dhvati ProductConnectSecurityPricingDocs
Book a demo
Security & deployment

Built to be the chokepoint.

Enforcement is credential custody: the Gateway is the only place vendor credentials exist, so there is no client to trust and nothing to bypass.

Credential custody
Vendor tokens live only in the Gateway's vault, sealed with AES-256-GCM. They are injected per allowed call and never shown to the agent, the browser, or the harness.
Verified identity on every call
Each tool call carries a short-lived signed token from your IdP (OIDC; SAML/SCIM sync). The acting employee is verified before policy is even consulted.
Policy as code
Authorization compiles to Cedar and is evaluated per call — roles, individual grants with expiry, and deny-by-default for anything unstated.
Fail-closed
If the control plane is unreachable, the Gateway serves last-known-good policy; if identity can't be verified, the call is denied. Unavailability never becomes permission.
Audit that answers questions
Who, what, when, allow or deny, and why — for every call. Export today; SIEM streaming is on the near-term roadmap.
Your data, your rules
dhvati stores decisions and metadata, not your tools' response payloads. See the privacy policy for exactly what is kept and for how long.
Deployment

Hosted, on-prem, or sovereign.

Hosted
Start in minutes on dhvati's cloud — nothing to deploy. This is where the free tier runs.
On-prem & air-gapped
Helm chart plus a complete air-gap bundle: your Kubernetes, your Postgres, your keys. The Console, control plane, and Gateway run entirely inside your boundary.
Sovereign
India-based hosting with no dependency on US cloud identity providers — for organizations whose regulators or customers require it.

No lock-in, by design: start hosted and take everything with you when you move on-prem — policy, roles, grants, members, and your full audit history export as one portable bundle (credentials never leave the vault; you re-connect tools in the new home). Your policy is Cedar-compatible JSON and your data is a Postgres schema you can own.

Put your agents under governance.

See dhvati govern a live agent's tool calls in a 30-minute walkthrough — or join the developer waitlist.

Book a demo Join the developer waitlist
dhvati
Sovereign identity, authorization & audit for the agent era. Run it hosted, or entirely on your own infrastructure.
ProductPlatformGatewayPolicy & CedarAudit & SIEM
CompanyDocsPricingContactTrust centerTerms
DeployHosted — book a demoSelf-hosted / on-premClaude Code setupCursor setup
© 2026 dhvati · a product of Adiyogi Technologies · Made for security-first teams. Cedar · OIDC / SAML / SCIM · MCP