AIRLOCK

Your agents, your models. Confidential data leaves only with a human's OK.

Airlock is an OpenAI-compatible gateway you set up in a minute. Connect your own local and frontier models, invite your team, and give every agent its own key.

  • Local model first: names and numbers are de-identified before anything leaves.
  • Confidential requests wait for an approver you invited, verified as a real human with World ID.
  • Your policy and your approvers live on ENS under a name your wallet owns.
A signature, not a transaction: it costs nothing.
AIRLOCK

Your gateways

Where your agents send their requests

Each gateway has its own models, members, API keys and ENS name. Open one, or create a new one.

AIRLOCK

Your gateways / New

Create a gateway

About two minutes. You can change everything later in Manage.

Name
AIRLOCK
AIRLOCK
offline

Overview

—

Waiting for approval

System status

Recent decisions

Playground

Send a request through Airlock

Requests go out as you, under the selected agent's ENS policy. Confidential data waits for an approver.

Agent ·

Ask something, or pick one of the examples.

Approval requests

Audit · hash-chained ledger

—

On-chain policy changes · indexed and pushed by Curvegrid MultiBaas

Every policy edit, link, access change, approver registration and revocation on Airlock's ENS contracts. Pushed to the gateway by webhook, so changes take effect immediately.

Agents & policy · ENSv2 · read live

—

Who runs under which policy

Each person sends as the agent an admin assigned them (Members). Each agent reads its policy from ENS: the gateway default, or a named policy it's linked to.

Read live from ENS

Agents · where each policy comes from

Registered agents link to one shared policy record (ENSv2 aliasing: edit once, all change). An agent that was never registered falls through wildcard resolution to the org default.

Policy

These records are the egress policy. Change one on-chain (Manage › Models, or any ENS app with the owner's wallet) and the next request obeys it.

Who may change what

Enhanced Access Control on the PermissionedResolver, per record key (read from the live contract).

Audit anchor

Name tree

Approvers

Who can release confidential data

Directory

Approvers seen in approvals, the audit log and on-chain registrations, with their live ENS status.

Enroll an approver

The approver verifies with World ID once. Airlock creates their ENS subname under the role and stores only a commitment, never their identity.


        

Look up / revoke

Connect

Point your agents at Airlock

Airlock speaks the OpenAI API. Change the base URL, use your own key, keep your client.

Your API keys

One key per agent or app. Requests made with a key are sent as you, and you can withdraw them. Keys stop working if you leave the gateway.

Models · name, models and gateway default policy

—

Name