Product description¶
Myra AI Workspace is a secured AI working environment. Myra AI Workspace combines the security and the control of an AI gateway with the tools of an AI platform for daily work, so that every person in an organization can work with AI without sensitive data passing out of the control of the organization.
Below the interface, the product is a multi-tenant reverse proxy that Myra Security operates behind its global Security CDN. The CDN stands in front of it as the trusted edge. The reverse proxy sits between the customer's applications and the programming interfaces of the AI providers, enforces the policies there, manages the credentials, and records every request. Authentication, rate limiting, the response cache, and the tier 1 content inspection run in the same process as the request. The tier 2 detectors run as sidecars inside the perimeter of Myra Security and never at a third party. No additional network hop occurs, and the latency stays consistently low even under high load.
The product is used through two access paths that pass through the same processing and are subject to the same policies:
- ■ web interface for people who work with AI every day
- ■ OpenAI-compatible programming interface for software that calls AI models
21 AI providers are connected behind one common interface, so that changing a provider or adding a second one requires no change to the customer's code.
A gateway is the named installation of a tenant. The gateway sets which providers and models are available, which rules apply to the content, which budget is available, and what Myra AI Workspace logs. This keeps the use of the AI traceable, limitable, and bound to the requirements of the organization.
As a security-as-a-service solution, Myra AI Workspace requires no installation on the customer side when it is operated as a managed service. Myra Security sets up the instance and maintains it. The service runs on the certified EU infrastructure of Myra Security and addresses the following risks:
- ■ Uncontrolled outflow of personal information to providers outside the EU: Personal, financial, or otherwise regulated information is detected and masked inside the EU, or converted into reversible placeholders, before a request leaves the certified infrastructure.
- ■ Prompt injection and jailbreak attempts: A two-tier guardrail chain detects instruction overrides, role takeovers, and injected system messages, and evaluates requests and responses semantically across 14 categories.
- ■ Uncontrolled spending on AI: Hard cost limits apply per access token, per tenant, and per gateway, and are enforced before a call goes out.
- ■ Disclosure of the providers' credentials: The provider keys are stored in a vault encrypted with AES-256 and are never disclosed to the calling application.
- ■ Missing evidence: Every request produces a structured log entry with identity, routing, token count, cost, latency per phase, and the verdict of every guardrail, sealed in the audit log by a chain of checksums.
- ■ Provider lock-in and provider outages: Fallback chains, weighted load distribution, and a circuit breaker keep the traffic running when a provider fails or slows down.
- ■ Data leaving the EU through an unnoticed detour: On a gateway with EU routing enforced, the endpoint actually observed is evaluated after the response, and an endpoint outside the EU is rejected before a single byte reaches the caller.
Functions¶
The following functions are available:
- ■ Unified provider interface: Connects 21 AI providers — among them OpenAI, Anthropic, Google Gemini, Vertex AI, AWS Bedrock, Azure OpenAI, Mistral, Cohere, Cloudflare Workers AI, HuggingFace, and Myra — behind one OpenAI-compatible endpoint. Every model name goes to
/compat/chat/completions, and the gateway derives the provider from the model name itself. - ■ Multi-tenancy: Divides the platform into tenants and gateways. Every gateway is a self-contained policy scope with its own provider keys, its own authentication tokens, its own rate limits, and its own routing rules, separated at the storage layer and addressed through the URL path
/v1/{tenant}/{gateway}/…. - ■ Two-tier guardrails: Enforces eleven types of detectors in two tiers. Tier 1 runs in-process below one millisecond and comprises jailbreak detection with 18 prepared attack phrases, keyword matching, and named pattern sets of regular expressions for card numbers, credentials, and information under HIPAA and GDPR. Tier 2 runs as a separate service in the certified Myra infrastructure and comprises NLP PII detection across more than 50 types of personal information, prompt guard across 14 semantic categories, and reversible PII protection.
- ■ PII protection: Detects personal, financial, and otherwise regulated data inside the EU and masks it or replaces it with reversible placeholders before the request leaves the certified infrastructure, then restores the original values in the response. The model therefore processes no real information and still answers coherently. A tenant blocklist and a personal list per account extend the detection.
- ■ EU data residency: Rejects every path that would leave the EU before the request reaches a provider, evaluates the endpoint actually observed after the response, and records a residency zone (
eu,non_eu,unknown) per request segment as evidence for data localization reporting. - ■ Budgets: Enforces hard cost limits per access token, per tenant, and per gateway, with automatic reset daily at midnight UTC, monthly, or never. An exhausted budget is answered with status
429and a message that names the exhausted level. - ■ Rate limiting: Enforces a sliding-window limit per gateway and per token before a call goes out, and returns the headers
X-RateLimit-Limit,X-RateLimit-Remaining, andRetry-After. - ■ Routing and failover: Evaluates an ordered rule chain that rewrites provider and model, splits traffic by weights, and appends fallback chains. A failed request is retried on a further provider, and the circuit breaker automatically removes a persistently disturbed provider from the routing.
