Govern

Stay in control as you scale

Budgets that stop traffic at the cap, guardrails on inputs and outputs, team roles, and an audit trail - enforced at the gateway without touching your application code.

Control at the gateway, not in your code

Spend caps, rate limits, guardrails, and RBAC run before requests hit providers. Provider keys live on Cran, encrypted - never in your repo, Slack, or CI.

Spend caps with hard stops Guardrails + per-product tokens Teams, roles & audit log
Control plane

RBAC

Scope agent tokens to read, propose, or apply. Invite engineers per project.

Guardrails

PII redaction and output-schema validation at the gateway; injection stress tests in every audit.

Audit log

Every sensitive action recorded - who changed routing, when, and from where.

Server-side keys

OpenAI, Anthropic, and Google keys live on Cran, encrypted - rotate or revoke anytime.

Map your AI in 2 minutes.

Connect your repo, route every call through Cran, and publish routing when you have proof - not vibes.