AdvancedAdmin

Compliance & Audit: Self-Hosted, Redaction, Logging, Retention

Request and response logging, two-layer sensitive-data redaction, login and permission audit, retention and deletion — data never leaves your network; SOC 2 controls aligned (certification in preparation), GDPR ready.

What the community actually complains about

Zhihu and Reddit: "finance / healthcare / government data can't leave the country," "calling an LLM requires an algorithm filing," "how do I redact PII," "how do I keep audit logs."

A SaaS gateway routes requests through its own servers, so compliance audits are hard; relays add data-exfiltration and resale risk.

How GateLLM does it

GateLLM deploys fully inside your network — data never leaves, satisfying data-export compliance. Request and response logs are exportable for audit; two-layer sensitive-data redaction (request side + response side); login and permission audit (SSO via OIDC / SAML 2.0); retention and deletion are configurable.

BYOK keys live in memory, never on disk. GDPR ready; SOC 2 Type II / ISO 27001 controls aligned (certification in preparation).

5 levers that actually land

  • Request and response logging, exportable to audit systems
  • Two-layer sensitive-data redaction (request side + response side)
  • Login and permission audit (SSO via OIDC / SAML 2.0)
  • Configurable retention and deletion policy
  • Fully self-hosted: data never leaves the network, keys in memory only
Full how-to: Compliance & audit (docs)

FAQ