Dike – Compliance framework for teams shipping LLMs

4 min read Original article ↗

✓ generation · gpt-4o · sealed a3f1…

✓ retrieval · 5 docs · sealed 91bc…

✓ human_review · approved · sealed d04e…

✓ redaction · pii · sealed 5e9f…

✓ incident · reported · sealed 7c2a…

✓ export · evidence · sealed b60d…

for teams who ship products

Everything the auditor will ask for. Nothing your team has to build.

Dike is a compliance gateway for AI products in the EU. Route your LLM traffic through our proxy and get audit-grade logging, human-oversight records and incident reporting, with a single base-URL change.

maximum fine, whichever is higher, of global turnover

transparency obligations for AI-generated content apply

high-risk AI system obligations apply (Annex III)

minimum log retention required by Articles 19 & 26

Compliance isn't optional, but building it yourself means months of engineering that ships zero product. That's the part we take off your plate.

Your OpenAI API calls route through the Dike gateway on their way to any OpenAI-compatible provider. PII is redacted, malicious calls are blocked, and every request becomes an audit record with full traces.

Application

POST /v1/chat/completions

OpenAI SDK — unchanged

Dike gateway

🛡️ PII redaction — names, card numbers, IDs stripped in-flight

⛔ Malicious calls blocked — prompt injection stops here

👤 Human oversight — flagged responses routed for approval (Art. 14)

🏷️ AI content marking — output labeled as AI-generated (Art. 50)

OpenAI-compatible provider

OpenAI · Azure · Ollama · vLLM

Receives clean, compliant traffic.

Dike Admin

Browse traces, audit logs, incidents & exports

🗄️ Audit log · Traces — every call recorded, allowed or blocked

Regulators don't care about your compliance roadmap. They care about proof. Dike captures every prompt, retrieval, and override as you run — so the audit trail builds itself.

⛓️

Article 12, on autopilot

Every prompt, retrieval and completion becomes a sealed, hash-chained audit record. Tamper-evident by construction: auditors can cryptographically verify that nothing was altered or deleted.

📚

Built for RAG & chatbots

We record which reference documents your model actually used to answer: the exact evidence Article 12(2) asks for, not just a chat transcript.

👤

Human oversight, provable

Approvals, edits and overrides are first-class events. When the regulator asks how humans supervise your AI (Article 14), you export the answer instead of writing it.

⏱️

Incidents with a deadline

Serious incidents start a 15-day reporting clock (Article 73). Dike opens the case, tracks the clock and drafts the report to your market surveillance authority.

🇪🇺

GDPR is not an afterthought

PII is redacted at the gateway, before anything is written to storage. Storage is EU-only, retention starts at the 6-month legal minimum and is fully configurable.

🛡️

Never breaks production

Fail-open by design: if audit storage is unreachable, the gateway still passes your requests through to the model provider. Sub-millisecond overhead, streaming supported.

Dike is a gateway proxy in front of your model provider. Point your existing client at our base URL and every completion, streaming or not, becomes a tamper-evident audit record. No SDK, no code changes.

  • One baseURL change, nothing to install
  • Works with any OpenAI-compatible SDK or framework
  • RAG pipelines and chatbots supported out of the box
  • Requests pass through even if audit storage is down

The gateway is built in Rust and streams responses through as they arrive. Compliance runs in-flight, not in your critical path — going through Dike is indistinguishable from going direct.

Direct to provider

842 ms

Through Dike

842.28 ms +0.28 ms

median latency added by the gateway

p99 overhead, streaming included

sustained throughput per core

requests dropped — fail-open by design

The Dike dashboard: every event sealed, every incident on a clock, every export one click.

Trusted by teams across EU

Track AI traces and calls. Start free, scale as you grow.

Starter

For small & medium companies

10K traces/month

Unlimited users

API access

Enterprise

For large companies

100K traces/month

Unlimited users

API access

SLA guarantee

Priority support

Custom

Unlimited traces, custom needs

Unlimited

Unlimited users

API access

SLA guarantee

Priority support

Custom integration

On-premise option

Point at the gateway

Change one base URL and your LLM traffic routes through our EU proxy. Ship the same day.

We seal & store

Hash-chained events, PII-redacted, retained in the EU for as long as the law requires.

Export evidence

One click: log extracts, technical documentation skeletons and incident case files.

We're onboarding a small group of EU AI teams into the closed beta: free during beta, with white-glove integration help from the founding team.