Nothing leaves uninspected.
The trusted LAN is shrinking, and the internet is as hostile as it ever was. Your users and workloads cross that line all day. Polymux™ is a self-hosted, fail-closed security gateway for the traffic they make: one junction where every stream is authenticated, inspected, tokenized, weighed against policy and budget, and recorded. Nothing crosses it uninspected — not because inspection is thorough, but because a stream that fails inspection has nowhere to go.
Under active construction: built and test-covered end to end, not yet proven under production traffic. That gap is what early access is for.
What happens to your data the second it leaves? Most organizations are guessing.
The perimeter moved and nobody redrew it.
Your people paste into other companies' text boxes. Your services, jobs, and agents open connections on their own schedule. The firewall still guards a boundary most of that traffic simply walks through.
Valid isn't authorized.
A request can pass authentication, schema validation, and every scanner you own — and still carry something, or reach something, that nobody signed off on.
There's no signature for it.
You can't pattern-match a call that's only wrong because of who asked, what it carries, and where it's going. That decision has to be deterministic, and it has to be made in-path.
One narrow waist. Every stream crosses it.
Outbound security is usually broken by breadth: a dozen products, each seeing a slice, none of them the last word. This does one thing. The internet is built as an hourglass — countless applications above, countless networks below, one narrow waist between — and Polymux gives your outbound traffic the same deliberate architecture: your users, apps, and agents on one side, the services they call on the other, a single governed junction between them. No ambiguous states: a stream is inspected and forwarded, or stopped and recorded. There is no third outcome.
Streams stay individually isolated as they multiplex through: each authenticated, inspected, and budgeted on its own terms. When an enforcement check fails — or even errors — that stream stops at the waist. Traffic halts rather than leaks. The deliberate exceptions are availability plumbing, not policy, and each is documented as an architecture decision instead of left as an accident.
This sits behind your edge, not instead of it. A firewall and an edge router decide whether a connection may be made — address, port, destination — and the deep-inspecting ones match signatures and categories on what passes. None of them carry meaning across the boundary: recognize that a value is yours, substitute it before it leaves, and put it back on the way home. That's the gap this fills, and it's why the junction belongs inside the boundary rather than at it.
The two planes are built to fail differently, and on purpose. The data plane fails closed: a check that fails, or errors, ends that stream. The control plane degrades visibly — when its own guard rails trip it boots fenced and stays reachable, reporting unready rather than serving, so an operator can reach the instrument that clears the fault instead of being locked out by it.
Any enforcement stage can stop a stream. When one does, nothing forwards and nothing returns unchecked — that stream ends at the waist. The others flow on.
What's already standing at the junction.
Everything below is implemented and exercised by the automated test suite — unit, end-to-end, and failure-path coverage against mock providers and lab clusters. None of it has carried production traffic yet. We say so on each card.
Meaning travels. Your topology stays home.
- Deterministic tokenization — hostnames, IPs, credentials, and PII become stable tokens before egress, rehydrated on the way back. Redaction collapses everything to one blank, destroying the relationships a reader still needs — which host appeared in both files, which environment a name belongs to. Tokens keep them.
- Detector registry — built-in PII / PCI / PHI and secret detectors, plus custom patterns defined in policy.
- Malware scanning — inline YARA-X inspection of payloads, bounded and fail-closed.
- Egress control — per-team destination allowlists plus threat-intel reputation: critical-severity hits block, lower severities are flagged for review.
Permitted, denied, or held for a human.
- Identity-scoped policy — OIDC SSO, RBAC, API keys, and workload identity via mTLS or source network. A stream resolves to a team before anything else is decided about it.
- Tool-call governance — allow, deny, or require approval per tool, with argument schema validation — enforced on streaming responses too.
- Policy as proposal — changes are reviewed, cryptographically signed, and rolled out canary-first. Automation assists; humans decide.
- Shadow mode — run any gate as a dry run first: it records what it would have done, without acting.
Verdicts are attributable, not silent.
- Tamper-evident audit — a hash-chained record of enforcement decisions, with an operator verify command.
