SignalVault sits between your application and your LLM provider. Every prompt, response and agent tool call passes through it and is recorded in an encrypted audit trail you can search, inspect and export.
Each request is scanned for sensitive data - email addresses, card numbers, US social security numbers, phone numbers, IP addresses, API keys and tokens - along with prompt-injection patterns and your own custom rules. Per policy, a match is blocked before it reaches the provider, flagged for review, or redacted so the sensitive value never enters the stored log. When a model proposes a tool call whose arguments contain a violation, SignalVault rewrites or refuses the call before it reaches your agent, on streaming and non-streaming responses alike. Violations appear in the dashboard in real time.
It proxies OpenAI chat completions and the Anthropic messages API. Integrate by pointing your base URL at SignalVault and adding one header - no changes to your application logic - or use the open-source (MIT) Python and Node.js SDKs.
Built for teams that need to show what their AI features actually sent and received: GDPR, the EU AI Act, security reviews, customer due diligence. Data is stored in Stockholm, Sweden. Prompts and responses are encrypted at rest with AES-256-GCM.
No comments or reviews, maybe you want to be first?