Early access · the hosted edition is live today at app.acutisgo.com/gate with your Acutis login. The on-prem editions, a Linux appliance and a Windows Server install, now sign people in with Windows, sync Active Directory and open file shares as the person. Join the pilot for the first installers.
For the CIO, CISO and IT director

Contain AI inside your network.

Let every employee use AI, cloud or local, and keep it inside your walls. Acutis Gate is AI access that knows who's asking: every action runs as the person who asked, under guardrails you set, recorded in full and streamed to your SIEM. Identity-based access control, built for AI. It works with what you already run, old and new.

Hosted edition live Cloud AI and local AI, same guardrailsEvery call as the person who asked Windows sign-in, no login pageOnly the files each person can open Learning mode, then guardrailsData filter before the modelStreams to your SIEM
The Gate console

Connect an AI. Connect your apps. See every decision.

One page per job: connect an AI, your apps, approvals, the audit trail, and for admins, identity, guardrails, groups and streaming to your SIEM.

Acutis Gate · console · live demo
Tour the live Gate, full interactive demo →

Opens right here. No login, no install. Click through every page with sample data.

Security product first

Three promises you can actually keep.

Gate does not guess intent and does not read minds. It makes three mechanical promises about every AI action in your company, and each one is checkable.

◉
01

Attributed

Every call is tied to a real person from your directory. When a system can only take a shared account, the row says so. There is no anonymous "the AI did it".

⚖
02

Fenced

A fresh Gate learns first: everything allowed, everything recorded. Then you build the guardrails from what people actually did, one click. From then on, rules you wrote decide what each person's AI may read, change or run, and which actions wait for an approver. Explicit deny always wins. Cards, Social Security numbers and secrets are redacted before the model ever sees them.

🔗
03

Recorded

Everything, hash-chained: full arguments and results, what each AI was shown, failed sign-ins, every policy and identity change. Streamed live to Splunk, Sentinel, QRadar or any syslog or webhook SIEM. One click proves nothing was edited.

What Gate never claims: it does not detect bad intent, it does not know on its own that a request "needs escalating", and it cannot see AI calls that bypass it. Approvals are rules you write, like change control. The companion control is a firewall rule that makes Gate the only tool server your AI clients can reach.

Runs in your building

Your model. Your network. Your directory. Nothing leaves.

Gate is built for organizations that can't send their data to a cloud AI: local government, hospitals, utilities, finance, MSPs with strict clients. It installs next to your local LLM and talks to the systems you already run, inside the walls, including the file shares and directory that never moved to the cloud.

Your employees' AI
Any MCP-speaking client

Open WebUI on a local model, Claude Desktop, Cursor, Copilot, Carlo. One personal token per person, whatever their job.

→
Acutis Gate · on-prem
One small box, inside the domain

A small Linux box, a VM, or your own Windows servers. Windows sign-in from a domain PC, no new SSO app. Policy, approvals and the audit chain live here.

→
Your systems
Called as that person

Active Directory, on-prem file shares, Microsoft 365, the HR system, firewalls, monitoring: each call carries that user's own ticket, token or key.

Local LLM on the same box, no tokens billed File shares read as the user: their mapped drives, their NTFS rights The model holds no credentials, no route to your tools Air-gap friendly: no cloud account, no telemetry
Live today

Hosted edition

Gate inside the Acutis cloud at app.acutisgo.com. Right for SaaS apps, trying it from Claude Desktop or Cursor, and seeing the policy and audit model in minutes. Free.

Pilot · early access

Linux appliance

A small box or VM inside your network, with Open WebUI and a local model preloaded, or pointed at the model you already run. Windows sign-in, Active Directory sync, file shares as the person.

Pilot · early access

Windows Server

The same Gate on the Windows servers you already run, from one installer: it sets up its own managed service account, certificate and Group Policy. Same console, same Active Directory setup, same Health check.

File shares

Each person's AI sees their drives. Only what they can open.

Most AI file connectors read a share with one powerful account and hope for the best. Gate opens files as the person, and only on the drives Group Policy already maps for them. If they couldn't open it in Explorer, their AI can't find it, read it or even learn its name.

