Corrath
Corrath is a deterministic security gateway placed between applications and LLM providers. It neutralizes prompt injections, caps spend per key, fails over during provider outages and logs every request in under 5 ms. Built for developers and platform engineers.
What is Corrath?
Corrath is a proxy gateway that sits transparently between client applications and LLM backends. The site frames the problem in four parts: calling a model API directly exposes you to prompt injection, to provider outages, to uncontrolled cost and to compliance risk. The answer is a single interception layer, in the publisher's own words a "high-performance proxy layer transparently between your core client applications and LLM backends, implementing security filters, spend caps, and outage failovers."
Ten systems are announced under one dashboard: AI Gateway, Security Firewall, Budget Controls, Cost Forecasting, Analytics, Webhooks, Multi-Provider Routing, Failover Protection, Usage Monitoring and Threat Detection. The features page regroups the same ground into eight modules: API Key Vault, Firewall Shield, Threat Center, Audit Logs, Webhooks & Alerting, Team Management, Cost Forecasting and Multi-Provider Routing. Five providers are covered behind a standardized call syntax: OpenAI, Anthropic/Claude, Gemini, Mistral and DeepSeek.
Detection runs in memory, combining high-performance regex filters with semantic embeddings, and is claimed to complete in under 5 ms. Failover works the same way: a circuit breaker trips on a 5xx error or a rate limit from the primary provider, and traffic is rerouted, again under 5 ms. Provider credentials live in a key vault with AES-256 encryption announced, secure decryption on read and multi-tenant scopes. Audit logs are described as immutable, with action tracing and structured downloads. The home page advertises a 99.99% SLA, 500,000+ protected requests and 10M+ tokens processed.
What the site does not say deserves equal attention. There is no about page, no team presentation and no social account, the JSON-LD declaring an empty sameAs. Developer keys carry an aishield_live_ prefix and the browser storage objects are named aishield_access_token and aishield_session, the trace of an earlier product name. Three named testimonials appear on the home page: Elena Rostova (CTO, NeuroFlux AI), Marcus Vance (VP Engineering, CloudCore) and Dr. Aris Thorne (Platform Architect, GuardSecure). The domain was registered on June 7, 2026 and the sitemap is dated June 3, 2026, so this is a very recent product, published by Corrath Corp. under the law of the State of California.
What it does
- Route completion requests to several LLM providers with automatic switchover
- Block prompt injections and jailbreaks before they reach the model
- Mask PII inside payloads using regex and pattern rules
- Cap spend per developer key and block calls beyond the threshold
- Store provider credentials in an encrypted vault
- Forecast the end-of-month bill and alert before the threshold is crossed
- Push HMAC-SHA256 signed alerts to Slack, Discord, email or a custom endpoint
When to use Corrath / When not to
A quick filter to help you decide if Corrath is the right fit.
When to use Corrath
- Engineering teams that call several LLM providers from a single production application
- Platform teams that need automatic failover when a primary provider returns 5xx errors or rate limits
- Teams where a recursive agent loop can blow up the model bill overnight, the case the site illustrates with a customer who intercepted a runaway billing loop in the first week
- Security and compliance owners who must stop PII, financial data or credentials from leaking into prompts
- Organizations that need RBAC, shared seats and immutable audit logs, available from the BUSINESS tier upwards
When not to use Corrath
- Anyone looking for a model provider: Corrath routes traffic but does not supply the LLMs, and your OpenAI, Anthropic or Gemini subscriptions remain your own responsibility under the terms (§1)
- Developers who want to read public API documentation or install an SDK before signing up: the ten-URL sitemap contains no docs page and /api/ is disallowed in robots.txt
- Users who need a mobile app, a browser extension or a desktop client, since the product is web and API only, with on-premise deployment reserved for a negotiated ENTERPRISE contract
- Buyers whose procurement demands documented supplier due diligence: no postal address, no registration number and no named team are published anywhere
- Small projects planning to stay on the free tier, which is capped at 500 requests a month and includes neither the security firewall nor the provider fallback
How to use Corrath
A typical end-to-end flow, from setup to results.
