Stay in control as you scale
Budgets that stop traffic at the cap, guardrails on inputs and outputs, team roles, and an audit trail - enforced at the gateway without touching your application code.
Control at the gateway, not in your code
Spend caps, rate limits, guardrails, and RBAC run before requests hit providers. Provider keys live on Cran, encrypted - never in your repo, Slack, or CI.
RBAC
Scope agent tokens to read, propose, or apply. Invite engineers per project.
Guardrails
PII redaction and output-schema validation at the gateway; injection stress tests in every audit.
Audit log
Every sensitive action recorded - who changed routing, when, and from where.
Server-side keys
OpenAI, Anthropic, and Google keys live on Cran, encrypted - rotate or revoke anytime.
Explore the rest of the control plane
Map your AI in 2 minutes.
Connect your repo, route every call through Cran, and publish routing when you have proof - not vibes.