Write rules once; Aperture compiles them into enforcement across the mesh, egress, and AI endpoints — with every decision logged and every change versioned.
Declare intent once — "finance may call the forecasting model, only from managed devices" — and Aperture enforces it on every path. No dialects per layer, no dashboard-only config that escapes review: policy lives in files, gets reviewed in pull requests, and deploys atomically.
The same rule set governs mesh traffic, egress routes, and AI gateway calls. A change applies immediately everywhere — no redeploy, no agent update, no waiting for the next release train — and every evaluation is attributable to a rule, a revision, and a person.
Governance primitives that compose — no separate product per layer.
Rules read like sentences. Reviewers argue about intent, not syntax.
Files under version control, reviewed in pull requests, deployed atomically.
One edit takes effect immediately; reverting is as fast as the edit.
Dry-run a change against last month's traffic before it ships.
Workloads reach exactly the hosts they need — registries, telemetry, APIs — and nothing else.
Pin egress to a compliant region for regulated data paths.
Each vendor sits in its own scope; a leaked token never becomes lateral movement.
Per-team ceilings catch runaway agents before the invoice does.
Every allow, deny, and log names the rule and revision that made it.
Who edited which rule, when, and with whose review — automatic.
Ship decisions to Datadog, Splunk, or any webhook endpoint.
Full decision and policy history as JSON or CSV, on demand.
Write your first three rules in the time it takes to read this page.