- Create an account on the registration page with an email and password, or through Google or GitHub SSO
- Start without a payment method: no credit card is requested to open an account
- Create a Project Space to scope your traffic, the publisher promising initialization of the secure API proxy tunnel in under a minute
- Deposit your provider credentials in the vault as Vaulted API Keys
- Collect the Corrath developer key issued for the project, recognizable by its aishield_live_ prefix
- Point your application's completion calls at the gateway, which exposes a standardized syntax across providers
- Set daily and monthly budgets per key from the dashboard
- Configure webhooks towards Slack, Discord, email or a custom endpoint, and verify the HMAC-SHA256 signature on your own side
- Invite team members, assign roles, then monitor threats, spend, latency and key health from the dashboard
- Manage or cancel the subscription from the Billing section of the settings
Pros & Cons
Pros
- A permanent free tier with no credit card, capped at 500 requests a month
- A low paid entry point at 9 USD per month
- An unambiguous no-retention commitment on routed payloads, written plainly in the privacy policy
- Three subprocessors named openly, Stripe, Resend and multi-cloud edge nodes, which is uncommon at this price level
- Broad declared regulatory coverage: GDPR, UK GDPR, CCPA/CPRA and India's DPDP Act, with a 14-day withdrawal right recognized for EU and UK customers
- Five model providers behind a single call syntax, with filtering and switchover both announced under 5 ms
- Provider keys isolated in an encrypted vault instead of sitting in application code, and no advertising or retargeting tracker claimed
Cons
- No public API documentation and no SDK: the complete sitemap holds ten URLs and none of them is a docs page
- No postal address, no registration number and no named team; the domain was registered on June 7, 2026 behind a Lithuanian privacy service, with no Wayback capture at all
- Three contradictory encryption statements on the same site: AES-256-CBC in the privacy policy, AES-256 on the contact page, AES-128 Fernet in the terms (§3)
- The cookie policy guarantees zero third-party analytics while the pages initialize a Google Analytics consent mode (gtag) and store a corrath_cookie_consent object
- The FREE_TIER and STARTER plans include neither the security firewall nor the provider fallback, that is, the product's two headline arguments
- Prices are absent from the server-rendered HTML and injected by an animated JavaScript counter, and the SOC 2 Type II badge is backed by no report, no auditor and no trust page
- No customer DPA, no Article 27 representative, no named DPO, and no support channel beyond support@corrath.io and a form, with priority support starting at PRO_TIER
Pricing & Plans
A permanent free plan is offered at 0 USD, presented as "/ forever" and capped at 500 requests per month, with no credit card required to open an account. The lowest paid price point is STARTER at 9.00 USD per month, followed by PRO_TIER at 29 USD per month and BUSINESS at 99 USD per month; ENTERPRISE is quoted on request. A seven-day trial applies to the tiers marked TRIAL. The refund policy allows monthly or annual billing, but only monthly amounts are published. Charges are taken at the start of the cycle, with no credit and no pro-rata if the subscription is cancelled mid-cycle. Subscriptions and prepaid API credits are non-refundable, except in the event of a billing error, a failure to meet the contractual SLA, or a statutory withdrawal right. EU and UK customers have 14 days, forfeited as soon as real requests have been routed. Verified refunds are credited within 5 to 10 business days to the original card. Payments are processed by Stripe, and billing questions go to billing@corrath.io. It should be noted that the displayed amounts come from the page's JavaScript bundle rather than from the server-rendered HTML.
