burgus.ai

Burgus Security · Enterprise

Secure your AI and what it connects to

Production security for LLM and MCP agent traffic — deployed on-premise or in your private cloud. Your providers, your keys, your audit trail. Active blocking on policy and security rule matches.

On-premise / private cloud GDPR-aligned by design NIS2-ready exports Metadata-first audit Active blocking BYOK

Platform

One layer for models, tools, and audit

Burgus sits in front of your production agent traffic — securing LLM calls and MCP connections on the same audit and alert pipeline, inside infrastructure you operate.

LLM data plane

Route model calls through your securellm hostnames. Threat and policy violations blocked in production — with security alerts, behavioral signals, and audit on every request.

MCP data plane

Tool and data connections through mcpdata hostnames. Access policies, credential handling, and audit on tool ingress and egress.

Control plane

Operator MCP and REST on your deployment — keys, policies, alerts, and compliance exports. No external dashboard dependency.

Capabilities

What you get on your deployment

Security enforcement

Platform rules, content policy, and behavioral matches can block requests that violate your configured policies — with full audit and alert history.

Integration →

Multi-agent visibility

Session graphs, delegation chains, and combined security reports across collaborating agents.

Multi-agent →

Behavioral analysis

Automatic learning from audit traffic — baselines, similarity bursts, and anomaly detection with configurable blocking actions.

Behavioral →

GDPR & NIS2 evidence

Export bundles, alert timelines, and compliance snapshots for assessors and incident response.

Compliance →

Platform API

Automate key management, policy workflows, and audit pulls via operator MCP or REST.

Platform API →

Your infrastructure

Licensed deployment in your VPC, private cloud, or air-gapped environment — data residency under your control.

Deployment →

Governance & compliance

GDPR and NIS2 — designed for accountability

Burgus is built for organisations that must demonstrate control over AI processing — not outsource it to an external SaaS control plane. Processing stays in your environment; exports support your compliance workflows.

GDPR

For AI agent traffic routed through Burgus, you remain in control of where processing happens:

  • Deploy in your environment — platform, audit store, and exports stay on infrastructure you operate
  • Metadata-first audit — timestamps, vendor, status, and correlation by default; not full prompt bodies
  • Purpose limitation — security and audit processing scoped to your tenant configuration
  • Accountability evidence — exportable audit and alert history for DPIAs, records of processing, and supervisory review

NIS2

For essential and important entities securing AI in production:

  • Incident-oriented timelines — alert history with timestamps for detection and response workflows
  • Export bundles — JSON/CSV evidence packs for internal CSIRT and regulatory notification prep
  • Multi-agent traceability — see how agents delegated and what data moved between services
  • On-premise operation — no dependency on external SaaS availability for your security layer

Burgus supports your compliance programme — it does not replace legal counsel or formal conformity assessment. Full compliance detail →

Architecture

How production traffic flows

01 Agents call models and MCP sources using your existing SDKs and credentials
02 Traffic routes through Burgus secure hostnames on your deployment
03 Security rules and behavioral analysis enforce policy — block, alert, and audit
04 Audit metadata and exports feed your ops, SIEM, and compliance workflows

Deployment

From license to production traffic

  1. License Burgus for your organisation
  2. Deploy the platform stack in your VPC or private cloud
  3. Register upstream keys and configure Access policies via operator MCP or REST
  4. Point agent traffic at your Burgus hostnames — same SDKs, same provider contracts

Integration guide →

FAQ

Common questions

How does Burgus support GDPR?

Burgus deploys in your environment, so AI security processing stays under your operational control. Default audit is metadata-only. You configure what is retained and exported — supporting accountability, data minimisation, and records of processing for AI agent traffic you choose to route through the platform.

How does Burgus support NIS2?

Burgus provides alert timelines, audit exports, and combined security reports from the layer that actually secures your production AI stack. Teams use these exports for incident detection, internal escalation, and evidence preparation — alongside your existing NIS2 governance processes.

Does Burgus block traffic when rules match?

Yes. Burgus actively blocks production traffic that matches configured platform rules, content policy, and behavioral enforcement settings. Every block is logged with audit metadata and alert history for review.

Where is data processed?

On infrastructure you operate — on-premise or private cloud. Audit metadata, alerts, and exports remain in your deployment boundary unless you integrate outbound to your own SIEM or GRC tools.

Do we keep our provider keys and contracts?

Yes. BYOK — model and MCP fees stay on your direct invoices with each vendor. Burgus adds the security and audit layer only.

Contact

Enterprise deployment or questions?

Licensed for on-premise and private-cloud deployment. Tell us about your environment — licensing, GDPR/NIS2 requirements, or a proof of concept.

Message sent. We'll be in touch.

Or email us at [email protected]