Security gateway

Secret detection and redaction

Twenty-seven detectors catch API keys, cloud credentials and passwords, then redact them or block the request.

What it is

Built-in detectors catch API keys, cloud credentials, private keys, tokens and passwords in prompts. Each rule can observe, redact the secret before it leaves, or block the request with a reason.

Why you want it

People paste config files and logs into chat. Catching credentials at the gateway stops them from landing in a provider's logs.

A prompt containing a database password and a cloud secret key reaches Janus at your network edge. Janus either redacts the secrets and sends the rest, or blocks the request so nothing is sent. PROMPT FROM PRIYA Why won't this connect? export DB_PASSWORD=Hunter2!prod aws_secret_access_key=wJalrXUtnFEMI… password cloud secret YOUR NETWORK EDGE Janus checks REDACT export DB_PASSWORD= [REDACTED] aws_secret_access_key= [REDACTED] The rest of the prompt goes to the provider. BLOCK Request blocked Priya is told to remove the credentials and retry. Nothing was sent.

How it works

  • 27 bundled rules including AWS, GCP, Azure, GitHub, GitLab, Slack, Stripe, OpenAI, Anthropic, private keys, JWTs and connection strings
  • Runs inside the gateway with no external service
  • Also applies to responses, including streams

In the product

Janus Violations screen with demo data
Violations

Each finding with what was detected, the action taken, who sent it and which model it was headed for.

Actual Janus interface · Demo identities and synthetic usage

See it on your own network.

The Community edition is free for up to 25 people. The 30-day Business trial unlocks every Business feature.