Argus — the security layer for all AI models
An OpenAI-compatible gateway that sits in front of any LLM — OpenAI, Anthropic, Bedrock, Gemini, Mistral, vLLM, Ollama, anything with an OpenAI-shaped endpoint — and enforces security policy before a model ever sees your data.
Every request passes through the policy engine on the way in and on the way out. Cost intelligence (tiered routing, graceful budgets, per-task attribution) rides along via tokenecon, but security is the product.
The security layer
request -> auth -> INPUT policy -> budget -> route -> model
-> OUTPUT policy -> audit -> response
Pluggable detectors (each scans, the policy decides):
| Detector | Catches | Default action |
|---|---|---|
| Secrets | AWS keys, private keys, GitHub/OpenAI tokens, password = ... |
block — never reaches a model |
| PII | emails, phones, SSNs, credit cards, IPs | redact — [REDACTED:EMAIL], request continues |
| Prompt injection | "ignore previous instructions", role overrides, system-prompt probes, known jailbreaks | flag — allowed but marked (one flag away from block) |
| Blocklist | your own regexes | block |
Policy engine: per-direction rules (in / out / both) with four
actions — allow, redact, block, flag. Add an ML-based detector later
by subclassing Detector; no other code changes.
Audit log: every decision recorded — timestamp, key, task, detector,
action, redacted snippet. Raw PII and secrets never touch the audit trail.
GET /admin/audit for compliance review.
Quickstart
pip install argus-gateway
export AIGW_MASTER_KEY="sk-admin-secret"
export OPENAI_API_KEY="..."
argus # serves on 127.0.0.1:4000
Point any OpenAI client at it — one base_url change:
import openai
client = openai.OpenAI(api_key="<virtual-key>", base_url="http://localhost:4000/v1")
Self-hosted models sit behind the same layer:
from gateway.providers.generic import GenericProvider
# vLLM, Ollama, llama.cpp — any OpenAI-shaped endpoint
Every response carries what happened:
"gateway": {
"provider": "openai", "tier": "small", "difficulty": 0.17,
"cost_usd": 0.000004, "degraded": false,
"security": {"redactions": ["pii:EMAIL"], "flags": ["prompt_injection:INSTRUCTION_OVERRIDE"]}
}
Also inside: cost intelligence
- Tiered routing — requests scored for difficulty, cheapest capable tier wins
- Graceful budgets — over budget? Falls back to the cheapest tier and flags
degraded: trueinstead of failing (hard-stop mode available) - Per-task attribution —
X-Task-Idgroups an agentic run's turns into one costed task:GET /admin/tasks/{id}
Admin API (X-Admin-Key required)
POST /admin/keys— issue virtual keys with budgets (degrade/hard, daily/monthly)GET /admin/spend,GET /admin/keys/{id}/spend— spend trackingGET /admin/tasks/{task_id}— per-task cost breakdownGET /admin/audit?limit=&key_id=— security decisions
Roadmap
Streaming (SSE), Bedrock/Gemini/Mistral adapters, semantic caching, OTEL/Prometheus export, admin UI, SSO/RBAC, ML-based injection detector.
License
MIT — Karmendra Pandey.
Metadata
Release files for argus-gateway 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| argus_gateway-0.1.0.tar.gz | 17.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| argus_gateway-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 38.1 kB
Release files / argus_gateway-0.1.0.tar.gz
| Download URL | argus_gateway-0.1.0.tar.gz |
|---|---|
| Size | 17.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
263e7842587008719380aaf3bf9972e0e0bb2080d3308fc6769bfbaeb5d91ef1
|
|
BLAKE2b-256 checksum How to use checksums |
24c9a96af3f6ce3815a909776ff2e59a404800e37452320582ac140bca38f2ae
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency logRelease files / argus_gateway-0.1.0-py3-none-any.whl
| Download URL | argus_gateway-0.1.0-py3-none-any.whl |
|---|---|
| Size | 20.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c7db112d43398542222b6249241f76481075fd5db1625d374ace110e49a1c305
|
|
BLAKE2b-256 checksum How to use checksums |
c296143245f1473e95c6c6f707f9d249220c3915a1e09b5a86610bfda6b4b4da
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency log