Source: https://cairl.co/docs/guides/gateway Content revision: sha256:d17531979f377fe8ab1830e11875a21d03bba8e1188b3e99595c0a785c152e71 How GateWay routes participating platforms What GateWay is If they're breached, there's less of you in it. GateWay routes participating-platform destinations through a CAIRL egress node. The participating set comes from CAIRL's service registry; it is not a separate list that an account or environment can widen. Every destination outside that set connects directly, with no CAIRL involvement. GateWay changes the connection address a participating platform sees. It does not hide you from a platform you sign in to. Where the proxy setting applies Firefox can be configured for one profile. Chrome and Edge use the computer's proxy settings. On those browsers, other applications that honor the same settings also route participating-platform destinations through GateWay. Safari also uses the macOS proxy settings, but CAIRL has not yet qualified Safari’s support for the current TLS-to-proxy route; behavior can be uneven. Do not treat Safari as supported until that verification is complete. Destinations outside the participating set continue to connect directly. This is not a network-wide service. Removing the configuration returns every destination to a direct connection. Nodes and failover The configuration contains one global ordered list: US East first and US West second. The second node is failover. The order is not selected for each caller and is not latency-based routing. With the configuration applied, participating platforms fail closed. If the credential is invalid or every CAIRL node is unavailable, those destinations do not silently connect directly. They do not load until the route is restored or the configuration is removed. Credential behavior The proxy credential has a handle and a one-time secret. Copy the secret when it is issued because it cannot be retrieved later. CAIRL stores only its hash. Rotating or revoking the credential invalidates the prior credential. The first time a participating platform loads, the browser can ask for the handle and secret. Availability and setup are managed inside the CAIRL account. Related resources - GateWay product page: https://cairl.co/products/gateway