Metadata Policy Judge
An optional judge reviews captured metadata.
Capture comes first. The judge then evaluates non-content metadata against your policy and records an honest review signal without receiving raw prompts or responses.
For interactions captured through the SDK, a configured judge evaluates the recorded metadata and returns a verdict such as clean, flagged, or unavailable. It is an operational review signal, not a compliance certification, and its verdict remains linked to the tamper-evident audit record. You choose which model judges your workspace and — depending on your plan — whose API key pays for those model calls.
What it does for you
- Content-blind review: configured providers receive metadata, never raw prompts or responses.
- Honest states: clean, flagged, pending, failed, and unavailable remain visible rather than being invented.
- Linked evidence: the verdict is linked to the captured audit record for investigation and export.
- Visible operations: the desktop app and dashboard surface record and grading status as it arrives.
Which judge, and whose key pays for it
You pick the model that grades your workspace — Google Gemini, OpenAI, or both (each record graded twice; a breach found by either wins). You also pick whose provider key pays for those model calls, and that part depends on your plan:
- Pro and Free bring their own key. Paste a Gemini or OpenAI key into the dashboard and the judge grades on it. Those model calls are billed by Google or OpenAI to your account, at your rates — not by us.
- Premium chooses either. Keep using your own key, or switch to Foxy's managed keys and let us cover the model calls. It is a toggle in the dashboard, not a migration.
To say the quiet part out loud: audit-event credits are not model tokens. Your plan buys capture, chaining, anchoring, exports and verification. Unless you are on Premium using our managed keys, the AI judge runs on your provider account and appears on your provider's bill.
A key you store is encrypted before it is written down, decrypted in memory only for the moment a verdict is produced, and never returned by our API, written into your audit chain, or included in an export — the dashboard can only tell you that a key is set, never show it back to you.
If no key is configured and you are not on managed keys, nothing is faked: those records fall back to deterministic metadata checks and are labelled as such, so an unavailable judge reads as an honest unknown rather than a clean pass.
See the judge catch a breach.
Book a demo and we'll run a policy-violating call and watch the flag fire in real time.
Book a demo
Foxy Audit