Enterprise AI, under contract.
openapi.ai is Sireto’s AI infrastructure product: versioned, schema-frozen capability contracts enforced by the platform, on an OpenAI-compatible gateway for every model. Inputs and outputs are validated, failures are typed, published versions are immutable, and organisations control which providers process their data. It is developed by Sireto B.V. and available hosted or self-hosted.
Integrate the interface, not the provider.
Every provider integration you write is a liability that drifts. A contract inverts the deal: your organisation owns the interface, whoever serves it must conform, and the platform is the referee.
- 1
Define
A capability is a name and a pair of JSON Schemas for input and output, written by hand or generated from Pydantic or TypeScript models, plus the requirements whoever fulfils it must obey: providers, jurisdictions, retention.
- 2
Publish
A published version is frozen forever. The schema your code integrates against today cannot change under you; a new version breaks nobody on the old one.
- 3
Fulfil
Providers register endpoints that serve the contract, or you fulfil it yourself. The platform dispatches, retries per your policy and fails over.
- 4
Invoke
Synchronous for seconds, asynchronous with signed webhooks for hours, files inline or by reference. Failures are typed with JSON-pointer paths.
The guarantee
- Input validated before anything is dispatched
- Output validated before you ever see it
- Nonconforming results retried across fulfilments, then failed with typed errors
- Published versions immutable, so contracts cannot rot
Infrastructure that scales with you.
From a weekend project to an enterprise deployment, the same gateway sits in front of every model you use.
Unified gateway
Models from multiple providers through one OpenAI-compatible API. One client, no separate SDKs.
Failover and routing
Configurable provider failover, model fallback and key rotation policies, with per-key and per-project budgets.
Data governance
Control which providers process your data, including EU-only and zero-retention requirements, set at organisation level and audited per request.
Analytics and audit
Latency, cost and performance across models in one place, exportable for your own reporting and audit.
Run it on your own infrastructure.
The community edition is the same software as the hosted service with the commercial surfaces switched off. No licence key, no build flag.
- Licence
- AGPL-3.0
- Deployment
- Docker Compose: backend, gateway, console, Postgres, Redis
- Provider keys
- Yours, encrypted at rest, used for every request
- Providers
- OpenAI, Anthropic, Gemini, xAI
- Metering
- None in community; spend bounded by the budgets you set
- Source
- github.com/sireto-ai/openapi-ai
The same principle as NormLogic.
Use AI where probabilistic work is useful, and put contracts, validation and evidence around it where trust is required. NormLogic applies that to regulation. openapi.ai applies it to the interface between an organisation and the models it uses.
Deterministic boundaries
Schema-frozen contracts make the inputs and outputs of AI work explicit and testable.
Governance by design
Which providers see which data, in which jurisdiction, with what retention, is policy, not hope.
Auditable by default
Every request is validated and recorded, so AI-assisted steps can be reviewed after the fact.
Questions about openapi.ai
What is openapi.ai?
openapi.ai is Sireto’s AI infrastructure product: versioned, schema-frozen capability contracts enforced by the platform, on an OpenAI-compatible gateway for every model. Inputs and outputs are validated, failures are typed, published versions are immutable, and organisations control which providers process their data. It is developed by Sireto B.V. and available as a hosted service and as a self-hosted community edition.
Is openapi.ai the same as the OpenAPI Specification?
No. openapi.ai is a product of Sireto B.V. for running AI work under versioned, schema-frozen contracts on an OpenAI-compatible gateway. The OpenAPI Specification is a standard for describing HTTP APIs, maintained by the OpenAPI Initiative. The names are similar; the things are not.
What is a capability contract?
A capability is a name and a pair of JSON Schemas for input and output, plus the requirements whoever fulfils it must obey, such as permitted providers, jurisdictions or data retention. A published version is frozen forever: the platform validates every input before dispatch and every output before it is returned, retries nonconforming results across fulfilments, and fails with typed errors.
Can we self-host openapi.ai?
Yes. The community edition runs on your own infrastructure with Docker Compose and is licensed under AGPL-3.0. It is the same software as the hosted service with the commercial surfaces switched off, and it uses your own provider keys, encrypted at rest.
How does openapi.ai relate to NormLogic?
They are separate products built on the same principle: use AI where it helps, and put contracts, validation and evidence around it where trust is required. NormLogic applies that to regulation; openapi.ai applies it to the interface between an organisation and the models it uses.
Put your AI work under contract.
Start free at openapi.ai, run the community edition yourself, or talk to us about enterprise deployment and how it fits a regulated environment.