- 1 project space
- 1 vaulted key
- 500 requests per month
- basic proxy gateway
- community support
- security firewall and provider fallback NOT included
- 5 project spaces
- 10 vaulted keys
- 50
- 000 requests per month
- cost forecasting engine
- real-time webhooks
- email support
- security firewall NOT included
- 20 project spaces
- unlimited vaulted keys
- 500
- 000 requests per month
- security firewall included
- provider fallback
- priority email support
- unlimited projects and keys
- unlimited requests
- up to 10 members
- RBAC over shared projects
- dedicated support SLA on Slack and email
- custom volume
- unlimited members
- on-premise SLA
- dedicated operations SLA
- custom model integration
- dedicated 24/7 engineering
- 1 / 1 / 1 / 10 / unlimited. Firewall: No / No / Yes / Yes / Custom Rules. Fallback: No / No / Yes / Yes / Yes (Dedicated). Keys: 1 / 10 / unlimited / unlimited / dedicated
Data, GDPR & hosting
A consolidated view of how Corrath handles your data.
GDPR overview
Corrath claims compliance with four frameworks: the GDPR and UK GDPR, the CCPA/CPRA and other US state laws, India's DPDP Act 2023, and the national requirements of other jurisdictions. A "GDPR Compliant" badge sits on the login page beside "SOC 2 Type II" and "99.9% Uptime". Transfers rely on standard clauses: "For transfers of EU or UK personal data, we utilize European Commission-approved Standard Contractual Clauses (SCCs) to establish equivalent safeguards." Four rights are explicitly opened, namely access and portability, rectification, erasure and withdrawal of consent, exercised from the dashboard's Privacy & Compliance panel rather than by email. Three gaps remain: no Article 27 EU representative, no named DPO (§8 routes every privacy, compliance, legal, GDPR and security request to support@corrath.io) and no customer DPA. Cookies are classed as strictly necessary, so no consent banner appears. The policy is dated June 3, 2026.
Who owns the data?
According to the privacy policy, what Corrath Corp. holds about you is narrow: account identifiers (name, work email, password hash), billing data handled through Stripe, and platform telemetry. Card numbers are never stored on Corrath servers. The prompts and responses you route are excluded outright: "Corrath does not store, log, or analyze dynamic payload inputs, response prompts, passwords, or keys routed through the AI Security Gateway. All proxy processing is ephemeral and handled entirely in-memory." Third-party provider keys placed in the vault remain yours and can be deleted at any time, and the dashboard exposes a structured "Export My Data" download covering every database entry tied to the account.
Reuse rights
The declared purposes are limited to authenticating the account, computing platform statistics and protecting the integrity of the gateway. The telemetry retained covers threat classification, latency distributions and proxy egress load, never prompt content. No model is trained on customer data, which follows mechanically from the payloads not being kept, and the cookie policy claims no advertising, no retargeting and no visitor profiling. Three subprocessors are named: Stripe Inc. for payment, Resend.com for transactional email, and multi-cloud edge nodes for routing. The privacy policy adds that "These vendors operate under strict data processing agreements and are barred from using your details for direct advertising." One caveat on encryption: the privacy policy states AES-256-CBC at rest for vaulted keys, the contact page states AES-256, and the terms (§3) state AES-128 Fernet. The three statements diverge and cannot all be accurate.
Data retention & training
Hosting summary
The privacy policy (§3) says compute instances are spread across international edge regions "including the EU, UK, US, and India", an enumeration the text itself presents as non-exhaustive. No datacenter, no hosting provider and no precise region is named, and the customer is not offered a choice of hosting region. Transfers outside the country of origin are acknowledged and said to be covered by Standard Contractual Clauses for EU and UK data. The routing nodes appear in the subprocessor list only as "multi-cloud edge nodes". DNS resolution observed on September 4, 2026 returned 216.198.79.1, an anycast node attributed to AS16509 Amazon.com Inc. and geolocated in the United States; that is a CDN point of presence, not evidence of where data is stored. In short: a globally distributed and unnamed infrastructure, a contractual transfer mechanism claimed, and no verifiable storage location.
Where Corrath works
Country-level availability.
Not available in
Things to keep in mind
Risks and trade-offs to weigh before adopting Corrath.
