Open source · Self-hosted · MIT License

Your team is already
building AI apps

Do you know what's running, where it's deployed, and what data it can access? GatekeeperAI gives your team a safe place to build and deploy internal AI tools — and gives security the visibility and control to say yes with confidence.

The problem today

Employees build AI tools on personal accounts, unknown APIs, and unreviewed code. Security has no visibility. One incident away from a breach.

With GatekeeperAI

Every AI app lives on your servers, goes through an automatic risk check, and needs security sign-off before it runs. Innovation stays — chaos doesn't.

Build your app with any AI assistant

ClaudeChatGPTGeminiGrokCopilotCodex

Load GKAPP.md into any AI assistant and it will generate an app that works inside GatekeeperAI out of the box — no auth code, no Dockerfile, no server config. Describe your problem. Get a zip. Submit it.

How it works

Build, check, approve, deploy, log. Your team keeps moving — nothing unsafe gets through.

01

Someone on your team builds an AI app

It doesn't matter if they're an engineer or not. They compress their app into a ZIP file and upload it directly in the browser — no technical setup required.

02

Gatekeeper checks it automatically

Before anyone sees it, the app is automatically scanned for exposed passwords, sensitive data, insecure packages, and AI-specific risks. The report surfaces what automation can catch — so your reviewer spends their time on judgment, not grep.

03

Your security team approves it

The risk report lands in a simple review queue. One click to approve or send back with feedback. Approved apps deploy automatically — rejected ones don't run.

04

The app is live and accessible to your team

Once approved, the app is deployed automatically inside your network — as a Docker container on a single server, or as a Kubernetes Deployment on EKS at enterprise scale. No manual setup, no IT ticket. The owner controls who can access it — by individual email or by SSO group, directly from the dashboard.

05

Every action is logged — and goes where you need it

Every approval, deployment, and security event is recorded with a full audit trail. Forward logs automatically to Splunk, Datadog, AWS CloudWatch, or Grafana Loki.

See it in action

Upload snake.zip, watch it scan and deploy, then play the game.

GatekeeperAI — demo
🐍

Drop snake.zip here, or use our sample

Every role has a view

A simple interface for every role — developer, reviewer, and admin.

Developer view

Submit an app, track scan progress, and see exactly what was flagged.

Approver queue

Review risk reports, apply decisions, and meet SLA deadlines.

Admin & deployment logs

Monitor all deployments and audit every platform event.

Built for teams that want to move fast — safely

Stop choosing between speed and security. GatekeeperAI gives you both.

🔒

Nothing leaves your building

Every app lives on your own servers. No third-party cloud, no data sharing, no vendor access. Your team's work stays inside your walls.

Security gets a real say

Every app goes through a review before it runs. Your security team sees exactly what was built, approves it or sends it back — with a clear paper trail.

Developers don't slow down

Low-risk apps move quickly through the review queue. Developers keep shipping — Gatekeeper raises the floor so reviewers can focus where it counts.

🔍

Automatic risk checks

The moment an app is submitted, Gatekeeper checks it for leaked passwords, exposed customer data, insecure dependencies, and more — automatically.

📋

Full audit history — and it goes where you need it

Every submission, review, and deployment is logged. Forward security events to Splunk, Datadog, AWS CloudWatch, or Grafana Loki automatically — or keep everything on-prem.

📦

No git required

Developers just zip their app folder and upload it in the browser. No SSH keys, no terminal, no configuration — anyone who can build an app can submit one.

🚀

One place for all internal AI apps

Instead of AI tools scattered across personal laptops and random cloud accounts, your team has one secure home for everything they build.

🔄

Update apps without any downtime

Developers can ship a new version of a running app at any time. The new container starts before the old one stops — users never see an outage, and the URL never changes.

🔑

Control exactly who can access each app

Every deployed app is private to its creator by default. Grant access to specific teammates by email, or map your existing SSO groups — any team in your identity provider can be given access in one click.

NEW
🏢

SSO and OIDC — bring your own identity provider

Connect Okta, Azure AD, Google Workspace, Keycloak, or any OIDC-compliant provider. Your existing groups map to Gatekeeper roles automatically. Accounts are provisioned on first login — no separate directory to manage.

