SHIM

Secure AI Gateway

Visit Website
April 1, 2026 Why am I building SHIM?

I was building AI-powered apps — the kind where real users type real things into a chatbot. Names, emails, health questions, financial details. And one day it hit me: all of that was going straight to OpenAI's API with zero filtering. My users' personal data, just... shipped off to a third-party model.

I panicked. I looked for a simple middleware solution — something I could drop in front of my LLM calls to strip out PII before it left my server. Something that would keep me GDPR and KVKK compliant without rewriting my entire stack.

It didn't exist.

At the same time, I was watching my OpenAI bill climb. Users were asking nearly identical questions, and I was paying full price every single time. I kept thinking — why am I sending the same semantic query to the API 200 times a day?

So I started building what I needed: a lightweight gateway that sits between your app and your LLM. It does two things really well:

  1. Redacts PII automatically before anything touches the model. Names, emails, phone numbers — gone before they leave your infrastructure.

  2. Smart caching that understands meaning, not just exact matches. Similar queries get served from cache. My API costs dropped ~40%.

That's SHIM. It exists because I couldn't sleep at night knowing my users' data was floating around unprotected, and I couldn't justify the bill knowing half those calls were redundant.

If you're building anything with LLMs in production — a RAG pipeline, a support chatbot, internal tools — you're probably facing the same two problems I was. SHIM is the thing I wish existed when I started.

Comment

About

Why am I building SHIM? Because I got burned. I was building AI-powered apps — the kind where real users type real things into a chatbot. Names, emails, h