We went looking for the benchmark behind our own published latency figure and could not find one. Measuring properly started at 302ms p95, surfaced three product bugs, and ended at a public, reproducible 16ms p50 / 21ms p95.
Gateco is now listed in the Okta Integration Network. Install the app from the OIN catalog and provision users and groups into Gateco over SCIM 2.0 in minutes, no custom SCIM app required.
Purview classifies, labels, and governs your data estate. It does not decide, at query time, whether a specific user may retrieve a specific document from the AI your team is building. That gap has a name: retrieval authorization.
Law firms are putting AI over matter documents. Here is how to enforce ethical walls, privilege, and conflicts screening at the retrieval layer with Gateco.
Gateco supports role, attribute, and relationship-based access control, and you can mix them in one policy set. Here is which model fits which pattern.
Gateco is not a RAG framework. It is the authorization layer you insert at the retrieval step of LangChain or LlamaIndex. Here is where it goes, and why.
Gateco now supports per-org OpenAI keys for Grounded Answers, encrypted with AES-256-GCM and per-tenant KMS binding. Here is how the credit model works.
Google has two retrieval products under the Vertex AI brand: Vector Search, a managed ANN index, and Vertex AI Search, Discovery Engine. When to use each.
The Gateco MCP server gives Claude Desktop, Cursor, and any MCP host policy-enforced access to your vector knowledge bases. Denied content never surfaces.
Gateco now supports 1-hop relationship-based access control: policies can check whether a principal owns or is assigned to a resource. How and when to use it.
IAM authenticates the agent. Gateco authorizes the data. Why one IAM role is not enough when your chatbot serves thousands of users, and how to fix it.
Cerbos is a generic authorization engine. Gateco is a retrieval-specific security layer for RAG. They solve different problems, and can be used together.
Every RAG pipeline your team ships creates an access surface that bypasses application-layer authorization. Here is how to close the gap, in security terms.
How much latency does an authorization layer add to RAG? The measured answer, with a public benchmark: 16ms p50 and 21ms p95 policy overhead, and what drives variance across connectors.
Gateco enforces the same deny-by-default policies across AWS OpenSearch, Azure AI Search, and Google Vertex AI, so RAG governance stays consistent everywhere.
Gateco now integrates with Google Vertex AI Vector Search and Vertex AI Search, bringing deny-by-default retrieval, ABAC policies, and audit trails to GCP.
Azure AI Search is a managed search platform; pgvector, Pinecone, and Qdrant are retrieval primitives. The choice shapes your RAG architecture and governance.
Metadata filters are the most common approach to RAG access control, and fundamentally insufficient. Why they can't replace a dedicated permission layer.
Four approaches to RAG authorization compared: no auth, metadata filters, app-layer RBAC, and a dedicated permission layer. Pros, cons, and when each fits.
DIY RAG authorization needs a policy engine, metadata resolution, audit logging, connector adapters, and identity sync. What it actually takes to build it.
We're launching Gateco, the security middleware between AI agents and organizational knowledge: deny-by-default retrieval, 12 connectors, and audit trails.
The Access Simulator dry-runs policy evaluation so you see exactly what a principal would be allowed or denied before activating policies. How to use it.
When auditors ask who accessed what data through your AI system, you need an answer. Gateco's audit trail covers 50+ event types across every operation.
Financial services face unique RAG challenges: information barriers, SOX compliance, and classification-based access to market-sensitive data. How Gateco helps.
Healthcare RAG must protect PHI at every retrieval. Gateco's ABAC policies, classification-based access, and audit trails support HIPAA minimum necessary.
SaaS platforms with LLM features must prevent cross-tenant leakage in shared RAG infrastructure. How to enforce tenant isolation at the retrieval layer.