define rules once at the organizational level. The Policy Engine enforces them on every AI request — deterministically, with a complete audit trail. Compliance Bundles map your policies to named regulatory frameworks so you can demonstrate alignment, not just claim it.

Related Resources

DLP Protection

Inspect every AI prompt for sensitive data

Compliance Frameworks

Pre-built policy packs for regulatory requirements

Model Routing

Cost-optimized intelligent provider selection

Manufacturing

ITAR and CMMC compliance

Read the policy engine admin guide

Governance enforced, not suggested.

Every AI request evaluated against your rules. Every decision traced. Every enforcement action logged.