AI Mesh Firewall
A production AI security gateway that checks every prompt before it reaches a model, and every response before it reaches a user.
Overview
Companies that plug large language models into their products need the same protections everywhere: verify who is calling, keep personal data out of prompts, stop prompt injection and check what the model sends back. The AI Mesh Firewall enforces all of that in one gateway, so individual apps do not have to.
I architected it and own it end to end at CyberUltron, across backend, frontend, DevOps, cloud deployment and scaling.
How a request flows
Every call passes five checks in order. A request that fails one never reaches the next, so an injected prompt is stopped before the model ever sees it.
Auth
The caller is verified with SHA-256 based authentication before anything else runs.
PII
Personal data in the prompt is detected before it can leave for the model.
Injection
Prompt-injection attempts are caught and blocked at the gateway.
LLM
Only requests that passed every check are forwarded to the model.
Output
The response is checked again on the way back: post-LLM security, before a user sees it.
Built for scale
The gateway fronts more than 500 endpoints and scales with async concurrency from 100 to over 100,000 requests per second.
Because the checks live in one place, a new rule reaches every endpoint at once instead of being rebuilt app by app. In production it cut unsafe LLM behavior by 99%.
What I own
I am its sole owner, so every layer is mine:
- The gateway architecture and the backend services behind it
- The web frontend
- DevOps, cloud deployment and scaling from 100 to 100k+ RPS
- Centralized pre- and post-LLM security: authentication, PII detection and prompt-injection mitigation
Related work at CyberUltron
Alongside the gateway I built core features of AIGuardX, an endpoint AI governance product that stops sensitive data leaking through widely used enterprise AI tools, now running on 1,000+ enterprise endpoints. On the application security platform I added CBOM scanning coverage and AI-powered vulnerability remediation that cut manual triage time by more than 60%.
This page covers what is public. Internal design details stay with the company.