- The pricing grid states that all tiers are "fully compatible with simulated sandbox checkouts" and that "Sandbox deployments charge no real payment cards", while the cookie policy describes "simulated, self-hosted analytics dashboards". These are the publisher's own words and they are compatible with a demonstration environment rather than a billed production service: the point should be clarified before any commitment
- Encryption is described three different ways on the same site: AES-256-CBC in the privacy policy (§7), AES-256 on the contact page and AES-128 Fernet in the terms (§3). The three statements cannot all be accurate, and the key vault is the very component they describe
- The cookie policy claims zero integration with third-party advertising, retargeting or commercial analytics, while the pages initialize the Google Analytics consent mode (gtag) and store a corrath_cookie_consent object
- Availability is stated as 99.99% on the home page, in the terms and on the contact page, but the login page badge reads 99.9%. The SOC 2 Type II badge shown next to it is backed by no report, no auditor and no trust page, and the /security route redirects to the login screen instead of a public trust page
- Developer keys carry an aishield_live_ prefix and the browser storage objects are named aishield_access_token and aishield_session, the trace of an earlier product name that the current pages never explain
- The domain was registered on June 7, 2026, the registrant is masked by a Hostinger privacy service, the Internet Archive holds no capture, and no postal address, registration number or social account is published anywhere. Due diligence on the publisher is therefore impossible from public sources
- The "500K+ REQUESTS_PROTECTED" figure shown on the home page is of the same order as the monthly quota of a single PRO_TIER subscription, and the three named testimonials cite companies (NeuroFlux AI, CloudCore, GuardSecure) that cannot be found
Setup & Integrations
Technical difficulty
Moderate, aimed at a technical audience of developers and platform engineers. Sign-up takes seconds through Google or GitHub SSO with no credit card, and the publisher promises to initialize the secure API proxy tunnel in under a minute. The work is redirecting your application's LLM calls to the gateway and depositing provider keys in the vault; a standardized syntax across providers limits the adaptation effort. Two frictions: webhooks must be configured and their HMAC-SHA256 signature verified on your own endpoint, and with no public documentation or SDK the integration can only be assessed after creating an account.
Deployment
Integrations
Behind Corrath
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
How does the firewall inspect prompts?
Are completion prompts stored or logged?
How fast is the failover router?
Can I impose spend caps on developers?
Which model providers are supported?
Is there a free plan?
How long is data kept?
Is there a mobile app?
How do refunds work?
Where is the data hosted?
Should you pick Corrath?
Corrath addresses a real and well-defined need: placing a single controllable layer between an application and the LLM providers it calls. The positioning is clear, the module list is coherent, the entry price is low and the free plan opens without a card. For a team already routing traffic to several providers, combining a firewall, spend caps, failover and audit logs is the right shape of answer.
Two reservations temper that. The first is commercial: the security firewall and the provider fallback, the two arguments the product leads with, are absent from FREE_TIER and STARTER, so the real entry point for the promised value is PRO_TIER at 29 USD per month. The second concerns traceability. Corrath Corp. publishes no postal address, no registration number and no team; there is no API documentation, the domain is three months old, and the Internet Archive holds no capture. The SOC 2 Type II badge on the login page is backed by no report and no trust page, and the three home-page testimonials name companies that cannot be identified.
One point should be settled before any other. The pricing grid states that all tiers work with simulated sandbox checkouts and that sandbox deployments charge no real payment cards, while the cookie policy describes simulated, self-hosted analytics dashboards. Those are the publisher's own words, and they are compatible with a demonstration environment rather than a billed service.
None of this makes Corrath a bad idea; it makes it an unverified one. The sensible path is to test it on the free tier, ask the publisher in writing to clarify the billing status, the encryption standard actually in use and the SOC 2 evidence, and only then consider routing production traffic through it.
- Choosing a selection results in a full page refresh.
- Opens in a new window.