Ask VitContactAsk VitGet Started
ENIT

Motus Limen · Enterprise AI gateway

In development

Control enterprise access to AI.
Keep governed requests verifiable.

Limen provides one OpenAI-compatible endpoint for local and external models. Before each model call, it identifies the requester, applies company policy and selects an approved route. Motus records the decision and the provider outcome.

The route exists. Passage depends on the rule at the gate.

Leonardo da Vinci, Codex Atlanticus, late 15th century · plate

What happens before an AI model is called.

Limen turns access policy into an executable Motus graph. The gateway evaluates the request before the provider call, then either blocks it, flags it for review or routes it to the approved local or external model.

Requesters

People
Applications
Agents

Motus Limen

01Verify principal
02Classify request
03Select approved model
04Apply policy
05Allow · deny · review
06Record decision

Approved destinations

Local models
Private providers
External providers

Identity is supplied by the organisation's OIDC/JWT system or LiteLLM virtual keys. The prompt content does not enter the decision trace; Limen records its hash.

Administrators decide who can use what.

Policies and gateway configuration define which principals may use which models, how request classes are routed, when access is denied or held for review, and which budgets and rate limits apply.

01

Identity

Uses the principal asserted by OIDC/JWT or a LiteLLM virtual key.

02

Policy

Evaluates groups, request class and requested model through a versioned Motus graph.

03

Data

Classifies request metadata and records a prompt hash, not the prompt text.

04

Routing

Selects the approved logical model, provider and local or external destination.

05

Review

Stops a request marked for review before a provider is called and queues it — there is no automatic release.

06

Costs

Uses LiteLLM keys, budgets and rate limits as the enforcement layer.

Control access.
Record governed use.

Limen is the policy decision point inside the LiteLLM enforcement layer. The policy is versioned by its Motus graph fingerprint, and the decision trace is created before the provider call rather than reconstructed later from gateway logs.

Conventional gateway

Records that a request was routed.

Motus Limen

Records the inputs read, policy clause, selected route and observed provider effect.

01the asserted principal, tenant, groups and issuer
02the policy graph fingerprint
03the prompt hash and request metadata — not the prompt text
04the resulting data classification
05the selected model, provider and locality
06the allow, deny or review decision and its policy clause
07the provider outcome and response identifier
08the declared link between the decision run and effect run

Adoption

Change the endpoint. Keep the applications.

Existing OpenAI-compatible clients can point to Limen instead of a provider, gaining a governed route without rewriting their AI integration.

Direct provider access

https://api.provider.com/v1

Governed through Limen

https://limen.company.ai/v1

Scope

What Limen does — and what it does not.

Limen controls and records the AI interactions routed through it. It supports governance and compliance processes, but it does not replace organisational policies, risk assessment or legal responsibility.

Beyond Limen

Limen cannot record AI tools that bypass it. Evidence is verified with the published Motus validator and, for the anchors, with OpenTimestamps' own tooling — not ours, so whoever verifies does not have to trust Limen or Vitruvyan. The current pre-MVP operates in local assurance mode: independent execution continuity is a declared gap until a future external witness lands.

What Limen does not do

Limen governs the API calls that pass through it. A browser opening a consumer AI site on a personal account does not pass through it, and no API gateway can see that traffic — closing that door takes three separate layers.

The network

Closing the wrong door is the network's job: corporate proxy or DNS blocks consumer AI domains, browser policy on managed devices enforces site lists, and DLP/CASB stops a classified upload where it is deployed.

Limen

Opening the right one is Limen's job: the company's own chat, routed through Limen, is the sanctioned alternative — same experience, evidence on every answer.

Rules and people

Written policy, training, and a real alternative close the rest. Whoever bypasses a governed path does so against a clear rule, not for lack of one.

Limen is the governed access point; blocking consumer sites is the network's job; together they close the case of the document uploaded to a personal ChatGPT.

One controlled access point
for enterprise AI.

Give people, applications and agents access to approved AI without losing control of models, data, costs or evidence.