Gateway previewCustomer-hosted in Microsoft Azure

Govern OpenTelemetry before it reaches the sink.

Cerbi Gateway gives platform teams a centralized OTLP governance boundary inside their Azure tenant. Keep existing SDKs, collectors, and observability platforms while applying signed policy before telemetry continues downstream.

Runs inside your Azure tenant
Uses existing OpenTelemetry SDKs and transports
Keeps current observability destinations in place
Activates only signed, versioned runtime policy
Does not require AI
Does not relay raw logs to Cerbi

One governed path between workloads and every destination.

Gateway is for organizations that already use OpenTelemetry or need a central adoption path across heterogeneous applications. It complements CerbiStream rather than replacing it.

Existing workloads

Applications and services

Existing OpenTelemetry SDKs and supported current or prior clients send OTLP using their normal configuration.

OTLP/HTTPOTLP/gRPCExisting SDKs

Cerbi Gateway

Verify, govern, and forward

The Gateway validates input, applies the active signed policy, stamps governance metadata, and forwards governed telemetry.

Policy verificationField decisionsEvidence metadataControlled forwarding

Your destinations

Keep the observability stack

Existing analytics, dashboards, alerts, retention, and incident workflows remain downstream and customer-controlled.

SplunkDatadogElasticAzure MonitorSentinelOther OTLP

CerbiShield controls policy

Governance profiles are authored, validated, signed, versioned, published, and audited through the tenant-hosted control plane.

CerbiShield receives evidence

Gateway reports bounded governance evidence and operational metadata. Cerbi does not operate a raw-log relay outside the customer tenant.

A clearer path from pilot to platform standard.

A central OTLP boundary

Route selected workloads through one governed OpenTelemetry boundary instead of changing every logging framework at once.

Signed policy activation

CerbiShield publishes a signed Runtime Policy Bundle. Gateway verifies it before activation and protects the last valid policy during reload failure.

Existing destinations remain

Forward governed telemetry to Splunk, Datadog, Elastic, Azure Monitor, Sentinel, or another OpenTelemetry-compatible destination.

Governance evidence

Send policy version, service, environment, decision, scoring, and remediation context to CerbiShield without creating a Cerbi-hosted raw-log pipeline.

Tenant-hosted security

Deploy with private ingress, managed identity, customer-controlled networking, and Azure-native operational controls.

Controlled rollout and recovery

Use immutable images, guarded revision updates, readiness checks, and rollback controls before expanding beyond a pilot workload.

CerbiStream, Gateway, or both.

The correct enforcement point depends on the workload. CerbiShield can manage policy and evidence across both paths.

DecisionCerbiStreamGateway
Policy runsInside the applicationAt the OTLP boundary
Best starting pointSelected high-risk appsExisting OTEL estates
Integration modelRuntime packageCentral endpoint
Network hop before policyNoYes, to tenant Gateway
Existing destinationKeptKept
Can operate togetherYesYes

Prove it with one non-production workload.

The evaluation is designed to preserve the customer's existing telemetry destination and produce evidence before any broader rollout decision.

Request an evaluation
  1. 01Deploy Cerbi Core into a non-production Azure subscription.
  2. 02Point one existing OTLP workload at Cerbi Gateway.
  3. 03Keep the workload's current downstream observability destination.
  4. 04Publish and activate a sample signed governance policy.
  5. 05Compare compliant, violation-bearing, and rejected input behavior.
  6. 06Review policy status and governance evidence in CerbiShield.

Keep OpenTelemetry. Add a governance boundary.

Gateway is currently offered as a controlled preview while final release validation is completed. Preview requests are scoped to tenant-hosted Azure deployments and one initial workload.

Tenant-hosted Controlled rollout Azure deployment

[ cerbi ] · Choose the boundary

Use CerbiStream inside selected applications, Cerbi Gateway at the OpenTelemetry boundary, or both. CerbiShield controls signed policy, rollout, evidence, and audit across either path.

One initial workload/Customer-hosted in Azure/No raw-log relay
Cerbi Gateway | OpenTelemetry Governance in Azure | Cerbi