🪪

Sign in with a passkey — no password needed

Touch ID, Face ID, and Windows Hello are first-class sign-in methods. Passkeys are phishing-proof and faster than any password. Password and SSO sign-in are available alongside passkeys.

NEW
🤖

Build with any AI — we handle the rest

Use Claude, ChatGPT, Gemini, Grok, or Copilot to generate your app. Load GKAPP.md as context and your AI assistant knows exactly what GatekeeperAI handles — no auth code, no Dockerfiles, no server config. Just describe your problem and submit the zip.

NEW
🏗️

Flexible deployment — Docker or Kubernetes

Run on a single server with Docker Compose for simple on-premises installs. Scale to Kubernetes/EKS with the included Helm chart and Terraform module — HPA, autoscaling workers, NetworkPolicy app isolation, and RDS/ElastiCache managed services.

Built for every role on your team

Three different people. One platform that works for all of them.

👩‍💻

The IC Developer

The problem

Wants to ship AI tools fast without filing IT tickets or waiting weeks for approval.

With GatekeeperAI

Submit a ZIP, get a scan result in seconds. Clean apps deploy automatically — no engineering overhead, no command line.

🛡️

The Security Manager

The problem

Can't see what AI tools are running, what data they touch, or who built them.

With GatekeeperAI

Every app goes through an automatic risk scan before it runs. Full audit trail, approval queue, and SIEM forwarding — without slowing anyone down.

⚙️

The IT Admin

The problem

Tired of being handed random Python scripts and asked to 'just make it run somewhere.'

With GatekeeperAI

Docker Compose deploy on any server, or Kubernetes/EKS for enterprise scale. Included Helm chart and Terraform module, pre-built images, no surprise dependencies. Runs and stays running.

Common questions

Does our team need to know Docker to run this?

Barely. If someone on your team can copy-paste four commands and edit a .env file, you're done. Most setups are complete in under an hour.

What happens if GatekeeperAI goes down? Do our deployed apps go down too?

No. Once an app is deployed it runs in its own container — GatekeeperAI going offline doesn't affect running apps at all.

What data does the scanner send externally?

Only the code in the submitted app is sent to the AI scanner at scan time. Nothing else — no user data, no secrets, no runtime traffic. Scanning happens once at submission, not continuously.

Can developers use this without touching the server?

Yes — that's the point. Developers interact entirely through the browser. No SSH access, no terminal, no infrastructure knowledge required.

Do our employees need to create yet another password?

No — that's the point. GatekeeperAI uses passkeys as the default sign-in method. Employees sign in with the fingerprint sensor or face scan already on their laptop or phone. No password to create, forget, or reuse. Password sign-in is still available as a fallback, and SSO lets you connect your existing identity provider so employees never need a GatekeeperAI account at all.

Can we connect our existing identity provider (Okta, Azure AD, Google Workspace)?

Yes. GatekeeperAI supports any OIDC-compliant provider. Admins configure it once in the admin panel. After that, employees sign in with their existing company credentials — accounts are provisioned on first login automatically. Your IdP groups map directly to Gatekeeper roles (IC, Approver, Admin) and can gate access to individual deployed apps, so you don't have to manage a separate directory.

Can we deploy GatekeeperAI on Kubernetes?

Yes. GatekeeperAI ships a Helm chart and Terraform module for EKS deployment alongside the standard Docker Compose install. The Kubernetes path adds Kaniko-based image builds, per-app Deployments in an isolated namespace, nginx-ingress routing, and autoscaling (HPA for the API, KEDA for Celery workers). Both paths share the same codebase — switch between them with a single DEPLOY_BACKEND environment variable.

Set up in an afternoon

GatekeeperAI runs on any server in your building or private cloud. Pre-built images pull straight from GitHub - no data leaves your network.

terminal — docker compose
$ git clone https://github.com/jacobthomasmichael/GatekeeperAI.git
$ cd GatekeeperAI && cp .env.example .env
$ docker compose -f infra/docker-compose.yml pull
$ docker compose -f infra/docker-compose.yml up -d

→ Open http://your-server:3000 to complete setup

Runs on any Linux server, Mac, or Windows machine with Docker installed. Full setup guide →