/AI-TOOLS · STEP ZERO · UPDATED SEPTEMBER 2026
Your AI tools have nothing between them and the model. Change that in one restart.
Gate AI sits between your agent and the model. On the way through it screens every request for prompt injection, removes the tokens the model has already seen (their number: cut your AI spend 20%), and keeps a record nobody can edit afterwards. Your Claude, ChatGPT or Codex login stays as it is. Free plan, no card.
Some links below are affiliate links: if you buy through them we may earn a commission at no extra cost to you. It funds the testing budget and never changes a verdict — affiliate policy.
Start free →Run your numbers firstRead the review
WORKS WITH CLAUDE CODE · CODEX · OPENCODE · CLAUDE DESKTOP · CHATGPT · GEMINI · ANY OPENAI- OR ANTHROPIC-COMPATIBLE SDK · PRICES AND CLAIMS CHECKED 2026-09
Between your agent and the model
It is not a new tool. It is a change of address for the tools you already have: instead of talking straight to Anthropic, OpenAI or Google, they talk to Gate, and Gate talks to the provider. Same code, same provider key, same response shape.
01 · Your tool
Claude Code, ChatGPT, an agent
Sends the whole conversation, the files it read, the pages it fetched.
02 · Gate AI
Screened · compressed · recorded
Injection caught, repeats removed, personal data redacted, entry hashed and chained.
03 · The model
Anthropic, OpenAI, Google, and more
Gets the same content with fewer tokens. Its reply comes back through the same gate.
Four things that happen on the way through
Screened
95.4% of attacks caught
Every request is checked for prompt injection before the model sees it, including instructions hidden in web pages, documents and tool output. Verdict: allowed, flagged or blocked.
Gate's published figure · 2026-09
Compressed
Cut your AI spend 20%
Files the model already read become pointers, tool schemas are minified, terminal noise and duplicate log lines are dropped, overlapping reads become diffs. Same content, fewer tokens.
typical on agent requests · 2026-09
Redacted
PII · PHI · credentials
E-mail addresses, credentials and other personal data are stripped from responses before they reach the next tool or a log. The summary still arrives; the addresses don't.
Pro plan · 2026-09
Recorded
Hash-chained log
Every call is fingerprinted, chained to the previous entry and anchored to Constellation Digital Evidence. Change one line afterwards and the chain breaks visibly. Hashes only, never content.
on the free plan · 2026-09
All figures are Gate's own published numbers, checked September 2026. Its technical report (arXiv:2606.02959) puts the injection defence at 97.4% F1 across 16 public benchmarks and 12,111 samples. Self-published, so a strong claim rather than an independent ranking; our own field test is running below.
Who this is for
Savings first
You run Claude Code, Codex, Cursor or an agent
Your agent resends the whole conversation every turn and re-reads the file it just edited. That is the spend Gate's compression removes, and the workload where its numbers were measured. The free plan alone is worth about a fifth of your API bill.
Screening first
Your AI reads the web, your mail or your documents
The moment a tool reads things written by strangers, it can read instructions written by strangers. Careful prompting does not close that gap. Something between the tool and the model can. If you connected Claude to a scheduler, CRM or inbox this year, this is you.
The record first
You do this for clients, or for a team
Clients are starting to ask what the AI did with their material. A hash-chained record answers it; a screenshot does not. For a team, one gateway shows every seat's requests in one place, with spend caps per key so a loop cannot run until the card declines.
If your AI use is a chat window, your own words and nothing sensitive, the savings will be small and you can wait. Come back the day you connect your first tool to an agent, because that is the day the risk changes.
Run your numbers
Gate's published rates applied to your own metered spend. Two honest caveats are built in: flat subscriptions count as zero, because your bill does not drop on them, and only the agent share of your spend is counted, because a chat window barely benefits.
Saved per month
$24
Saved per year
$288
Pro would cost
$20 / mo
At this spend, Pro pays for itself on the saving alone: about $24 saved against $20 for one seat. Blocking, redaction and spend caps come on top.
Start free, no card →Read the full reviewAffiliate link. Free plan: 20,000 recorded requests a month.
Get the fifteen-minute setup checklist and our field-test numbers
One e-mail with the checklist now; the token numbers from our own Claude Code sessions as they land, starting 30 September.
One email with the goods, then the weekly letter. Unsubscribe anytime.
What it costs
Checked September 2026 on constellationgate.ai/pricing. These are Gate's fees; the models are billed separately, either through Gate's keys or through your own provider account.
Free
$0
20,000 / month · 30-day logs · 90-day metrics
- +One gateway for every model (OpenAI, Anthropic, Gemini, Bedrock, Vertex and more)
- +Request-level logs: cost, tokens, latency
- +Basic compression on requests
- +Immutable audit trail, fingerprinted to Constellation Digital Evidence
- +Gate Connect desktop app
RECORDS INJECTION ATTEMPTS · DOES NOT BLOCK
Pro
$20 per user / month
200,000 / month · 90-day logs · 180-day metrics
- +Everything in Free
- +Prompt-injection scanning: block or flag before tokens reach the model
- +PII, PHI and credential redaction before the response returns
- +Spend, token and rate limits per organisation, project or key
- +Advanced compression: 20%+ saved per message
BLOCKS INJECTION · REDACTS · CAPS SPEND
Enterprise
Custom
Custom · Custom
- +Everything in Pro
- +Private cloud or VPC hosting, data isolation and export
- +Custom security policies and retention
- +Dedicated onboarding, security review, DPA, invoicing
BLOCKS INJECTION · REDACTS · CAPS SPEND
Our meter
Everything above is what Gate publishes. This is what we measure: our own Claude Code sessions, behind Gate, week by week, unedited. Numbers appear here first and in the letter the same day.
