
Dymium has introduced GhostAI, a security gateway designed to let enterprises use AI models safely with their sensitive data. The product sits between company data and AI systems, applying real-time policies to protect information through masking and synthetic data replacement while recording all activity for auditing. It supports over 800 models and is aimed at regulated industries and organizations protecting intellectual property.
Summaries like this, in your inbox every morning.
Sign up free →What happened
Dymium introduced GhostAI, a security gateway that sits between enterprise data and AI models, agents, and tools. The gateway inspects interactions in real time, applies governance policies across models, context, tools, and data, and records activity—enabling companies to use over 800 public and private models while protecting sensitive information through masking, redaction, or synthetic data replacement.
Why it matters
Enterprise AI systems derive much of their value from access to proprietary data, but sharing that information creates privacy, security, and regulatory risks. GhostAI addresses this conflict by allowing security teams to enforce centralized controls without forcing employees to abandon their preferred AI services, which is especially valuable for regulated industries like financial services and healthcare.
What to watch
GhostAI is available through an early-access program, with general availability planned but no date announced. Pricing will be based on consumption. Wessels noted that customers have already been running on the underlying technology for about six months and that most organizations can configure it in under five minutes.
Dymium Inc., a secure AI infrastructure startup, unveiled GhostAI, a gateway designed to allow enterprises to use AI models safely with their sensitive data. According to founder and Chief Executive Denzil Wessels, the product addresses a fundamental conflict: "The enterprise value is when they bring their sensitive data to the models," he said. "But that was where 100% of the problem lives."
GhostAI functions as an intermediary between enterprise data and the AI models, agents, and tools that seek to access it. The gateway inspects each interaction, applies security and governance policies in real time, and records activity, giving security teams centralized control without requiring employees to stop using their preferred AI services. The product governs across four layers Dymium calls Models, Context, Tools and Data. At the model layer, GhostAI can route requests among more than 800 public and private models. Users can select a model directly or allow the system to choose one according to the task, data sensitivity and governance policies. For example, a request involving confidential information could be sent to private inference running through Amazon Web Services' Bedrock, Google's Vertex AI, or an enterprise data center.
To protect sensitive information, GhostAI identifies data such as names, account numbers, credentials and proprietary material before it reaches a model. Depending on policy, the data can be blocked, masked, redacted or replaced with synthetic information that preserves the relationships needed for analysis. Wessels explained: "We can obfuscate based on the governance rules to replace real data with synthetic data that's still joinable, and we keep all the real data inside the organization." Once a model returns its response, GhostAI retrieves the original values from a protected vault and restores them for authorized users. Dymium's zero-copy architecture also lets AI systems work with live enterprise data without first replicating or staging it in another location.
The context layer includes a shared-memory system that lets conversations and organizational knowledge move and be shared between users, agents and models, with policies restricting memory by company, group, topic and individual user. Sensitive information is stored separately using token and vault protection. The tools layer governs API calls and interactions using Model Context Protocol, the emerging standard for connecting AI systems with external data and software. Each tool call and data operation can be logged for auditing. GhostAI initially supports secure chat, coding assistants and agentic workflows. Dymium is targeting regulated industries such as financial services and healthcare, as well as organizations seeking to protect intellectual property. The product is available through an early-access program, with general availability planned but no date announced. Wessels noted that customers have been running on the underlying technology for about six months and that most organizations can configure it in under five minutes. "We take care of all the security, the complexity, the governance behind the scenes," he said. Pricing will be based on consumption.
Dymium's introduction of GhostAI reflects a growing tension in enterprise AI adoption: companies want to leverage the power of foundation models, which derive significant value from access to proprietary data, but sharing internal information with external or even internal AI systems introduces substantial privacy and regulatory risks. The company's founder, Denzil Wessels, framed this as the core problem—the enterprise value lies in feeding sensitive data to models, but that is where 100% of the problem lives.
GhostAI's architecture attempts to solve this by inserting a governance layer between data and models. Rather than requiring companies to choose between security (air-gapping their data) and capability (using powerful AI services), the gateway lets them do both simultaneously. The product operates across four layers—Models, Context, Tools, and Data—through a single policy engine, which Dymium claims distinguishes it from competitors that combine separate security products. The zero-copy architecture is also notable: AI systems can work with live enterprise data without first replicating or staging it elsewhere, reducing both complexity and data exposure.
The targeting of regulated industries like financial services and healthcare, combined with the emphasis on intellectual property protection, suggests the startup sees its primary market among organizations with the highest compliance and confidentiality burdens. The early-access availability and consumption-based pricing model are typical for infrastructure plays at this stage, allowing the company to refine the product and pricing based on real customer workloads.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion





Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime