Skip to main content
Beyond the Guard Gateway API, BeyondGuard can inspect traffic inline as a proxy using ICAP (Internet Content Adaptation Protocol). In this mode, client traffic flows through a proxy that hands each request to BeyondGuard for inspection before allowed traffic is forwarded to its destination.

Core services

Backing services for this module are PostgreSQL 15+ (primary datastore) and Kafka 3.x (event bus for the audit-log pipeline consumed by bg-log-writer). Each can be containerized or an existing external instance.

Proxy network position

Because the proxy is what ultimately relays approved traffic to external destinations, its outbound reachability is the critical networking decision for this module. There are two supported positions:
Position bg-proxy-server on a network segment with outbound internet access (directly or via NAT / egress gateway). Outbound access is required to the destinations being inspected — external web endpoints and/or LLM provider endpoints — typically on TCP 80 and 443. No additional proxy configuration is required.

Internal connectivity

  • All guard microservices and the Service Engine are internal-only and require no outbound internet access.
  • bg-icap-server must be reachable from bg-proxy-server on the ICAP port (1344) and HTTP port (8080).
  • bg-management-panel-be requires connectivity to PostgreSQL and Kafka.
  • During installation, outbound access to the image repository (and Helm repository for Helm deployments) is required to pull artifacts — mirrorable to an internal registry in restricted environments.
bg-proxy-server is the only traffic-facing service and should run in HA so that interception is not a single point of failure.

Mail interception

In addition to HTTP/proxy traffic, BeyondGuard can monitor email via IMAP, Microsoft Exchange, and POP connectors, bringing mail-borne content under the same policy engine as the rest of your AI traffic.

Architecture Overview

Where the proxy and ICAP layers sit in the stack.

On-Prem Requirements

Backing services and network prerequisites.

Guard Gateway API

The API-based integration path.

Installation

Deploy the proxy and ICAP services.