📁

Mapped drives, learned from AD

Gate reads the drive maps you already publish: Group Policy drive maps with their group and OU targeting, home drives and logon scripts. No list of shares to maintain. A person's AI reaches only paths under their own S:, H: and friends.

🔑

Your NTFS rights decide

Every folder and file is opened with that person's own Windows identity, so the permissions and Access-Based Enumeration you set years ago apply to AI exactly as they do on their PC. Gate's guardrails can narrow it further, never widen it.

👁

Hidden means hidden

On shares without Access-Based Enumeration, people can still see folder names they can't open. Gate removes those from listings and searches, so the AI never learns them, and the audit trail records only a count. The Health check tells you which shares to switch ABE on for.

Works with what you run

Cloud AI or local AI. Old infrastructure or new.

One set of guardrails, whatever your people use and whatever you still run. The promise to the board is the same either way: AI never sees or does more than the person using it.

Cloud AI

Microsoft Copilot, Claude, ChatGPT, Cursor. They connect to Gate as the only tool server they have. Each call carries the person's own identity; what comes back is logged. Hosted edition today, free.

Local AI

Open WebUI with a model on your own hardware. Gate runs on the same box or beside it. Nothing leaves the building: not the prompt, not the data, not the credentials. On-prem edition, in early access.

Modern apps

Each person's own sign-in

Microsoft 365, Google Workspace, the HR system, CRM, finance: OAuth on behalf of the user, so the app's own permissions decide.

Your directory and shares

Windows sign-in, as the person

Kerberos from a domain PC, or NTLM for older PCs and apps (NTLMv2 only, with relay protection). File shares open with that person's own identity, under the NTFS and AD rights you already set.

Legacy systems · limited

Shared account, labelled

Systems with no personal login run under one shared account. Gate marks every such call "shared" in the audit trail and lets you fence it with guardrails. Honest, not magic.

How it works

Not in the conversation. In every action.

Gate doesn't police what people say; it controls what they can reach and do, because it is the only door the AI has.

◉
01 · Sign in as you

Your identity, not a bot's

Email + authenticator, Google Workspace, or (on-prem) Windows sign-in from your domain PC with no login page at all. Your AI client gets a personal token that is you.

⚙
02 · The AI sees only your tools

Policy before the prompt

When the client asks what tools exist, Gate answers with only what your policy allows. A tool you can't use is never in the model's context.

✓
03 · Every call runs as you

Delegated, then audited

Gate re-checks policy, carries your own key, token or ticket to the system, hashes the result into the audit chain, and returns it. Nothing else can reach the tools.

👤

Delegated execution

The call to a file share, Microsoft 365, the HR system, Orion or AD carries that person's own credential. If the application wouldn't show them something, the AI can't either. No god account.

⚖

Guardrails built from the trail

Rules read like a director thinks: HR partners can read the HR system. Firewall changes need a network admin. Nobody touches the Legal share. Gate drafts the first set from a week of real use; explicit deny always wins.

🔗

Everything in the chain, streamed

Every call with its full arguments and result, what each AI was shown, failed sign-ins, every policy, group and identity change. Hash-chained, and streamed live to your SIEM as syslog, CEF, a signed webhook or Splunk HEC.

🖥

Any AI, same rules

Open WebUI on a local model, Claude Desktop, Cursor, Copilot or Carlo. Same endpoint, same per-user tools, same audit trail.

The what-if sheet

The questions your CISO will ask. Answered before the meeting.

Most AI policies ban integrations because nobody could answer these. Gate is the answer sheet.

an L1 tech asks the AI for the firewall rules?

The call runs under their own PAN-OS account. The firewall returns what their role allows, which for L1 is nothing. Gate logs the attempt either way.

HR asks the AI for someone's salary?

The HR system is called as that HR user, with their own login. If they may see it at the console, the AI may; if not, not. Finance asking the same gets a deny, and both attempts are in the chain.

someone asks the AI to summarize a file on the Finance share?

Gate opens it as that person, and only if it sits under a drive Group Policy maps for them. If NTFS says no, the AI is told the file isn't there, and the attempt is in the chain. The share permissions you set years ago keep working, now for AI too.

someone asks the AI "anything about layoffs?"

The search runs with their own permissions. Folders they can't open are left out of the results, names included, so a folder called "Layoffs 2027" never reaches the model. The trail records "hidden: 1", never the name.

some of our PCs and apps can't do Kerberos?

