Platform teams
Give every application and agent one governed path.
Runtime AI governance
DVARA is a runtime AI governance platform for model, tool, and agent-to-agent calls — policy, data protection, spend control, and evidence.
Run DVARA in your VPC, cloud, or on-prem. Policies, credentials, budgets, and audit records stay in infrastructure you control. Model and tool payloads go only to the providers and servers you configure.
Give every application and agent one governed path.
Control what AI can access and see what crossed the boundary.
Produce evidence from decisions that actually ran.
Attribute spend and stop overruns before the next call.
Deploy DVARA, change the endpoint, and verify what happened on the first governed call.
Keep your existing providers and SDKs. Change the endpoint, not the application.
Every call is identified, evaluated, protected, costed and recorded before it reaches the destination you configured.
Tie each call to its workspace and credential.
Apply versioned rules before model requests reach providers.
Detect sensitive data and apply the workspace action—LOG by default.
Attribute cost and enforce configured budgets before each call.
HMAC-sign and hash-chain records so changes are detectable.
Evaluate agent model requests against configured policy, data and spend controls.
Routing
One OpenAI-compatible endpoint with configurable routing and automatic failover.
Model calls pass through the DVARA LLM Gateway, tool calls through the MCP Gateway, and agent handoffs through the A2A Gateway. All three use the same policy and evidence model.
Model callsModels
Tool callsTools
Agent handoffsPeer agents
Policy, data and spend checks run where each request is handled, without a separate policy-service network hop.
See request-path observability →Add gateway instances behind your load balancer or autoscaler as traffic grows.
See autoscaling guidance →Run gateways in the regions your workloads require and use region-aware routing for governed traffic.
See multi-region guidance →Dry-run a versioned policy against a supplied context and inspect the decision without changing live traffic.
Explore Policy-as-Code →HMAC signatures and hash chaining make edits, deletions and breaks in the governance record detectable during verification.
Explore audit evidence →For MCP servers registered with DVARA, policy and data checks inspect tool arguments before execution and record the decision.
Explore MCP governance →Configure loop detection and approval rules to stop repeated activity and hold matched tool calls or agent handoffs for review.
Explore agent governance →DVARA turns the decisions made on the request path into traceable records your security and compliance teams can filter and export. It supplies evidence; it does not make your organization compliant.
Filter records by workspace, event and date range in DVARA Flightdeck, then export evidence for SOC 2, HIPAA and GDPR reviews.
See how reports are generated

See where DVARA provides gateway-level controls across the OWASP LLM Top 10—and where application, model or retrieval-layer controls are still required.
Coverage assumes the relevant controls are configured and the traffic passes through the applicable DVARA gateway. Training, application, model, identity and retrieval controls remain your responsibility.
Answer 15 questions about visibility, policy, data, spend and evidence. You receive the result immediately, and your answers stay in your browser.
15 questions · about 5 minutes · no form required
DVARA governs model calls that pass through the DVARA LLM Gateway. It applies configured identity, policy, data, spend, and evidence controls on the request path. Registered MCP tool calls and agent-to-agent traffic use the DVARA MCP Gateway and A2A Gateway.
See the governance architecture →For OpenAI-compatible model calls, you usually change only the base URL and credential. Your existing SDK sends the request to the DVARA LLM Gateway, which returns an OpenAI-compatible response. MCP and A2A traffic use their corresponding DVARA gateway paths.
Run the quickstart →DVARA can run self-managed in your VPC, cloud account, or on-premises environment. You can use Docker Compose on one host or Helm on Kubernetes. Dedicated managed hosting in a region you choose is available through DVARA.
Deployment models compared →DVARA sends each model request to the provider you choose and each governed tool call to the MCP server you registered. On a self-managed deployment, DVARA stores policies, credentials, budgets, and audit records in infrastructure you operate; it does not send that governance data back to DVARA.
Review the data boundary →Yes. Keep your existing provider accounts and credentials, then configure DVARA to route governed model calls to the providers you choose. The integrations page lists supported providers and setup requirements.
Review supported integrations →A basic AI gateway standardizes provider APIs and routes model traffic. DVARA is an AI governance platform: its LLM, MCP, and A2A Gateways are enforcement components for shared identity, policy, data, spend, and evidence controls.
Compare DVARA with AI gateways →Connect one workflow and watch DVARA apply policy, protect data, attribute spend, and record evidence on the first call.