Every Feature You Need to Govern AI

One platform. Five modules. Zero stitching. From security scanning to compliance export — everything is here.

Security

Prompt Injection Detection

87-payload library detecting indirect prompt injection, jailbreak attempts, and system prompt leakage. Updated weekly with new attack vectors.

API Vulnerability Scanner

BOLA/IDOR detection, insecure HTTP methods, missing auth, CORS misconfigurations, rate limit bypass testing. OWASP API Top 10 mapped.

Secret Scanning

10-rule detection for AWS, GitHub, OpenAI, Anthropic, Stripe, Slack, JWT, and private keys. Includes Aadhaar and PAN for India compliance.

Shadow API Discovery

Static route extraction for Express, FastAPI, Flask, Django, Spring Boot, Laravel. No production traffic needed.

PII Redaction

Real-time redaction of emails, phone numbers, SSNs, credit cards, and Indian ID numbers before data leaves your infrastructure.

Cost Governance

Per-Request Cost Tracking

Track every LLM token across OpenAI, Anthropic, Gemini, Cohere, Mistral, and Groq. Includes reasoning token isolation.

Holt-Winters Forecasting

Predict next 30 days of spend with 95% confidence intervals. Detect seasonality and trend shifts automatically.

Anomaly Detection

Statistical anomaly detection flags unusual spend patterns. Alert when daily variance exceeds 3 standard deviations.

Autonomous Kill Switch

Circuit breaker that blocks all LLM calls when budget, anomaly threshold, or red-team score triggers. Sub-second response.

Thinking Token Attribution

First-in-world isolation of reasoning tokens (o1, o3, Claude). Patent NHCE/DEV/2026/002. Exact cost per reasoning step.

Compliance

SOC 2 Evidence Builder

Auto-generate evidence for all 5 Trust Services Criteria. Map findings to controls. Export for Vanta/Drata import.

PCI DSS v4.0.1 Mapping

47 controls mapped to API security findings. Requirement 6.5, 11.3, and 6.4 coverage with remediation guidance.

OWASP Compliance Scoring

Real-time score for OWASP API Top 10 and LLM Top 10. Track improvement over time with trend analysis.

Audit Log Export

Immutable audit logs with tamper-proof hashing. Export as JSON, CSV, or PDF. 7-year retention for enterprise.

GDPR / DPDP Act Support

Data subject request handling, right to erasure, consent tracking, and cross-border transfer documentation.

Developer Experience

VS Code Extension

Scan collections, view findings, and trigger kill switch from your editor. Inline security warnings as you code.

GitHub Action

PR comments with severity badges, exact endpoint names, one-line fixes, and cost impact in USD + INR.

JavaScript SDK

One-line integration: `import { RakshEx } from '@rakshex/sdk'`. Automatic request interception and cost tracking.

Python SDK

Drop-in middleware for FastAPI, Flask, Django. Async-first design with zero blocking on the hot path.

Express.js Middleware

app.use(rakshEx.middleware()) — automatic route discovery, secret scanning, and cost attribution.

Enterprise

SAML 2.0 + OIDC SSO

Okta, Google Workspace, Microsoft Entra, Azure AD, OneLogin. JIT provisioning and 4-role RBAC.

Team Workspaces

Isolated workspaces with shared collections, role-based access, and per-team budget caps.

Custom Data Retention

Configure retention from 30 days to 7 years per workspace. Automated archival and deletion workflows.

Priority Support

4-hour SLA for Enterprise. Dedicated Slack channel, quarterly business reviews, and custom onboarding.

Private Cloud Deploy

Self-hosted option with Docker Compose, Kubernetes Helm chart, or AWS/Azure/GCP marketplace deployment.

Ready to see it in action?