unlokai · For security, compliance and procurement

The control plane for every AI request your organisation makes.

It sits between everyone in your organisation who uses AI and every vendor they reach — OpenAI, Anthropic, Google and Groq — so routing, secrets, spend and access are decided in one place instead of per tool, per person, per contract.

No self serve signup at this tier. Deployment, retention terms and support commitments are set directly with an engineer.

What a review asks first
Does our vendor relationship stay direct?Yes, BYOK
Does access come from our identity provider?SAML + SCIM
Is our data used for training?Never
Could a bug or a stolen key overspend?Checked before the request
Can we get the logs into our SIEM?JSON, CEF
Can it run inside our own boundary?VPC or self host

Every answer on this card is expanded below with the specifics, not restated.

01 / What it is

One path in, one path out, four things decided in between

Every request follows the same path: it leaves a tool, gets checked for secrets, gets routed and priced, gets logged, and only then reaches a vendor.

01
Request leaves a tool
02
Checked for secrets
03
Routed and priced
04
Logged, then sent to a vendor
02 / Built to pass review

The two things that decide whether a review continues

Every request, one policy

Routing, secret scanning and spend limits apply the same way whether the request came from an editor, an agent, or a script — nothing to configure per tool.

Nothing decided twice

Access, budgets and approval rules live in one place, so a change to policy does not mean reconfiguring five different vendor consoles.

03 / OptimusENTERPRISE ONLY

SSO and a deployment boundary around the same shared memory

Personal memory stays with one person; a Team's memory bank is shared across the whole team. Every pin, correction, and removal is logged with who did it, and Enterprise adds SSO and a deployment boundary you choose on top of that same bank.

04 / Spend and access control

A ceiling checked before the request, not deep inside it

The balance is checked before any request reaches a vendor, in the same place every request passes through — not scattered across per endpoint logic where a bug or a compromised credential could skip the check entirely. Access itself comes from your identity provider, not a separate account this system invents on its own.

05 / Deployment

Three boundaries, and a real choice between them

Managed

We run the relay. Fastest to start, same routing, memory and controls as the other tiers.

VPC

The relay runs inside your cloud account. Traffic to vendors leaves from your own network boundary.

Fully self hosted

You run the relay end to end. Nothing about a request touches infrastructure outside your own perimeter.

This tier is the layer above, not a different product

Routing, the memory bank, secret scanning and budgets all work the same way as Team. Enterprise adds SSO and a deployment boundary you choose — it does not remove anything underneath.

Everything in Team
  • Routing, escalation and semantic cache
  • Secret scanning on every request
  • Budgets, approval rules and a hard stop
  • Bring your own keys
07 / Start the conversation

Four answers, so the first call is not a discovery call

Tell us the shape of the deployment and we come to the first call already knowing what to show.

Deployment, retention terms and support commitments are set in the contract — this just gets the right engineer on the first call.
Organisation size
Requirements
Deployment
Timeline

No self serve signup at this tier. Deployment, retention terms and support commitments are set directly, so the first conversation is with an engineer.

© 2026 HEX INNOVATION LIMITED. ALL RIGHTS RESERVED