HomeProductsGoverned API Gateway
Products · The API plane

The whole platform, as governed APIs.

Everything Prove7 does — agents, workflows, trust, policy, evidence — is a full-fledged, OpenAPI-documented API. The Governed API Gateway puts one default-deny plane in front of all of it: scoped credentials, distributed rate limits, quotas, entitlements, and a sealed audit line per call.

How it fits your estate

Your applications, scripts, portals, and partners drive the platform programmatically. Nothing is reachable by default; everything callable is scoped, limited, metered — and on the record.

YOUR SYSTEMS PROVE7 CONTROL VECTOR™ THIRD-PARTY & MODELS Your applications internal portals · services Automation & scripts CI/CD · cron · notebooks Partners & MSSPs scoped, expiring access Your developers OpenAPI / Swagger docs · typed errors Governed API plane (default-deny) scoped API keys or OAuth2 client-credentials · IP allowlists exposure tiers: customer / internal / admin — least surface by default Limits, quotas & metering distributed token-bucket RPM + burst · daily quotas · per-tenant metering 1,000+ platform APIs agents · workflows · skills · trust scores · policies · approvals · evidence Sealed record every call audited on the hash chain Entitlements & editions rides your plan — READ_ONLY or FULL Billing modes pre-committed or usage-based Key lifecycle create · rotate · suspend · revoke SIEM export access audit streamed out scoped calls honest 429s gated by plan audit stream typedresponses
Default-deny: every route is classified by exposure tier; only customer-tier, scoped, entitled routes answer. Same plane, same record, whether the caller is your portal or your partner.

API protection that reads like a spec sheet

Frequently asked

What is the Governed API Gateway?

It is the single governed entry plane for the entire Prove7 platform API surface: every capability — agents, workflows, trust scores, policies, evidence — is exposed as OpenAPI-documented endpoints behind default-deny authentication, scoped keys or OAuth2, distributed rate limits, quotas, and per-call sealed auditing.

How is this different from the MCP Gateway + SDK?

The MCP Gateway and SDK govern your agents’ executions — they bring outside agents under governance. The Governed API Gateway exposes Prove7 itself as APIs, so your applications, scripts, and partners can drive the platform programmatically with API-grade protection and limits.

How are API rate limits enforced?

With a distributed token-bucket per credential: requests-per-minute with burst headroom plus a daily quota, enforced consistently across the whole fleet. Exceeding a limit returns a clean 429 with retry headers — and the event is recorded like everything else.

RELATED:MCP Gateway + SDK →Platform →Products →
Accountable Autonomy™ — answers as it acts.

See it govern an agent end-to-end in 30 minutes.

If you’re the one who answers when the machine acts — a CISO, a CFO, a COO — watch Prove7 Control Vector™ take an agent from discovered to governed to proven, live.

Schedule a Demo →