For Managed Service Providers

Let your clients' AI reach their real systems — safely.

Claude, ChatGPT and Gemini are already in your clients' hands. The Acidni MSP AI Gateway is the control layer that lets those assistants query line-of-business systems — FileMaker, QuickBooks, file servers, PSA/RMM — with per-client isolation, deny-by-default permissions, and an audit trail for every request.

Deny-by-default permissions Per-tenant credential vault Fail-closed audit On-prem data stays on-prem
The problem

AI is useful only when it can reach the systems of record.

Consumer AI assistants can't touch a client's FileMaker jobs, QuickBooks Desktop, or the file server — and wiring them up directly means handing an AI vendor standing credentials to production systems, with no isolation between clients and no record of what was accessed. For an MSP, that's a non-starter.

The gateway

One control layer, every AI client.

  • Connect any MCP-capable AI client over OAuth — no pasted keys.
  • Each client's data is reachable only by that client, enforced at the identity layer.
  • Credentials never leave the client's premises; the AI vendor never sees them.
  • Every call is authorized, masked, and written to an immutable audit trail.
How it works

Three tiers. One outbound connection. Zero inbound exposure.

A cloud control plane brokers identity, permissions and licensing. An on-prem gateway inside the MSP — and one inside each client site — connects outbound only over a reverse tunnel, so nothing needs to be exposed to the internet. Every tool call runs the same pipeline:

1Identitywho is asking
2PermissionsRBAC, deny-by-default
3Entitlementis it licensed
4Dispatchto the on-prem system
5Mask + Auditredact, then record
What you get

Everything an MSP needs to offer AI as a service.

🔌

Connect any AI client

Claude, ChatGPT and Gemini connect as a custom connector over OAuth 2.1 + PKCE. No API keys to paste, rotate, or leak.

🧰

First-class connector tools

Each licensed system shows up as a real tool the AI can call — filemaker.find_jobs, quickbooks.list_customers — with its own schema.

🏢

True multi-tenancy

Every request is bound to one client. One client's AI can never reach another's data — enforced at identity, not by convention.

🛡️

Deny-by-default permissions

Nothing is reachable until you grant it, per role, per connector. Change access from one control panel; it takes effect on the next call.

📜

Full audit trail

Who did what, when, and every refusal — fail-closed, so a call that can't be recorded doesn't run. Review it in-app or ship it to your SIEM.

🏠

On-prem data stays on-prem

The gateway runs inside the network. Credentials live in a per-tenant vault on-site; the cloud plane brokers trust, never the data.

Connectors

Built for the systems your clients actually run.

Reference connectors ship today; line-of-business systems are added per engagement. The heavy, no-off-the-shelf-AI-connector systems are exactly where the gateway earns its keep.

FileMaker Pro / Server QuickBooks Desktop Windows File Server QNAP NAS Synology NAS FedEx tracking UPS tracking Microsoft Entra ID Autotask PSA NinjaRMM / Datto IT Glue + your systems
Security you can defend to a client

The trust model is the product.

This isn't AI convenience bolted onto open credentials. Each property below is enforced and tested — the invariants the whole platform depends on.

  • Identity bound to exactly one tenant — no cross-client access, ever.
  • Per-tenant encrypted credential vault; secrets never reach the cloud.
  • Deny-by-default RBAC on every tool call.
  • Fail-closed audit: no record, no execution.
  • Short-lived, per-call signed service tokens.
  • Offline-verifiable licensing — the gateway proves entitlement without phoning home.
  • Outbound-only connectivity; nothing exposed to the internet.
For MSPs

Add a client by directory ID. License by connector. Resell it.

Onboard in minutes

Add a client by their Microsoft directory ID; their staff sign in with the Entra accounts they already have.

🎛️

One control panel

See every client, gateway and connector in one tree. Grant roles, license connectors, review the audit log — all in one place.

💵

A new recurring line

License per connector and per seat. AI access becomes a managed service you own — not a risk you absorb.

Get started

See it working against real systems.

We'll walk you through connecting Claude or ChatGPT to a live gateway, show the audit trail, and scope the connectors your clients need.