Skip to content
Comparisons

AI gateways for EU organisations compared

Sluis, LiteLLM, Portkey, Kong, Cloudflare, OpenRouter, Azure API Management and Bifrost on one criteria table, with the situations where each is the better choice.

Last checked
1 October 2026
Reading time
11 min

An AI gateway sits between your applications (or your employees and their coding agents) and the model providers. For an EU organisation the interesting question is what the gateway does about jurisdiction, personal data and evidence; routing, fallbacks and caching are table stakes. This page is written by Sluis, which is one of the eight. We took every other row from the vendor's own documentation on 2026-10-01 and list the sources at the end. Where we could not verify something, we say so.

How to read the table

A gateway can do two different jobs, and most products are strong at one. Connectivity and reliability means one API for many providers, retries, fallbacks, load balancing, budgets, caching and metrics. Control and evidence means policy on where a request may go, handling of personal data before it leaves, and a record you can show an auditor. The criteria below are the second job, because that is where EU requirements bite. If you only need the first, most of these tools do it well and the choice is about operations and price.

The criteria table

SluisLiteLLMPortkeyKong AI GatewayCloudflare AI GatewayOpenRouterAzure API ManagementBifrost
Hosting and jurisdictionManaged, EU-hosted, 7Lab B.V., AmsterdamYou run itPortkey, Inc. (San Francisco), acquired by Palo Alto Networks (closed 29 May 2026); VPC hosting on EnterpriseKonnect control plane, data plane you run, or on-premCloudflare's network, company based in San FranciscoOpenRouter, Inc. (New York); EU and US regional domains on Business and EnterpriseAzure service, in the region you chooseYou run it; in-VPC on Enterprise
Self-hostOptional enterprise data plane (Sluis Edge), flat annual licence per gatewayYes, core use caseOpen source gateway; fuller features in the managed productYesNoNoNo, but runs in your Azure subscriptionYes
LicenceProprietaryMIT, except the enterprise/ directoryMIT gateway; commercial platformKong Gateway Apache 2.0; several AI plugins enterprise-onlyProprietary serviceProprietary serviceMicrosoft serviceApache 2.0
PII handlingDetection and reversible pseudonymisation before dispatch (60 detectors, optional AI name recognition)Presidio masking in open source; you deploy the containersPII redaction on selected guardrails, plan dependentAI PII Sanitizer (enterprise), separate PII serviceDLP free on all plans, two predefined profiles without Zero TrustSensitive Info guardrail: redacts or blocks matches (regex, plus Presidio names and locations in beta), input onlyContent Safety moderation; no dedicated PII policy foundEnterprise guardrails: regex, Presidio and cloud vendor services
Residency enforcementOrganisation policy at dispatch; default EU-only, others refused with 403No built-in jurisdiction policy in the docs we readRegion-pinned SaaS and VPC hybrid on Enterprise; no per-request policy describedYou choose where data plane and backends runNo provider-region control found; listed as incompatible with Regional ServicesEU or US in-region routing on Business and Enterprise; fails closedYou choose the region of gateway and backendsIn-VPC deployment on Enterprise
AuditHash-chained ledger, verifiable offlineRequest logging; audit logs with retention are EnterpriseRequest logs by plan; admin audit logs on EnterpriseAudit log documentedLogs on by default; audit logs cover configuration changesActivity logs and exportPrompts and completions to Azure MonitorImmutable audit trails on Enterprise
Pricing modelList price plus 10%, BYOK EUR 0.50 per 1M tokens, no seat fee, prepaid from EUR 25Free to run; enterprise by quoteFree, USD 49 per month, enterprise quoteKonnect Plus from USD 25 per month plus usage; enterprise quoteCore free; Unified Billing adds 5% on credits5.5% (Standard) or 8% (Business) on credit purchasesAzure pricing by tierFree open source; enterprise by contact

Read the table as a starting point. Cells that say "not found" reflect a vendor's overview pages, not proof the capability is missing. Ask each vendor directly.

Sluis

Sluis is a managed gateway and an employee workspace behind one gate. It speaks the OpenAI and Anthropic Messages protocols, so existing SDKs and coding agents connect by changing a base URL. Every request is inspected, routed by policy, sealed in a hash-chained audit entry and metered in real money. See the gateway product page.