- ■ Key vault (BYOK): Stores the API keys of the providers encrypted with AES-256 and decrypts them only for the associated gateway at request time. The calling application authenticates with its own token and never sees a provider key.
- ■ Response cache: Answers a verbatim repetition from the cache and marks it with the header
X-AIG-Cache: HIT. This lowers cost and latency. - ■ Chat and daily work: Provides a persistent multi-turn conversation with model selection, attachments, read-aloud and dictation through a voice operated in the EU, reusable commands, a tenant-wide prompt library, web search with sources, and a ghost mode that stores nothing and logs nothing.
- ■ Projects and knowledge: Groups conversations under shared instructions, a knowledge base, and a fixed model. Knowledge files, scanned PDF files, and images are evaluated by text recognition, and connected sources such as SharePoint and Confluence are synchronized. The per-document permissions of SharePoint are carried over. A Confluence source stays with the account that created it until a tenant administrator releases the source for the whole organization.
- ■ Agents and automation: Provides reusable assistants made of system prompt, model, tools, and bound knowledge, multi-step workflows in the graphical editor, scheduled tasks with delivery into the chat, and access to an agent from Mattermost, Slack, or Microsoft Teams.
- ■ Code interpreter and generation: Runs Python on an attached file in an isolated environment and returns charts and files, generates and edits images on a model operated in the EU, and creates artifacts that can be exported as an Office or OpenDocument file.
- ■ Governance and audit: Maps regulatory obligations onto the settings through governance templates, lets a second administration approve a change to the prompt library or to an agent, seals every entry of the audit log with a chain of checksums, enforces retention and deletion periods per tenant, project, and account, and marks every response as AI-generated, as the EU Artificial Intelligence Act requires.
- ■ Observability: Records a structured request log with identity, routing, status, cache state, token count, cost, latency per phase, and the verdict of every guardrail, and shows usage and spending by tenant, gateway, provider, model, agent, and account, together with a live monitor and a view of the providers' health. Counters and latency distributions are available at
/metrics. - ■ SIEM integration: Sends one structured event per request to Splunk, Elasticsearch, Vector, or syslog.
- ■ Access management: Signs in without a password through a six-digit one-time code by e-mail or through single sign-on with OIDC and SAML 2.0, takes over accounts and groups through SCIM, restricts access to defined address ranges through an IP allowlist, and assigns rights through the roles
admin,tenant_admin,ki_manager,member,finance,viewer, anddemouser. - ■ Self-registration and billing: Provides the Starter and Pro plans with a monthly or yearly billing period, a monthly message quota, invoices in the application, and cancellation through a public page without signing in.
Limitations¶
The following limitations apply:
- ■ Tier 2 guardrails default to fail open: If the guardrail service of the certified Myra infrastructure is unreachable, the request passes as if the guardrail had not triggered. The setting must be switched off for every tier 2 check as soon as the processing is subject to regulatory requirements.
- ■ The IP allowlist accepts IPv4 ranges only: IPv6 addresses cannot be entered, and the
ip_allowlistfield is maintained exclusively through the administration interface — it does not appear in the web interface. - ■ The IP allowlist is only as strong as the edge in front of it: The check matches the leftmost entry of the
X-Forwarded-Forheader. That entry names the real client only for as long as the Myra CDN replaces a header supplied by the client. The check filters the inference endpoints only. Requests to the administration interface pass it unchecked. - ■ A provider's own web search never counts as EU-clean: A model that runs the search on its own server is blocked before the call only on a gateway with EU routing enforced. On a gateway without an enforced floor, the search axis of such a request is always
non_eu. - ■ The residency zone stays
unknownfor opaque paths: OpenRouter, a cross-region Bedrock profile without evidence for the EU-27, a per-gateway base URL to an endpoint that cannot be identified, and an Azure path without a region are reported as not EU-clean. - ■ The response cache covers non-streamed responses only: A response is stored only with status 200, only if it is not transferred as a stream, and only if
cache_ttlis greater than0. - ■ The
viewerrole cannot make inference requests: The Chat and Playground views stay reachable but refuse the creation of tokens and the sending of messages. - ■ The context-window estimate is approximate: The gateway calculates with about 3.5 characters per token and a fixed amount per attachment, so that a request with many attachments can exceed the context window even when its visible text is short.