Turn on NTLM for them. Gate accepts NTLMv2 only, requires relay protection by default, has a domain controller check every answer, and marks each NTLM sign-in in the trail so you can see who still needs it.

someone skips the chat UI and hits the API directly?

They reach Gate, not the tools. Policy is enforced at the gateway, not in the interface, and their token is still their identity.

a document contains a prompt injection?

Tool output is data, never instructions. Writes and executes are staged for an approver by policy, so a tricked model still can't change anything alone.

the auditor asks who saw what?

It is already in your SIEM, and the chain exports as NDJSON. Every row carries the user, their groups at that moment, the policy version in force, the identity the call ran as, the arguments and the result. Verify proves nothing was edited.

our model runs on our own box, not in a cloud?

Gate runs beside it. Open WebUI, the model and Gate stay inside the building; the prompt, the data and the credentials never leave. Same guardrails, same chain as the cloud AI your other teams use.

the SIEM is down for an hour?

AI calls keep working; delivery is off the request path. The destination shows its last error in the console, every row is still in Gate's own chain, and the collector can page what it missed by cursor when it is back.

how does Gate know an action needs approval?

It doesn't guess. You write the rule, like change control: finance writes, firewall commits, or every write not explicitly allowed. A matching call is staged with its exact arguments; an approver sees them, enters an authenticator code, and it runs as the person who asked.

How we stack up

Built for the company, not the platform team.

Agent gateways exist for cloud apps that speak OAuth. Vendor copilots cover one product each. Gate covers every employee and reaches the on-prem estate, as that person, on a box you own.

CapabilityAcutis GateCloud agent gatewaysVendor copilotsShared service account (today)
Runs on-prem next to a local LLM✓ Linux appliance, VM, or your Windows servers✗ Cloud or Kubernetes✗ Vendor cloud✓ Wherever you put it
Every call as the person who asked (Kerberos, OAuth, per-user keys)✓ Delegated by construction✓ OAuth apps only✓ Inside that one product✗ Everyone is the admin
On-prem AD, file shares, firewalls, monitoring, hypervisors✓ AD, SMB shares, PAN-OS, Meraki, Orion, vCenter✗ No OAuth, no support✗ One vendor each✓ With a god account
File shares: only the person's mapped drives, hidden names never reach the model✓ Group Policy drive maps, NTFS, ABE-style hiding✗ No SMB✗ Their own storage only✗ Sees every share the account can
Any AI client (Open WebUI, Claude Desktop, Cursor, Copilot)✓ One MCP endpoint✓ Developer clients✗ Their chat only✓ And that is the problem
Guardrails a director can read, drafted from real use✓ Learning mode · allow · deny · approve · break-glass✓ Developer-grade YAML✗ Vendor roles only✗ None
Tamper-evident audit, streamed to your SIEM✓ Full payloads, syslog/CEF, Splunk HEC, webhook✓ Logs✓ Inside that product✗ One shared login in the logs
Sold and priced for a company, not a platform team✓ Free hosted, appliance in early access✗ Enterprise sales cycle✗ Per-platform licensing✓ Free, until the audit

Why start with the hosted edition?

Sign in with your existing Acutis account, create a token, and run "what will this AI see as me". You'll have the policy and audit model in your hands in ten minutes, before any box is ordered.

Open the Gate console

Same login as the Fleet and the Floor.

Choose your edition

Same Gate, three places to run it.

The console, guardrails and audit trail are identical everywhere. What changes is how far Gate can reach: the on-prem editions live inside your network, so they can sign people in with Windows and open your file shares as them.

What you getHostedLinux applianceWindows Server
StatusLive, freePilotPilot
Runs onThe Acutis cloudA small Linux box or VM in your networkYour Windows Server (domain member)
Each person's AI reaches your apps as that person (MCP)✓✓✓
Guardrails, approvals, learning mode✓✓✓
Data filter before the model✓✓✓
Tamper-evident audit trail, streamed to your SIEM✓✓✓
Sign-in with email + authenticator or Google✓✓✓
Windows sign-in from a domain PC (Kerberos, NTLMv2)✗✓✓
Active Directory sync: people, nested groups, leavers✗✓✓
File shares as the person: mapped drives, hide what they can't open✗✓✓
Local AI modelBring your own cloud AIOpen WebUI + a local model preloaded, or yoursConnects to the model you run
Prompts, files and credentials stay in your building✗✓✓
Who runs itAcutisYou, one installerYou, one installer

Your AI work lives in cloud apps

Microsoft 365, Google Workspace, SaaS tools, no on-prem directory to reach. Start with Hosted, free, in ten minutes.

