New · Iris Control

The control plane for every LLM call in production

Route, govern, evaluate, and guard model traffic across every product, tenant, and provider. Policy lives in one layer your platform team owns, not in the gaps between four vendors.

Evaluating AI gateways? Iris Control covers the gateway and the governance around it.

Iris Control architectureApplications send every LLM call through Iris Control, which routes, governs, guards, and evaluates it before it reaches a model provider.YOUR APPSIRIS CONTROLMODELSSupport agentSearch & RAGInternal copilotAgent workflowsIris Controlone policy layer for every callRouteGovernGuardEvaluate+ Prompt ShieldOpenAIAnthropicGoogle GeminiSelf-hosted modelsProvider degraded: traffic failed over

By the IrisAgent team · Last updated

Your LLM stack grew faster than your controls

Multi-model products ship quickly. Then the platform team inherits a split stack: one vendor for routing, another for logs, a notebook for evals, a guardrail library per app. Nobody owns the policy in between.

Today: a split stack

Gateway vendorroutingLogging tooltracesEval notebookoffline onlyGuardrail libraryper apppolicy lives here?

With Iris Control: one layer

Iris Controlshared policy, one audit trailRoutingGovernanceObserveTool policyEvalsOutput guards

Outages become incidents

A provider outage or a model swap takes a live feature down when there is no routing policy and no failover.

Data crosses segments

Multi-product and multi-tenant orgs must decide which models may touch which data. A budget cap does not answer that.

No single view of I/O

Prompts and completions are scattered across apps, so nobody can answer what a model was asked and what it said.

Benchmarks, not your data

Generic leaderboards do not tell you which model wins on your corpora, your traces, and your users.

Tool sprawl

Agents keep picking up tools. Someone has to decide which models and workflows may call which ones.

Ungrounded answers ship

Without checks on the production path, hallucinated answers reach users before an offline eval ever sees them.

Six controls. One layer.

Everything a platform team needs to run LLMs in production, sharing one policy model and one audit trail.

Model routing and failover

Keep production LLM paths up when a provider or model degrades. Iris Control picks the right model for each use case and falls back automatically when a call fails.

  • Route each use case to the model that fits it
  • Fail over when a model or provider call fails
  • One routing policy shared across every product

Data-segment governance

Multi-product and multi-tenant stacks need more than a spend cap. Iris Control keeps retrieval inside the product or segment a request is allowed to search.

  • Filter knowledge by product or segment
  • Keep each corpus with the calls that should see it
  • One place for security to reason about data access

Observe every call

Inputs and outputs for every LLM call land on one path, so platform and security teams can audit what a model was asked and what it returned.

  • Log prompts and completions as calls happen
  • Inspect traffic across models from one place
  • A durable record of model I/O for review

Tool-use controls

Agents stay useful and safe when someone decides which tools they may call. Iris Control keeps tool use inside the set each workflow is allowed to invoke.

  • Invoke tools as part of the model workflow
  • Limit a workflow to the tools it may call
  • Add Prompt Shield for argument checks in your own apps

Evals on your data

Pick models by how they perform on your production data, not a public leaderboard. Quality checks run on your signals, on the same layer as routing.

  • Evaluate on customer-specific data
  • Grounding checks against the sources you approve
  • Quality gates that sit next to routing decisions

Output guards

Check the answer before it reaches a user or a tool. Grounding and judge-style review keep outputs tied to approved sources.

  • URL grounding on the production path
  • Judge-style review of every answer
  • Prompt-leak and citation checks via Prompt Shield

Anatomy of a governed LLM call

Every request takes the same path through Iris Control. Your apps call one endpoint. The control plane does the rest.

  1. 01
    One path for I/O

    Request in

    An app sends a prompt to one endpoint, tagged with its product, tenant, and use case.

  2. 02
    Prompt Shield

    Input check

    Prompt Shield inspects the input and isolates untrusted content before a model sees it.

  3. 03
    Governance

    Segment policy

    Retrieval and tools are scoped to the data segment and tool set this call is allowed to use.

  4. 04
    Routing

    Route and fail over

    The router picks the model for the use case and falls back if the provider call fails.

  5. 05
    Quality gate

    Output guard

    Grounding and judge-style review check the answer against approved sources.

  6. 06
    Observe + evals

    Logged and scored

    Inputs, outputs, and eval signals land in one record for platform and security review.

More than an AI gateway

Gateways stop at the proxy: one endpoint, many models, failover. Iris Control does that job and adds the policy a CTO org needs around it.

CapabilityProxy-only AI gatewayIris Control
One endpoint across model providersYes✓Yes
Failover when a provider degradesYes✓Yes
Data-segment governance for retrievalRarely✓Built in
Tool-use policy per workflowRarely✓Built in
Evals on your production dataSeparate tool✓Built in
Output grounding on the live pathSeparate tool✓Built in
Prompt injection protectionAdd-on✓Prompt Shield
Security module · Early access

Prompt Shield, built into the control plane

Prompt injection protection sits on the same path as routing, governance, and output guards. Prompt Shield inspects inputs, isolates untrusted content, and checks outputs. The same protections already run inside IrisAgent apps in production.

Inspect inputs
before the model sees them
Isolate untrusted content
docs, tickets, web pages
Check outputs
before users or tools do

Built for the platform org

The CTO and the platform or AI engineering team own Iris Control. Security joins for data access, audit, and enforcement. Every line-of-business app consumes the same layer.

Economic buyer

CTO

One control layer for production risk, cost, and quality, in place of four vendors that do not share policy.

Technical buyer

Platform and AI engineering

Owns model choice, failover, call visibility, tool limits, and evals on your data. Ships faster when the guardrails are already on the path.

Co-buyer

Security

Gets data-segment access rules, an audit trail of model use, and guards on inputs and outputs. Prompt Shield is the module to review with them.

Any questions?

We got you.

Iris Control, LLM control plane

Put every LLM call behind one control plane

We will walk through routing, governance, failover, and quality gates with your platform and security leads, on your use cases.