- Budget governance — per-team spend limits with soft alerts and hard caps, metered in exact integer arithmetic.
- Detection evidence — an optional encrypted store of what the request-side detectors actually saw, and an operator digest over it, so tuning starts from records rather than recollection.
- BYO observability — Prometheus metrics, syslog in CEF / LEEF, OTLP. Your SIEM, your dashboards — nothing phones home.
An agent's authority should be checked somewhere the agent can't reach.
Under the AI features is the same inspection-and-enforcement engine, and AI is where it earns its keep first — because an agent breaks the assumptions the rest of your stack still makes. It chooses what to send. It acts on whatever enters its context. It does both faster than anyone reviews.
So be exact about what a gateway buys you here. It cannot tell you which tool call is a mistake — that judgement needs intent, and we don't claim a detector for intent. What it does is move the decision off the agent: onto a policy the agent can't edit, at a point it can't route around, with a record of what was decided and why. You still have to write the policy. It just stops being advisory, and it stops living inside the thing that might be compromised.
Everything an agent reads steers it.
Models act on whatever enters their context. A poisoned document doesn't look like an exploit; it looks like your agent working.
Tool calls are actions, not text.
A tool call is a change to a real system, and by default the code that decides whether to run it is the code being steered. Allow, deny, or hold for a human — per tool, arguments validated, including mid-stream where they arrive in fragments.
Which models, and how much.
Per-team model allowlists and spend limits, metered in exact integer arithmetic: soft alerts first, hard caps behind them.
This is a run on the same enforcement path the automated suite drives — a 403 on the secret, a 200 with the infrastructure tokenized and rehydrated. Token identifiers are minted fresh each run, so the ones shown are representative, not fixed; what holds every time is their shape. The kind stays legible while the rest is random, so count, ordering, and relationships can't be derived from the token stream — and it's chunked and free of look-alike characters (no l-versus-1, no o-versus-0), so an operator can still read one off an audit line and drop it into a search box. The provider never sees the real names; your team gets them back rehydrated.
There is a real cost here, and it is worth naming rather than hiding: the model loses your topology. It cannot infer which environment a host belongs to, how your subnets group, or what your naming scheme implies. That loss is the point. Those relationships are the map an attacker builds first, and a model that cannot see them cannot leak them — to a provider, to a log, or to whoever reads either one later. What survives is everything that is not about your topology: the error in the traceback, the type mismatch in the config, the logic in the code.
Pre-release is a claim about traffic, not about rigor.
By construction is the whole posture, and it means something specific: the unsafe option is removed, not defaulted off. When the weak token format was replaced, the switch that selected it was deleted rather than flipped. A service started with no environment declared refuses to boot rather than assuming the permissive one. The control plane cannot clear a safety fence that it is itself subject to. None of those are checks someone has to remember to run; there is no longer a way to express the wrong thing.
The same instinct governs what we write down. A security product asks you to believe a lot of sentences, so ours are bound by a rule we enforce on ourselves: a claimed guarantee has to be enforced or cited. Where a claim's shape can be checked mechanically, that rule is a build gate — a grant-style claim that doesn't name the line enforcing it fails the build. Where it can't, it's a review duty, and we track what that leaves undrained rather than rounding it up.
More than a hundred architecture decisions are recorded with the reasoning and the alternatives that lost. Our readiness file is generated, carries measurements with named sources, and has no status column — because a status column is where a document starts asserting instead of counting. And we run our own audits asking the only question that matters here: what in this repository reads as implemented but isn't? The findings go in the repository, resolved or not.
What we don't publish is the roadmap. Specifics land when they ship — a roadmap is a to-do list for a competitor, and ours stays in the lab.
If traffic leaves your network for systems you don't control, we should talk.
Polymux is pre-release: built, test-covered, and not yet proven under production traffic. The first deployments will be partnerships, not downloads — shaped with a few teams who take outbound traffic, and the authority they've handed their software, as seriously as we do. If your users and workloads are reaching outside infrastructure that matters, we'd like to show you where it stands — including the rough edges.