  • Residency enforced at dispatch. The default allows the EU jurisdiction only. A request for a provider outside the allowed set, such as OpenAI, returns 403 before anything is sent until an owner allows that jurisdiction with a recorded transfer-terms acknowledgement. EU ownership of the provider is a separate restriction, because an EU serving region does not imply an EU-owned provider.
  • Personal data before dispatch. Detection and reversible pseudonymisation run before the request leaves. Detection is not perfect, and using Sluis does not by itself establish GDPR or HIPAA compliance.
  • Evidence. The audit chain uses sha256(prev_hash + record), so a changed field breaks every later link, and verification runs offline with the gateway CLI. Sluis is ISO 27001 certified.
  • Price. Provider list price plus 10%, or EUR 0.50 per million input plus output tokens for bring-your-own-key and custom providers, plus metered checks such as name recognition at EUR 0.005 or EUR 0.01 per request. No platform subscription; payment-method surcharges apply.

On throughput, our internal benchmark shows the gate adding about 1 ms at the median in a controlled run, with about 9% fewer requests per second under synthetic saturation. It is one harness on one developer machine, not a reproduced benchmark, and we build no ranking on it. See the performance page.

Honest limits: Sluis is a managed product from a young company and the repository is proprietary. Within one provider it balances calls across several keys by weight, with retries and circuit breaking, but it has no weighted or latency-based balancing across models or deployments. It has no SAML single sign-on or SCIM provisioning. The Agent Harness route for local coding agents is a residency exception: the provider subscription chooses the serving region and Sluis records it as unverified.

LiteLLM

LiteLLM is an open source gateway: a unified OpenAI-format interface to 100+ providers as a Python SDK or proxy, with virtual keys, spend tracking, budgets, fallbacks and logging. It is MIT licensed apart from its enterprise/ directory. Custom guardrails and Presidio PII masking are in the open source version. SSO is free for up to five users; beyond that, and for audit logs with retention policies, SCIM, key rotation and several built-in guardrails, an enterprise licence is required, priced by quote. You deploy it on your own infrastructure, so jurisdiction is whatever you make it.

Choose it when you have platform engineers and want to own the deployment. Residency and audit evidence are things you assemble. See the Sluis versus LiteLLM comparison.

Portkey

Portkey positions itself as a control panel for production AI: gateway, observability, guardrails, prompt management and an MCP gateway. On 29 May 2026 Palo Alto Networks completed its acquisition of Portkey, and the pricing page now presents the product as Prisma AIRS AI Gateway. That page shows a free Developer tier, a Production plan at USD 49 per month that it says is not recommended for organisations requiring custom security controls or data residency guarantees, and an Enterprise plan with private cloud and VPC hosting, SSO, configurable retention and compliance documentation. The MIT-licensed gateway is also offered for self-hosting.

Choose it when observability and prompt management are the centre of the job and you will negotiate an Enterprise plan, or when you already buy from Palo Alto Networks. See the Sluis versus Portkey comparison.

Kong AI Gateway

Kong extends its Apache 2.0 API gateway with LLM, MCP and agent-to-agent traffic. Its documentation lists provider routing and load balancing, semantic caching, prompt guards, an AI PII Sanitizer that redacts PII before the upstream provider, and integrations with AWS, Azure and Google guardrail services. Several of these AI plugins, including the sanitizer, are enterprise-only. It runs through Konnect with a local data plane or on-prem on self-hosted Kong Gateway, and documents FIPS 140-3 support.

Choose it when Kong already fronts your APIs and you want AI traffic governed by the same team. Policy design is yours to build from plugins. See the Sluis versus Kong AI Gateway comparison.

Cloudflare AI Gateway

Cloudflare AI Gateway gives you analytics, logging, caching, rate limiting, retries and model fallback in front of AI providers, "available on all plans". Core features are free. DLP scanning is free on all plans with two predefined profiles, with fuller profiles on a Zero Trust subscription. Guardrails use Llama Guard on Workers AI and are billed as inference. Unified Billing adds a 5% fee on credits, and logs follow Workers Logs pricing for gateways created from 24 September 2026.

Choose it when you already use Cloudflare, want fast setup and low cost, and need visibility and basic controls rather than enforced jurisdiction. We found no provider-region control in the pages we read, so confirm it if that is a requirement. See the Sluis versus Cloudflare AI Gateway comparison.

OpenRouter

OpenRouter is a hosted router over 500+ models from 80+ providers with one API and one credit balance. It is the broadest option here for model choice. Its documentation describes zero-data-retention routing and EU in-region routing: requests sent to eu.openrouter.ai are only routed to EU endpoints and fail with an error rather than falling back outside the region. In-region routing needs the Business plan or above, and web search, some server tools and the Batch API are not available on regional domains.

For personal data, its Sensitive Info guardrail redacts or blocks matches in requests, using regex presets plus Presidio-based names and locations, which its docs label beta. It scans input only and does not restore original values in the response. Fees are 5.5% (Standard) or 8% (Business) on credit purchases, with provider list prices passed through. SSO (SAML) and SCIM are Enterprise only.

