Inspiration

Every team now pastes support tickets, CRM exports and code into AI tools. Those prompts carry customer emails, card numbers, national IDs and API keys. Small and mid-size companies have no way to stop that data from leaving, to prove to an auditor what was sent, or to cap what each team spends. Enterprise DLP suites solve it for five-figure contracts. We wanted the same control as a drop-in endpoint a team can adopt in an afternoon.

What it does

Aegisly sits between your apps and the LLM. Every request to POST /api/v1/chat goes through one pipeline:

  1. Authenticate the key (stored only as SHA-256), then check the plan's monthly quota and the key's USD budget.
  2. Evaluate the workspace policy: 12 deterministic detectors (email, phone, Luhn-validated cards, US SSN, Brazilian CPF with check digits, IBAN, IP, AWS / GitHub / sk- keys, JWTs, private keys), blocked confidential terms, allowed models and prompt size. The result is redact, block (403) or allow.
  3. Call the model (Workers AI: Llama 3.2 3B, Llama 3.1 8B, Mistral Small 3.1) with redacted text only, such as [EMAIL_1] and [CREDIT_CARD_1].
  4. Scan the output, then append a hash-chained audit entry. Each entry stores the prompt's SHA-256 (never the prompt) and the previous entry's hash. One click re-verifies the chain, and CSV export is available for auditors.

The dashboard includes a playground that shows exactly what reached the model, a policy editor, keys with budgets, the audit log with verification, usage and spend, and plans and billing. A one-click sandbox workspace lets judges try everything with sample traffic.

How we built it

  • Runtime: a single Cloudflare Worker serves the static dashboard and the API.
  • Storage: D1 (SQLite) holds workspaces, keys, the audit chain, monthly usage and billing events.
  • Inference: the Workers AI binding.
  • Dependencies: none at runtime. The same ES modules run on the edge and in Node.
  • Tests: 14 end-to-end tests run against a 15-line D1 shim on node:sqlite.
  • Billing: Stripe Checkout and signed-webhook handling are implemented. This demo deployment runs in clearly labelled sandbox billing because no payment account is connected.

Challenges we ran into

  • Accurate redaction: detectors had to be precise enough not to mangle text. Cards are Luhn-checked, CPFs are check-digit validated, and overlapping matches resolve longest-first.
  • Tamper evidence without a ledger service: a per-workspace hash chain with retry on sequence conflicts, plus a verifier that names the first broken entry.
  • Response shapes: Workers AI models return different shapes (response vs OpenAI-style choices), so the gateway normalizes them and turns model failures into clean 502s.

Accomplishments that we're proud of

  • It works on the live deployment: PII is replaced before Llama sees it, secrets are blocked with a 403, the CPF is redacted and the audit chain verifies.
  • It is honest about data: raw prompts and API keys are never persisted.
  • It enforces plans for real: limits are applied server-side, not just shown on a pricing page.

What we learned

Governance features only sell when they are visible. The "sent to model" panel in the playground is the moment the value clicks, so the product is designed around showing it.

What's next for Aegisly

  • Named-entity detection for people's names and addresses.
  • Industry policy templates (healthcare, fintech, LGPD).
  • Anchoring the audit-chain head externally for stronger tamper resistance.
  • Bring-your-own provider keys (OpenAI, Anthropic, Gemini).
  • n8n / Zapier / LangChain integrations, and SSO for the Business plan.

Business model

Plan Price Limits
Free $0 3 keys, 1K requests/month, 7-day retention
Team $49/month 25 keys, 50K requests/month, 90-day retention, per-key budgets
Business $299/month 500 keys, 500K requests/month, 1-year retention

Unit economics (estimate): a Team account at full quota uses about 30M tokens, roughly $6 of inference, which leaves about 88% gross margin. Go-to-market: a free playground leading to self-serve upgrade, and agencies reselling to their clients.

AI disclosure

Built during the hackathon window with an AI coding assistant (Anthropic's Claude), operated by the participant. The disclosure is also in the README. Screens in the video were recorded from the open-source build (same commit as the live deploy); model outputs shown are real Llama 3.2 3B responses recorded from the live deployment on 1 Oct 2026.

Built With

Share this project:

Updates

Submission history