- ■ The value of a token is shown once: The plain text appears only in the response to the creation and cannot be restored. A lost token must be deleted and created again.
- ■ Self-registration is a property of the respective installation: If it is switched off, the registration pages are unavailable, and no reference to the registration appears on the sign-in page.
Target groups¶
Myra AI Workspace addresses organizations that use AI across the organization under regulated conditions. The following groups use the product:
- ■ Enterprises and public sector bodies in the EU that use AI across the organization
- ■ Regulated industries with obligations under the GDPR, the EU Artificial Intelligence Act, and BSI requirements
- ■ Departments that use AI in daily work
- ■ Development teams that call AI models from their own applications
- ■ Administrations that govern AI usage, cost, and compliance for several teams or business units
- ■ The security, data protection, and compliance areas that keep the evidence of the processing
On the Myra Security side, sales and onboarding set up the instance, and support maintains it.
Functions of your role¶
The following options are available:
| Function | Limitation |
|---|---|
| Hold conversations with the AI and create projects, agents, workflows, scheduled tasks, and MCP connectors | |
| Manage the prompt library, the governance rules, and the approvals of the tenant | |
| Manage the gateways, their models, routing rules, budgets, and API tokens | |
| Manage the user accounts, groups, and roles of the tenant | You do not assign the Administrator, Tenant Administrator, and Demo User roles. |
| Set up the sign-in through SSO, SAML, and SCIM | |
| Analyse the cost of the tenant and manage the billing | The cost of other tenants and the model prices stay reserved for the Administrator role. |
| Manage the settings of its own tenant | The creation and the permanent deletion of tenants stay reserved for the Administrator role. |
Note
The AI Manager role manages the governance rules, the prompts of the organization, the agents, and the groups and analyses the cost. The AI Manager role does not manage the user accounts, roles, gateways, request logs, and billing. The Finance role analyses the cost per user, manages the billing settings of the tenant, and creates projects. The Finance role creates no own agents, workflows, scheduled tasks, and MCP connectors.
Permissions¶
The catalogue of Myra AI Workspace holds 38 permissions. The Tenant Administrator role has 25 of them.
The following options are available:
| Module | Permission | Description |
|---|---|---|
| Roles | Manage roles within the tenant | Creates your own roles of the tenant and changes their permissions. |
| Agents | Create and manage own agents | Creates and manages your own agents. |
| Agents | Review, approve, and moderate agents | Reviews, approves, and moderates agents. |
| Agents | Curate the tenant agent catalog | Curates the agent catalogue of the tenant. |
| Workflows | Create and run own workflows | Creates and starts your own workflows. |
| Workflows | View all workflow runs in the tenant | Shows all workflow runs of the tenant. |
| Workflows | Enable or disable workflows for the workspace | Switches the workflows for the workspace on or off. |
| Scheduled tasks | Create and manage own scheduled tasks | Creates and manages your own scheduled tasks. |
| Projects | Create projects | Creates projects. |
| Model catalogue | View model prices | Shows the model prices. |
| Connectors | Create and manage own MCP connectors | Creates and manages your own MCP connectors. |
| Connectors | Manage tenant connector-sync and chat-bridge | Manages the connector synchronization and the chat integrations of the tenant. |
| Groups | Manage groups and memberships | Manages groups and their memberships. |
| Governance | Manage governance rules, prompts, and approvals | Manages the governance rules, the prompts, and the approvals. |
| Analytics | View analytics dashboards | Shows the analyses. |
| Analytics | View cost breakdowns | Shows the cost breakdown. |
| Analytics | View per-user cost | Shows the cost per user. |
| Analytics | View request logs and traces | Shows the request logs and the related traces. |
| Users | Manage tenant users | Manages the users of the tenant. |
| SSO | Manage SSO, SAML, and SCIM | Manages SSO, SAML, and SCIM. |
| Workspace | Manage tenant settings | Manages the settings of the tenant. |
| Gateways | Manage gateways and routing | Manages the gateways and their routing. |
| Gateways | Manage gateway API tokens | Manages the API tokens of the gateways. |
| Approvals | Approve agent egress requests | Approves the outbound requests of agents. |
| Billing | Manage billing settings | Manages the billing settings. |
Note
The Tenant Administrator role does not have the permissions of the Platform module or the Manage system (Myra-curated) roles, Manage users across all tenants, View cross-tenant cost, Create tenants, and Purge tenants permissions.
Note
The AI Manager role has 10 permissions of the catalogue, the Finance role 3.