HIPAA compliance for AI, from first prototype to production scale

The LLM Gateway enforces HIPAA compliance controls across your AI systems, no matter how many providers you add or how much PHI moves through them.

HIPAA compliance for AI, from first prototype to production scale

The LLM Gateway enforces HIPAA compliance controls across your AI systems, no matter how many providers you add or how much PHI moves through them.

HIPAA compliance for AI, from first prototype to production scale

The LLM Gateway enforces HIPAA compliance controls across your AI systems, no matter how many providers you add or how much PHI moves through them.

“Our view: AI in healthcare must be trustworthy, traceable, and controllable, and we won’t compromise security for speed.”

A BAA is just the start of what it takes to safely run the AI your team is already using.

Audit logging, PHI de-identification, and detection for prompt injection or harmful outputs are still your responsibility, whether you're building AI products or internal workflows. With LLM Gateway, you get all those controls under one BAA.

Audit logging, PHI de-identification, and detection for prompt injection or harmful outputs are still your responsibility, whether you're building AI products or internal workflows. With LLM Gateway, you get all those controls under one BAA.

BAA coverage, audit logging, and access control

BAA coverage across every model you use, with every prompt and response logged automatically. Admins control alerts, restrict which models are allowed through the gateway, and can control access by provider, model, or version.

BAA coverage across every model you use, with every prompt and response logged automatically. Admins control alerts, restrict which models are allowed through the gateway, and can control access by provider, model, or version.

Cost and usage controls

Set budget limits per scope and automatically stop excess spend so a runaway agent loop doesn't become an incident. Usage is tracked by model, so you can monitor which models are driving the most spend.

Set budget limits per scope and automatically stop excess spend so a runaway agent loop doesn't become an incident. Usage is tracked by model, so you can monitor which models are driving the most spend.

Coming soon

De-identification and safety guardrails, defined in your code

Aptible's AI SDK gives you the same protections as other SDKs, but it's tuned specifically for HIPAA and other regulated use cases. Use it to de-identify PHI before it reaches the model, catch prompt injection and jailbreak attempts, and block harmful, hallucinated, or unsafe outputs.

Aptible's AI SDK gives you the same protections as other SDKs, but it's tuned specifically for HIPAA and other regulated use cases. Use it to de-identify PHI before it reaches the model, catch prompt injection and jailbreak attempts, and block harmful, hallucinated, or unsafe outputs.

View docs

Building for the AI-native era

AI is raising the bar on what attackers can do and what regulated buyers expect from their infrastructure. Some of LLM Gateway's highest-usage accounts already run Claude Code and other coding agents against regulated data, often without governance built specifically for that pattern. Here's what's coming soon to close that gap.

model routing & failover

If a provider has an outage, requests fail over automatically to another provider serving the same model.

Secure cloud-hosted agents

Run agents in a sandboxed environment with no open network access, routing every request through the Gateway.

Data residency

Keep all gateway infrastructure within a required region. Keys are automatically restricted to in-region models.

Product roadmap

Without a gateway, you’re building and maintaining all of this yourself.

With separate platforms and diy

Compliance controls

BAA coverage

One BAA covers AI Gateway usage

Separate BAAs per provider

Audit logging

Prompts, responses, and metadata logged automatically

Build and maintain your own logging pipeline

Log retention

Aptible provides long-term log storage and search

Design and maintain your own export process to meet HIPAA retention requirements

Model access

Every provider under one BAA, including open-weight models

Separate BAA and integration per provider

No model training on PHI

Enforced at infrastructure layer

Rely on provider policy and configuration

Breach investigation

Logs and activity history available immediately for audits or incident investigation

Reconstruct activity across systems during audits or breach reviews

Accesss management & governance

Model access controls

Restrict models per scope

Manage access separately per provider and integration

Cost attribution

Usage tracked per scope and model

Aggregate bill with limited breakdown and across cost dashboards from different providers

Data protection

De-identification (coming soon)

Scrub PHI before sending to a model or logs, re-identifying before responding to application

Build and maintain your own PHI de-identification pipeline

Prompt injection and harmful output detection (coming soon)

Configurable guards, with best practices on by default

Build and maintain your own detection

Consistency across models

Same controls regardless of provider

Re-implement safeguards per integration

Observability

Request inspection

View actual prompts and responses

Build dashboards or search raw logs

Audit readiness

Evidence available immediately

Reconstruct activity during audits

Cost and operations

Budget enforcement

Set alerts and hard stops for requests to limit spend

Monitor spending manually

Protocol translation

Same keys work across supported providers

Maintain separate integrations

Capacity management

Managed within the LLM Gateway

Manage rate limits and availability yourself

Time to safe usage

Immediate

Weeks to months

Use Cases

Why teams choose Aptible

From a team's first AI feature to an advanced builder's full production stack, the LLM Gateway covers the compliance and safety controls regulated teams actually need.

Use Cases

Why teams choose Aptible

From a team's first AI feature to an advanced builder's full production stack, the LLM Gateway covers the compliance and safety controls regulated teams actually need.

Get through health system security reviews faster

Security review evidence is available for all model usage instantly, so you can turn a conversation that used to kill deals into a non-issue.

Protect PHI from model training

Training on PHI is disabled at the infrastructure layer; that protection holds regardless of any provider's own data-use policy or default settings.

Manage spend on a per-key basis for better visibility and control

Give internal automations and agent harnesses their own keys with individual spend limits so you can easily identify where to optimize spend.

Use one gateway for internal tools and production AI

Claude Code sessions and patient-facing chat features route through the same gateway, so BAA coverage and audit logging apply whether it's your engineers or your customers driving the request.

FAQs

How much does LLM Gateway cost?

What happens when I hit my spend limit?

How do I stay in the loop on new features?

Which model providers are covered?

Does integrating LLM Gateway require any changes to my existing applications?

Can't find an answer to your question? Contact us for help

Can't find an answer to your question? Contact us for help

Built for teams shipping AI in regulated environments

One gateway. One BAA. Every model you need.

Built for teams shipping AI in regulated environments

One gateway. One BAA. Every model you need.

Built for teams shipping AI in regulated environments

One gateway. One BAA. Every model you need.