G8KEPR
Why It Runs in Your VPC (and Nothing Leaves)
Part 5 of the thread Building G8KEPR
- G8KEPR runs inside your own VPC, the private slice of the cloud that belongs to you. There's no hosted version it phones home to.
- You deploy it with Helm or Terraform, it sits in-path, and your app doesn't need a rewrite.
- By design, 0 bytes leave your VPC, and there's no per-token charge.
- It works alongside the API gateway you already have instead of replacing it.
When I narrowed G8KEPR down in September 2026, one decision got simpler rather than harder: it's self-hosted, VPC-only. This post is about why.
A few terms first
A VPC, or virtual private cloud, is your own walled-off network inside a cloud provider. Your servers live there, your data lives there, and you decide what gets in and out.
Self-hosted means you run the software on your own infrastructure. Nobody else operates it for you.
In-path means traffic actually flows through it. It isn't watching a copy of your requests off to the side; it's standing in the doorway, so it can stop something instead of just reporting it later.
The reasoning
Think about what an AI security layer has to look at. Your users' prompts. The documents you hand the model. The tools it calls and what they return. The model's answers. Sometimes personal information, sometimes API keys that should never have been in a prompt at all.
That's close to the most sensitive traffic a company has. The usual SaaS move is to ship all of it off to a vendor's cloud to be inspected. For a security product, that's always felt backwards to me. You'd be creating a new place for your sensitive data to live in order to protect your sensitive data.
So G8KEPR goes the other way. "0 bytes leave your VPC" is a design rule, not a setting. The checks run where the data already is.
That rule is also a big part of why detection is regex and classical ML instead of an LLM judge. A hosted AI model grading your traffic would mean sending that traffic out. Local, classical detection doesn't.
How it's deployed
You deploy it yourself, with the tooling most platform teams already use:
| Option | What it is | Good fit when |
|---|---|---|
| Helm | The package manager for Kubernetes | You already run workloads on Kubernetes |
| Terraform | Infrastructure as code: you describe what you want and it builds it | You manage your cloud setup as code |
Either way, it lands in your environment, in the request path, and your app doesn't need to be rewritten to use it. That last part matters. A security tool that needs you to rebuild your application tends to stay on the "someday" list forever.
It doesn't replace your gateway
Plenty of teams already have an API gateway in front of their services, handling routing, authentication and the like. G8KEPR is built to work alongside it, not to make you rip it out.
What it adds is the AI-specific view: the four pillars covering API security, MCP tools, calls to 14 LLM providers, and verification of the model's answers, plus the cross-pillar correlation engine that scores signals showing up together across all four.
$0 per token
A lot of AI tooling is priced by the token, meaning by the amount of text that passes through a model. That's fair for things that run a model. For a security layer it creates an odd incentive, where your protection costs more exactly when traffic spikes, which is often exactly when you're under attack.
G8KEPR has no metered inference. Detection runs locally, so there's no per-token charge for it. Founder pricing starts at $399 a month.
Note
There's a 30-day free trial, extendable to 90, with no credit card. The simplest way to judge whether it fits your setup is to put it in a test environment and send real-looking traffic through it.
The trade
Self-hosting isn't free of cost. You run it, you upgrade it, you own the box it lives on. For some teams a fully managed service is the better answer, and that's a reasonable choice.
G8KEPR is for teams who'd rather keep the data at home and take on a little operational work to do it. That's who I'm building for.
If that sounds like you, g8kepr.com has the details. And if you work in security and want to help shape it, I'm looking for a few design partners.