Week 0 · from 16 Sep 2026Our Claude Code sessions go behind Gate on 16 September. The first week's numbers publish here on 30 September, whatever they say.
Your first fifteen minutes
Minute 0 to 3. Create the free account, no card, and install Gate Connect. Start here →
Minute 3 to 5. Connect exactly one tool: the one you used most yesterday. Claude Code and Codex connect through their own config; Claude Desktop, ChatGPT and Gemini through the local proxy. Restart it when asked.
Minute 5 to 13. Do your normal work. Do not test it; use it. One real task you would have done anyway.
Minute 13 to 15. Open the Gate dashboard, find the Messages page, read two numbers: requests recorded and tokens saved. Write both on a sticky note with today's date. Stop.
Output: one sticky note with a baseline. A week later the same two numbers tell you whether Free is enough or Pro is due. This is the same recipe as in the review, and the method behind it is in how to actually use the tools you pay for.
The trade-offs, then the verdict
What works
- +One change of address gives every tool you already run screening, compression and a record
- +Free plan with no card: 20,000 recorded requests a month, compression and the audit trail included
- +Works with subscription logins through Gate Connect, not only with API keys
- +Single-digit over-block rates on the benchmarks built to trip filters up (2.7% and 1.4%, vendor-published)
What broke
- −Your prompts pass through a third party; Gate says it does not train on them, and the ledger stores hashes only
- −A proxy is a dependency: the docs do not describe behaviour when the gateway is unreachable (we are testing it)
- −Benchmarks are the vendor's own report; the product launched in July 2026 and the track record is short
- −The free plan watches; blocking, redaction and spend caps are $20 per user
Rolling this out to a team?
You did not roll AI out to your team; your team rolled it out to themselves. Tell us the seat count and the tools in use and we send a written rollout note: which seats first, what to write down on day one, what to show the client on day thirty. Twenty minutes on a call if you want them. No service line, no retainer.
Questions we actually get
Is it safe to route my prompts through a third party?→
It is a trade to make with your eyes open. Your prompts and responses pass through Gate's infrastructure, which Gate says it does not train on; the audit ledger stores only cryptographic fingerprints, never content. In return you get screening, redaction and a record you can hand to a client. If your contracts restrict processors, read Gate's data-processing terms first or ask about the Enterprise private-cloud option.
What is Gate AI?→
A security, savings and audit gateway for AI, built by Constellation Network and launched publicly in July 2026. It is a proxy: your tool sends its request to Gate instead of straight to Anthropic, OpenAI or Google. Gate screens and compresses it, forwards it, screens the response and hands it back. The tool behaves the same; you get a dashboard, a smaller token bill, prompt-injection defence and a verifiable record of every call.
Does it work with my Claude or ChatGPT subscription, or only with API keys?→
Both. The Gate Connect desktop app routes Claude Code through its custom-header setting with your sign-in untouched, writes the base URL into Codex's config, adds itself as a provider in opencode, and runs a local proxy for Claude Desktop, ChatGPT, Gemini and other apps. Developers point any OpenAI- or Anthropic-compatible SDK at Gate's gateway with a Gate key, paying per token through Gate or forwarding to their own provider key.
How much does it save?→
Gate's published typical figure is 20% fewer tokens on agent requests; its one case study, Rocket Resume, is 23% on roughly $40,000 a month. The savings are lossless: repeated files become pointers, tool schemas are minified, terminal noise and duplicate log lines are stripped, editor scaffolding is trimmed, overlapping reads become diffs. A chat window barely changes; coding agents and long sessions change most. The calculator on this page applies those rates to your own spend.
What does the free plan actually do about prompt injection?→
It records. The free plan logs every request, compresses it and keeps the audit trail, and it shows you prompt-injection attempts. Blocking and flagging before tokens reach the model, redaction of personal data and credentials, and spend caps are Pro features at $20 per user per month (checked September 2026). Our rule: free until client data or an acting agent goes through, then Pro.
How good is the injection defence?→
Gate's technical report (arXiv:2606.02959, June 2026) puts it at 97.4% F1 across 16 public benchmarks and 12,111 samples with a pooled false-positive budget of at most 1%, and at 96.6% mean F1 against Lakera Guard's 83.7% at a matched false-positive rate. Over-block rates on the benchmarks built to trip filters up are 2.7% and 1.4%. The numbers are self-published; treat them as a strong claim, not an independent ranking.
What does it cost a team?→
Free is free at any headcount up to 20,000 recorded requests a month. Pro is $20 per user per month, so ten people is $200 a month for blocking, redaction, spend caps per key and 200,000 requests. Enterprise is custom, with private cloud and procurement support. Model usage is billed separately, through Gate's keys or your own provider accounts.
The numbers, as they land
Our own token counts behind Gate every week from 30 September, the fifteen-minute checklist now, and one tested tool a week. In the letter.
One email with the goods, then the weekly letter. Unsubscribe anytime.