Security
Your keys. Your data. Zero markup.
Alpha is a control layer, not a data broker. No hand-waving, no fine print — here's exactly how your keys and data are handled.
Arena
Arena never needs your credentials.
The whole point of Arena is a cost revelation before you integrate anything. Computation happens in your browser.
Paid plans
BYOK, and no markup — ever.
Bring your own key
You add your own provider keys (OpenAI, Anthropic, Google, Bedrock, and more) in the dashboard. Alpha routes through your own accounts and never marks up your model costs — you pay providers exactly what you always did.
Keys stay scoped and isolated
Provider keys are stored server-side and isolated per workspace — no tenant can see another's keys. Each key is scoped per agent: a request can only reach the providers that agent is explicitly allowed to use. Clients authenticate with an Alpha gateway key, never your raw provider key.
Fails open, not closed
If the gateway is unavailable, your agents keep running against your providers directly. Control shouldn't be a single point of failure.
Sovereign option
Enterprise can deploy Alpha self-hosted or in a sovereign environment, so nothing leaves your boundary at all.
Governance & deployment
Built for the people who sign off.
Deploy where you must
Cloud, hybrid, or fully self-hosted / on-prem (Kubernetes, VMs, your GPUs). Your data and keys can stay entirely inside your boundary.
NIST AI RMF aligned
Compliance tracking mapped to the NIST AI Risk Management Framework, with audit logs — governance you can produce as evidence, not assert.
Roles & workspaces
Multi-tenant workspaces with role-based access (owner, admin, developer, member) and per-workspace isolation of keys and data.
Regulated-data mode
For sensitive workloads, enforce redacted storage and restrict what can be used downstream — controls that run at request time, not after the fact.
Questions about a specific control? Talk to us.