You run Active Directory and file servers

And you want a local model with nothing leaving the building. The Linux appliance brings Open WebUI and a model with it.

You only run Windows servers

Same on-prem features on the servers you already patch and back up. Windows Server, from one installer.

Pricing

Priced per person, not per enterprise.

Gate is the middle of the Acutis ladder: Go on every desktop, Gate for every employee who uses AI, Networks for the whole site. Appliance pricing is being set with the first pilots.

Hosted

$0 / mo

Gate in the Acutis cloud, today.

  • Your Acutis login (email + authenticator, or Google Workspace)
  • Personal tokens for any MCP client
  • Acutis' own tools as the first upstream
  • Policy versions, test-as-user, dry run
  • Approval queue, full audit trail, SIEM streaming, data filter
Start free
The real one

On-prem appliance

Set with first pilots

Everything in Hosted, inside your network.

  • Linux appliance or Windows Server, one installer
  • Windows sign-in from a domain PC (Kerberos, or NTLMv2 with relay protection), no new SSO app
  • Active Directory sync: people, nested groups, leavers disabled
  • File shares as the person: mapped drives only, hide what they can't open
  • Per-user keys and OAuth for Microsoft 365, HR and finance systems, PAN-OS, Meraki, Orion
  • Local LLM and Open WebUI preloaded, or bring your own
  • Security-review packet for your AI policy
Join the appliance pilot

MSP · Gate

Set with first pilots

One team, thirty client environments, zero god accounts.

  • One Gate per client site, one portfolio login
  • Your staff act inside each site as themselves
  • Every site keeps its own policy and audit chain
  • Client-visible "your MSP did this" provenance
Join the MSP pilot

Start lower on the ladder? Acutis Go is the free endpoint agent, and Acutis Networks is the appliance that manages the gear. Gate makes both act as the person who asked.

Roadmap

From hosted to inside the domain.

✓ Shipped · Oct 2026

Gate v0.1, hosted

MCP endpoint, per-user tool visibility, delegated and mapped upstreams, learning mode with guardrails drafted from the trail, approve and break-glass, data filter, full-payload hash-chained audit streamed to syslog, CEF, webhook and Splunk HEC, console with Google Workspace sign-in.

✓ Shipped · Oct 2026

Windows sign-in, AD and file shares

No-login Windows sign-in (Kerberos, and NTLMv2 with relay protection), Active Directory sync with nested groups, and file shares opened as the person: mapped drives only, hide what they can't open. On the Linux appliance and on Windows Server.

Q4 2026

Signed one-click installers

The Windows Server install as one signed installer, and the Linux appliance image, with Open WebUI and a local model preloaded if you want them. Fresh secrets per box.

Q1 2027

SAML and field allow-lists

SAML for ADFS shops, groups from Google Directory, and per-connector field allow-lists that keep secrets out of model payloads entirely.

Behind the name

A gate, not a wall.

A wall keeps AI out, which is what most AI policies do today. A gate lets the right person through, on their own name, and remembers who passed. Acutis means sharp: clear-eyed about who is asking.

Go is the cyan signal on every desktop. Networks is the gold light on the appliance. Gate is the red line every action has to cross: the AI acts as you, never as the box.

Nobody sees what they aren't authorized to see

Get in touch

Running a local LLM and want it to reach your systems safely, for everyone? Let's talk pilots.

Official emailsupport@acutisgo.com

Note on LinkedIn outreach: due to automated spam and phishing, inquiries sent via LinkedIn messaging are ignored. Please use the official email.

Early access

Get the first on-prem installers.

The hosted edition is free today. Leave your email and we'll send the appliance installers and the security-review packet as they land.

No card, no sales call.

✓ You're on the list. We'll be in touch as the on-prem edition opens up.

Ready when you are

Let everyone use AI on your systems. As themselves.