CAIN-42 CAIN Studio

Developer documentation

Beside your gateway

Last reviewed 31 August 2026

All docs

CAIN beside the gateway you already run#

Most teams that ship agents already run an LLM gateway (Portkey, Kong AI Gateway, Cloudflare AI Gateway, LiteLLM or their own), and often an AI runtime security product that inspects prompts and responses. Keep them. They govern model traffic. CAIN governs what the agent does with your tools, and leaves a signed record of every decision. The two sit side by side; neither routes through the other.

            prompts / completions
  agent  ─────────────────────────▶  your LLM gateway  ─▶  model provider
    │                                 (routing, keys, budgets, prompt guardrails)
    │
    │  before each tool call: "may this run?"
    └──────────────────────────────▶  CAIN decision API ─▶ verdict + signed record
                                            │
             only if ALLOWED* and not blocked
    agent ─────────────────────────▶  the tool / API / MCP server

Nothing in your gateway configuration changes. CAIN needs no access to your model traffic, and your gateway needs no access to CAIN.

What each layer answers#

QuestionAnswered by
Which model, which provider key, what budget, what retry?your LLM gateway
Is this prompt or completion malicious or leaking data?your prompt guardrail or AI runtime security product
May *this agent* call *this tool* with *these arguments*, now?CAIN
Can we prove afterwards what was decided, without trusting any vendor's dashboard?CAIN's signed decision records (format)

A prompt filter lowers the chance a model is talked into a harmful call. It cannot stop the call once the model makes it. The decision at the tool boundary is the control that still applies when the prompt check missed.

Step 1: ask CAIN before tool calls#

Use the one-file guard from Use with your existing stack (LangChain, OpenAI Agents SDK, CrewAI, MCP), or call the API directly. Your gateway keeps handling the model call exactly as before.

Step 2: correlate CAIN with your gateway's logs#

Send the same run identifier to both. Most gateways accept a trace or request id header; pass that value to CAIN as chain_id, and every decision in the run becomes one trace in the CAIN console:

curl -s https://cainstudio.online/fabric/decisions \
  -H "X-API-Key: $CAIN_API_KEY" -H 'content-type: application/json' \
  -d '{"path":"/tools/refund_order","agent_id":"billing-agent",
       "chain_id":"run-8f2c",
       "payload":{"order_id":"o_123","amount_cents":4200}}'

GET /fabric/trajectories/run-8f2c then returns every decision of that run in order, which you can line up against the gateway's own log for run-8f2c.

Step 3: put MCP servers you do not own behind MCPGate#

For third-party MCP servers you cannot add code to, put MCPGate in the call path. See MCP.

Step 4: send decisions to your SIEM#

Security teams want CAIN's decisions next to everything else they watch. CAIN forwards each decision as it is made, to a destination the workspace owner configures: Splunk (HTTP Event Collector), Cortex XSIAM (HTTP log collector) or any HTTPS endpoint that accepts JSON. See SIEM forwarding.

Step 5: keep the evidence#

Every decision's signed record can be exported and checked offline with a verifier that has no CAIN code in it (specification and verifier). Your gateway's logs show what the model was asked; the signed records show what the agent was allowed to do.

Questions teams ask#

Does CAIN replace our gateway? No. CAIN does not route, cache or meter model traffic.

Does it add latency to model calls? No. It is not on the model call path. It adds one HTTP round trip before each consequential tool call; read-only tools can skip the check.

We already bought an AI security platform. Keep it. Most of these products inspect prompts, responses and posture. CAIN decides and records tool calls, and forwards those decisions into the same SIEM your platform feeds.

What if CAIN is unreachable? The guard treats that as "do not run". Choose which tools need the check; tools that only read public data can run unguarded.

Evaluating this for a team? [Contact us](mailto:support@cainstudio.online) and we will set it up beside your gateway, on one of your agent's real tool calls.