Miso runs where your AI does.

Miso is deployed within your health system's cloud environment, between the applications using AI and the model providers they access.

Your organization retains control of model credentials, governance policies, and audit records. Miso provides and supports the software that enforces those policies across AI traffic.

01

Architecture

Where Miso sits and what it controls.

Customer-cloud deployment

The Miso gateway and policy store are deployed within your cloud account, so model credentials, governance configuration, and audit records remain under your organization's administrative control.

Compatible with existing applications

Applications connect through an OpenAI-compatible API rather than integrating separately with each model provider. Existing AI applications are pointed at Miso; their code stays as it is.

Designed for enterprise operations

Miso works with your infrastructure, security, and privacy teams through deployment, initial policy configuration, and production rollout, and maintains the software after.

A deliberately small footprint

The core deployment consists of an application container, a PostgreSQL database, and the cloud services you already run: identity, secrets, networking, logging. This keeps the infrastructure a health system has to introduce and operate to a minimum.

Application containerThe gateway: endpoint, policy engine, identifier detection, budgets, audit writer
PostgreSQLPolicy store and append-only audit tables, in your database service
Existing cloud servicesIdentity provider, secrets manager, load balancer, log pipeline
02

Security boundary

What remains inside, what may leave, where credentials and records reside.

Stays in your environment

  • Miso policy and configuration
  • Application identities and credentials
  • Model-provider credentials
  • Approval history and route requests
  • Audit records
  • Governance metadata: registries, obligations, budgets

May leave your environment

Only traffic sent to model providers through routes your organization has authorized.

Identifiers the route names are replaced before the request leaves. The provider that receives it is on your registry with an agreement in force. The record of the request stays inside.

Miso does not create a second, external repository for the governance data required to operate the gateway.

Data in transitTLS between callers and Miso, and between Miso and providers
Data at restYour PostgreSQL and your key management; Miso stores hashes, identifier types and counts, and the record fields. Prompt and response text are off by default.
AccessConsole sign-in through your OIDC identity provider. The console reads through a read-only database role. Audit tables accept inserts only, enforced by a database role.
RetentionSix years by default, set by you
Failure modeIf the gateway is unreachable, callers receive an error and no request is sent
03

Enterprise integration

Miso is a control point inside an architecture you already own. It does not replace your cloud, identity, or security stack.

Existing systemMiso's role
AWS, Azure, or Google CloudRuns within it, as a container and a database in your account
Your identity provider (OIDC)Uses identity from it for console access and approvals
Your log pipeline or SIEMSends operational and security events to it
Anthropic, Azure OpenAI, AWS Bedrock, Google VertexGoverns access to them under your agreements
GRC and contract systemsEnforces the decisions recorded in them; exports the record back
Internal applications and AI vendorsGives them governed model access through one endpoint
04

Production rollout

How Miso and your teams get the first applications governed.

A narrow integration surface

Miso fits into existing cloud and application environments without requiring teams to rebuild their AI applications. Applications connect through an OpenAI-compatible endpoint. Miso works with the health system to establish the surrounding identity, network, provider, and governance configuration.

01

Establish the environment

Deploy Miso within the health system's cloud boundary and connect identity, networking, and logging.

02

Connect approved model providers

Configure the model accounts and the contractual relationships the organization has already approved.

03

Encode initial governance policies

Translate approved use cases, data classes, models, and agreements into enforceable routes. The policy is validated before it is deployed.

04

Bring applications onto Miso

Move selected internal applications or vendors to governed endpoints and expand from there.

Miso

  • Drafts the policy with your privacy and security teams
  • Checks each provider's current published terms against its agreement
  • Onboards the first application and the first vendor with you
  • Reviews the first month's record with you and tunes the routes

Your organization

  • Names a privacy owner and a security owner for approvals
  • Operates the container and the database in your account
  • Decides which applications go first
  • Holds the provider agreements and credentials
05

Operations

Your environment. A supported Miso deployment.

Miso maintains the software, delivers updates, and supports the deployment as your AI environment evolves. Your organization controls the infrastructure it runs on.

UpdatesMiso ships versioned releases. You apply them on your schedule; in a Miso-operated deployment, Miso applies them under the support agreement.
Configuration changesPolicy changes are validated before deployment and recorded with a date and a hash. Route requests and approvals go through the console and land in the policy.
MonitoringA health endpoint, and operational and security events to your log pipeline.
AvailabilityThe gateway is stateless. Run two or more instances behind your load balancer.
RecoveryBackups are your database's backups. A gateway instance is recreated from the release image and the policy.
SupportNamed contacts at Miso through rollout and after, under a support agreement.
AttestationsAsk us for the current status of third-party assessments. Architecture, test results, and the dependency list are available to prospective customers under NDA.

Review Miso with your infrastructure team.

Send us a description of your environment: cloud, identity provider, the providers you hold agreements with. We reply with how Miso would sit in it.

See how Miso would fit into your environment