Grow your business with AI you can trust.
The guarded AI platform behind your business — hundreds of models through one endpoint, with prompt-injection defense, PII masking, and predictable pricing on every call.
# drop-in — change two lines
base_url="https://api.anoman.io/v1"
model="claude-haiku-4-5"
What Anoman does
Defense-in-depth for every AI call
Guardrails
ML-based prompt-injection detection, PII masking (SEA + global entities, 4 modes), content moderation in EN + Bahasa Indonesia, conversational flows.
Smart Routing
Latency-based provider selection, batch routing with 50% cost savings on non-interactive workloads, opt-in response cache, provider-side prompt cache injection.
Full Observability
Every call traced — prompt, completion, cost, latency, guardrail results, routing mode, cache hit. Self-hosted tracing + analytics backend. Real-time SSE live feed.
Policy Control
Tool call allowlist/denylist via AgentPolicy, per-API-key guardrail overrides, MCP server governance with per-tool RBAC and rate limits.
Cost Transparency
0% markup — pay what providers charge. Weighted token formula surfaced per request. Batch savings and cache savings tracked in dashboard.
SEA Compliance
Jakarta-hosted gateway, UU PDP-ready; each model's processing region is shown on its page. IDR billing. Bahasa Indonesia content moderation. Append-only audit log.
Request pipeline
How every request flows
- 01
Your app calls Anoman
Drop-in replacement for OpenAI or Anthropic SDK. Change base_url and api_key — nothing else.
- 02
Guardrails run first
Injection detection, PII masking, content moderation, and a tool-call policy check before any LLM call.
- 03
Smart routing decides
Cache hit? Return immediately. Batch-eligible? Enqueue with 50% savings. Otherwise route to the best live provider.
- 04
Response + _anoman metadata
Full OpenAI-compatible response plus guardrail results, routing mode, cost, and cache status in _anoman block.
Two ways to use Anoman
Build on the API, or just start chatting
The same guarded engine on a Jakarta-hosted gateway — whether your developers call it over an API or your team chats in a branded app.
Anoman Gateway
One OpenAI-compatible API to hundreds of models — with guardrails, routing, caching, and full observability. For developers and agents.
- Drop-in OpenAI / Anthropic base URL
- Prompt-injection + PII guardrails on every call
- Batch routing + prompt caching to cut cost
Anoman CopilotNew
A branded AI chat app for your whole team — the ChatGPT experience on a Jakarta-hosted, UU-PDP-ready gateway. No code required.
- Chat with hundreds of models — vision + streaming
- Bahasa PII-masking + per-member model & quota controls
- Give non-technical staff safe AI, centrally governed
Pricing
0% markup. Pay what providers charge.
- Up to 2M tokens/day, best-effort
- Full guardrails on every call
- $3 credit + premium-model trial
No subscription — pay per day or per week.
- All models — Budget, Mid, Premium & frontier
- Monthly allowance: ~250M tokens (lean) → ~1M (frontier: Opus, GPT-Astra)
- Batch routing (50% off)
Start free, no credit card. Cancel anytime — drop-in and drop-out with two lines of config. No lock-in.
See full pricing with annual discounts and feature comparison →
Refer & earn
Refer a friend — you both get 20% credit
When someone you invite subscribes, you each get 20% of their payment back as Anoman credit — on their first 3 settled payments. Credit is spendable on Anoman usage and overage. Grab your invite link from your dashboard.
Frequently Asked Questions
Everything you need to know about Anoman AI and LLM gateway security.
What is an LLM gateway?
An LLM gateway is a proxy between your application and the upstream model providers. It routes requests, enforces security policies, meters usage, and gives you observability — through one OpenAI-compatible endpoint. Anoman is the guarded LLM gateway: prompt-injection defense, PII masking, and policy control run on every call.
Is Anoman a drop-in replacement for OpenAI?
Yes. Anoman exposes a fully OpenAI-compatible API — point your base_url at Anoman and nothing else changes. Any SDK that works with OpenAI (Python, TypeScript, Go, and others) works with Anoman out of the box.
How does Anoman stop prompt-injection attacks?
Every request passes an ML classifier trained for prompt-injection detection (configurable threshold) plus heuristic and content-moderation checks, blocking malicious prompts before they ever reach a model. Injection detection is mandatory — only the sensitivity is adjustable, never the check itself.
What latency does the gateway add?
Under ~30ms at p50 and ~80ms at p95, including the full guardrail pipeline (injection detection, PII masking, content moderation, policy). A typical model call takes 500ms–3s, so the overhead is negligible.
Is my data safe from Anoman itself?
Anoman never trains on your data, and guarded models' providers never train on it either; the may-train community lane is opt-in. Cache is partitioned per customer so no one sees another customer's data, API keys are bcrypt-hashed, and PII is detected and masked on every request before it reaches any model.
Where does my data actually go?
Your account data and logs are stored in Jakarta (subprocessors listed on the privacy page), where the gateway runs. A request leaves Indonesia only when the model you choose is processed elsewhere, and each model's detail page shows its processing region. No silent cross-border transfers.
Is there any lock-in?
No. Anoman is OpenAI-compatible — you changed two lines of config to come in, and you can change them back to leave. There's no proprietary SDK to rip out. Start free, cancel anytime.
Why trust a newer, Indonesia-based vendor?
Because trust here is instrumented, not asserted: every response returns a verifiable receipt of exactly what we did (region, guardrail results, routing, cost), we run a public status page and the Founding 50 program, and Anoman is built by security experts with more than 15 years in enterprise cybersecurity.
Do you have SOC 2 or ISO 27001?
Formal certification is planned. In the meantime we handle enterprise security reviews and vendor questionnaires directly, and every call already returns machine-readable evidence of the controls applied — contact us for provider documentation and a Data Processing Agreement.
What's your uptime and SLA?
We target 99.9% monthly on the gateway and publish live status at anoman.io/status. A contractual SLA is available on the Enterprise plan.
Why not just use LiteLLM or build this myself?
You could — and then you'd own building and maintaining guardrails, PII masking, data residency, batch routing, observability, and audit logging yourself, forever. Anoman ships all of them on every call, maintained, behind one OpenAI-compatible endpoint.
Start securing your AI calls today.
Free API key. No credit card required. Jakarta-hosted, UU PDP-ready gateway.