The open-source intelligence layer for enterprise AI.
Routers move requests; they don't examine them. Bowline is the layer above — open source, in your environment — turning task distribution into an evidenced decision: which class of work runs on which supply, at what modeled cost, with what measured quality. It watches in shadow mode first, changes nothing, and takes authority only when you grant it — one exact workload at a time.
Routers move requests. Bowline decides where work belongs.
Bowline is not a router and doesn't replace yours. It sits in-path as an OpenAI-compatible process — or entirely off the request path, importing bounded, content-free records from routers you already run (LiteLLM and Envoy profiles ship in-repo). Either way, the decision layer stays yours.
The unit is the task, not the request.
Distribution starts by naming the work. Every request maps to a task class, and every class carries a quality floor a candidate supply must clear — before cost even gets a vote. The floors, ratings, and formulas are published, not proprietary sauce.
rote transforms, extraction, formatting
coding, synthesis, longer knowledge work
copy, design, brand-adjacent output
decisions where weak reasoning is costly
▸ quality floors a candidate supply must clear per task class — published defaults, tunable per policy
Three tenets. One gateway.
Enterprise AI keeps ending up rented: someone else's meter, someone else's rules, someone else's custody of your traffic. Bowline is built for the opposite — evidence that makes cost, control, and data sovereignty yours to hold.
Import your real billing exports, reconcile them against what Bowline observed on the wire, and model the counterfactual: what identical traffic would have cost on supply you own or rent — open weights in your VPC included. Every delta carries a confidence label and a published methodology. Opportunities are counterfactual modeled evidence, not realized savings — which is exactly what makes them decision-grade.
Shadow mode is the default: Bowline forwards traffic unchanged and records every decision it would have made. Controlled enforcement is a separate, explicit step, limited to one exact allowlisted workload with fresh verified economics and quality evidence behind it. A kill switch and fail-closed fallbacks stay in your hands. Startup never arms authority automatically.
Bowline deploys where you decide — your VPC, your metal — and policy binds to what a workload is (key, route, app, tags), never to what a prompt says. Persisted evidence is content-free by design: outcomes and integrity-bound reports, not prompts or responses. One deployment is one enterprise security domain.
▸ Supply-agnostic by design: owned hardware, open weights in your VPC, VPC frontier endpoints, and public APIs share one registry schema, one policy shape, and one set of published formulas — floors, ratings, confidence labels, TCO, and the sovereignty ratio.
Four kinds of evidence.
Everything Bowline produces is evidence an operator can verify — rendered from a local, integrity-bound ledger, never from a dashboard you have to trust.
Every request is accounted: the policy and allocation decision Bowline would have made, recorded in an append-only local ledger and rendered as an integrity-aware report.
Bounded offline runs of your own cases against candidate supply, scored by evaluators you configure. Persisted outcomes are content-free; verdicts are advisory evidence for one exact dataset and configuration — not a universal quality score.
Canonical billing import, reconciliation against one named observation window, and counterfactual opportunity arithmetic — sealed as a deterministic, static, private bundle.
An explicit route mode for one exact allowlisted workload, backed by a fresh verified grant. Each request dispatches to zero or one target; fallback is bypass or fail-closed, configured by you.
Evidence before authority.
The operating loop is a ladder you climb deliberately. Each rung produces evidence; only the last one touches traffic — and only after you seal and arm it.
$ bowline preflightvalidate the config against the environment
$ bowline serveshadow mode — forward unchanged, record every decision
$ bowline reportrender integrity-bound decision evidence
$ bowline canary runquality evidence on your own cases, offline and bounded
$ bowline economics reportreconciled billing, counterfactual modeled deltas
$ bowline promotion sealbind the exact evidence to one exact workload
$ bowline kill armyou, explicitly, grant authority — and can take it back
Start with the public evidence.
Inspect the source, reproduce the bounded synthetic path, and read the operating contract. Enterprises helping shape the method can join the research and design conversation.
Apache-2.0 · shadow-first · Enterprise-owned AI infrastructure →