Choose it when you want maximum model choice and credible EU routing, and input-side redaction meets your personal-data needs. See the Sluis versus OpenRouter comparison.

Azure API Management

Azure API Management has AI gateway capabilities across its tiers: token limits and quotas, semantic caching, managed-identity authentication, content safety checks through Azure AI Content Safety, load balancing and circuit breakers, MCP server exposure and logging of prompts and completions to Azure Monitor. It can front Microsoft Foundry, Amazon Bedrock and self-hosted models. Region follows your deployment, and Microsoft's guidance is to deploy AI backends in the same regions as the gateway.

Choose it when your estate is on Azure and you want AI governance inside existing identity, networking and monitoring. See the Sluis versus Azure API Management comparison.

Bifrost

Bifrost is an Apache 2.0 gateway written in Go, with 20+ providers behind an OpenAI-compatible API, fallbacks, load balancing, virtual keys, budgets, semantic caching, an MCP gateway and Prometheus metrics. Enterprise deployments add guardrails through AWS, Azure, Google and Patronus services, clustering, adaptive load balancing, identity provider integration, in-VPC deployment and immutable audit trails. The project reports very low per-request overhead in its own benchmarks.

Choose it when you want a fast self-hosted open source gateway you can embed. Evidence and residency features sit in the enterprise tier. Bifrost has no dedicated comparison page on this site.

How to choose

  • Enforced EU-only routing, personal-data handling and verifiable audit, managed for you, with employees and agents on one policy: Sluis.
  • Own the deployment, open source, engineering-led: LiteLLM or Bifrost.
  • Existing Kong or Azure estate: Kong AI Gateway or Azure API Management.
  • Fast, cheap visibility if you already use Cloudflare: Cloudflare AI Gateway.
  • Widest model catalogue with documented EU in-region routing: OpenRouter.
  • Observability and prompt management first: Portkey.

Three questions separate the field: can the gateway refuse a request for jurisdiction reasons before it is sent, what happens to personal data in the prompt, and can you hand an auditor evidence that has not been editable after the fact?

When the other products are the better choice

Sluis is not the better choice if you must run everything on your own hardware without any managed component (use LiteLLM, Bifrost or Kong, or Sluis Edge on an enterprise licence), if you need 500+ models behind one key (OpenRouter), if your gateway must live inside an existing Azure or Kong estate, or if you want the lowest setup cost for visibility only (Cloudflare). Sluis also has no SAML single sign-on or SCIM provisioning, which several enterprise tiers above list.

FAQ

What is the best AI gateway for EU data residency?

It depends on what you need enforced. Sluis enforces an EU-only default at dispatch and refuses other jurisdictions with a 403. OpenRouter offers EU in-region routing on Business and Enterprise plans that fails closed. Self-hosted gateways such as LiteLLM, Kong and Bifrost let you place everything in the EU yourself, but you design the policy.

Is an open source AI gateway enough for GDPR?

An open source gateway can be part of a compliant setup, but no gateway makes an organisation compliant by itself. You still need a lawful basis, a DPA with each provider, retention decisions and a legal assessment.

Does LiteLLM mask personal data?

Its documentation says Presidio PII masking is included in the open source guardrail framework, and that key and team scoped guardrails and several built-in moderation callbacks need an enterprise licence. Masking quality depends on the detectors you configure and is not a guarantee.

Can a gateway prove what policy ran?

Some can log it. Azure API Management sends prompts and completions to Azure Monitor, and LiteLLM, Bifrost and OpenRouter keep logs. Sluis additionally seals each request and each check in a hash chain that can be verified offline. Tamper evidence is a narrower property than logging, so check which one a vendor means.

Does a gateway add latency?

Every hop adds some. Vendors publish different figures under different conditions, and none are directly comparable. Sluis's own measurement shows about 1 ms at the median under controlled load, from an internal harness we do not present as independent. Benchmark on your own traffic.

Which gateway is cheapest?

Self-hosted open source (LiteLLM, Bifrost) and Cloudflare's core features have no platform fee, but cost operations time or lack enterprise controls. OpenRouter charges 5.5% or 8% on credit purchases, Sluis adds 10% to managed model usage with no seat fee, and Portkey, Kong and the enterprise tiers are priced by plan or quote. The cheapest fee is rarely the cheapest outcome once audit and residency work are counted.

Sources

All comparisonsNext comparisonEuropean ChatGPT alternatives for organisations

Not sure what fits?

Tell us your requirements and we will say honestly whether Sluis is the right choice.

Talk to our team