Skip to main content

Argus — the security layer for all AI models

An OpenAI-compatible gateway that sits in front of any LLM — OpenAI, Anthropic, Bedrock, Gemini, Mistral, vLLM, Ollama, anything with an OpenAI-shaped endpoint — and enforces security policy before a model ever sees your data.

Every request passes through the policy engine on the way in and on the way out. Cost intelligence (tiered routing, graceful budgets, per-task attribution) rides along via tokenecon, but security is the product.

The security layer

request -> auth -> INPUT policy -> budget -> route -> model
                                              -> OUTPUT policy -> audit -> response

Pluggable detectors (each scans, the policy decides):

Detector Catches Default action
Secrets AWS keys, private keys, GitHub/OpenAI tokens, password = ... block — never reaches a model
PII emails, phones, SSNs, credit cards, IPs redact — [REDACTED:EMAIL], request continues
Prompt injection "ignore previous instructions", role overrides, system-prompt probes, known jailbreaks flag — allowed but marked (one flag away from block)
Blocklist your own regexes block

Policy engine: per-direction rules (in / out / both) with four actions — allow, redact, block, flag. Add an ML-based detector later by subclassing Detector; no other code changes.

Audit log: every decision recorded — timestamp, key, task, detector, action, redacted snippet. Raw PII and secrets never touch the audit trail. GET /admin/audit for compliance review.

Quickstart

pip install argus-gateway
export AIGW_MASTER_KEY="sk-admin-secret"
export OPENAI_API_KEY="..."
argus   # serves on 127.0.0.1:4000

Point any OpenAI client at it — one base_url change:

import openai
client = openai.OpenAI(api_key="<virtual-key>", base_url="http://localhost:4000/v1")

Self-hosted models sit behind the same layer:

from gateway.providers.generic import GenericProvider
# vLLM, Ollama, llama.cpp — any OpenAI-shaped endpoint

Every response carries what happened:

"gateway": {
  "provider": "openai", "tier": "small", "difficulty": 0.17,
  "cost_usd": 0.000004, "degraded": false,
  "security": {"redactions": ["pii:EMAIL"], "flags": ["prompt_injection:INSTRUCTION_OVERRIDE"]}
}

Also inside: cost intelligence

  • Tiered routing — requests scored for difficulty, cheapest capable tier wins
  • Graceful budgets — over budget? Falls back to the cheapest tier and flags degraded: true instead of failing (hard-stop mode available)
  • Per-task attribution — X-Task-Id groups an agentic run's turns into one costed task: GET /admin/tasks/{id}

Admin API (X-Admin-Key required)

  • POST /admin/keys — issue virtual keys with budgets (degrade/hard, daily/monthly)
  • GET /admin/spend, GET /admin/keys/{id}/spend — spend tracking
  • GET /admin/tasks/{task_id} — per-task cost breakdown
  • GET /admin/audit?limit=&key_id= — security decisions

Roadmap

Streaming (SSE), Bedrock/Gemini/Mistral adapters, semantic caching, OTEL/Prometheus export, admin UI, SSO/RBAC, ML-based injection detector.

License

MIT — Karmendra Pandey.

Metadata

Release files for argus-gateway 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for argus-gateway 0.1.0
File Size Uploaded
argus_gateway-0.1.0.tar.gz 17.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for argus-gateway 0.1.0
File Interpreter ABI Platform
argus_gateway-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 38.1 kB

Release files / argus_gateway-0.1.0.tar.gz

Download URL argus_gateway-0.1.0.tar.gz
Size 17.7 kB
Tags Source
SHA-256 checksum
How to use checksums
263e7842587008719380aaf3bf9972e0e0bb2080d3308fc6769bfbaeb5d91ef1
BLAKE2b-256 checksum
How to use checksums
24c9a96af3f6ce3815a909776ff2e59a404800e37452320582ac140bca38f2ae
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.

Transparency log

Release files / argus_gateway-0.1.0-py3-none-any.whl

Download URL argus_gateway-0.1.0-py3-none-any.whl
Size 20.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c7db112d43398542222b6249241f76481075fd5db1625d374ace110e49a1c305
BLAKE2b-256 checksum
How to use checksums
c296143245f1473e95c6c6f707f9d249220c3915a1e09b5a86610bfda6b4b4da
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page