An AI gateway sits between your applications (or your employees and their coding agents) and the model providers. For an EU organisation the interesting question is what the gateway does about jurisdiction, personal data and evidence; routing, fallbacks and caching are table stakes. This page is written by Sluis, which is one of the eight. We took every other row from the vendor's own documentation on 2026-10-01 and list the sources at the end. Where we could not verify something, we say so.
How to read the table
A gateway can do two different jobs, and most products are strong at one. Connectivity and reliability means one API for many providers, retries, fallbacks, load balancing, budgets, caching and metrics. Control and evidence means policy on where a request may go, handling of personal data before it leaves, and a record you can show an auditor. The criteria below are the second job, because that is where EU requirements bite. If you only need the first, most of these tools do it well and the choice is about operations and price.
The criteria table
| Sluis | LiteLLM | Portkey | Kong AI Gateway | Cloudflare AI Gateway | OpenRouter | Azure API Management | Bifrost | |
|---|---|---|---|---|---|---|---|---|
| Hosting and jurisdiction | Managed, EU-hosted, 7Lab B.V., Amsterdam | You run it | Portkey, Inc. (San Francisco), acquired by Palo Alto Networks (closed 29 May 2026); VPC hosting on Enterprise | Konnect control plane, data plane you run, or on-prem | Cloudflare's network, company based in San Francisco | OpenRouter, Inc. (New York); EU and US regional domains on Business and Enterprise | Azure service, in the region you choose | You run it; in-VPC on Enterprise |
| Self-host | Optional enterprise data plane (Sluis Edge), flat annual licence per gateway | Yes, core use case | Open source gateway; fuller features in the managed product | Yes | No | No | No, but runs in your Azure subscription | Yes |
| Licence | Proprietary | MIT, except the enterprise/ directory | MIT gateway; commercial platform | Kong Gateway Apache 2.0; several AI plugins enterprise-only | Proprietary service | Proprietary service | Microsoft service | Apache 2.0 |
| PII handling | Detection and reversible pseudonymisation before dispatch (60 detectors, optional AI name recognition) | Presidio masking in open source; you deploy the containers | PII redaction on selected guardrails, plan dependent | AI PII Sanitizer (enterprise), separate PII service | DLP free on all plans, two predefined profiles without Zero Trust | Sensitive Info guardrail: redacts or blocks matches (regex, plus Presidio names and locations in beta), input only | Content Safety moderation; no dedicated PII policy found | Enterprise guardrails: regex, Presidio and cloud vendor services |
| Residency enforcement | Organisation policy at dispatch; default EU-only, others refused with 403 | No built-in jurisdiction policy in the docs we read | Region-pinned SaaS and VPC hybrid on Enterprise; no per-request policy described | You choose where data plane and backends run | No provider-region control found; listed as incompatible with Regional Services | EU or US in-region routing on Business and Enterprise; fails closed | You choose the region of gateway and backends | In-VPC deployment on Enterprise |
| Audit | Hash-chained ledger, verifiable offline | Request logging; audit logs with retention are Enterprise | Request logs by plan; admin audit logs on Enterprise | Audit log documented | Logs on by default; audit logs cover configuration changes | Activity logs and export | Prompts and completions to Azure Monitor | Immutable audit trails on Enterprise |
| Pricing model | List price plus 10%, BYOK EUR 0.50 per 1M tokens, no seat fee, prepaid from EUR 25 | Free to run; enterprise by quote | Free, USD 49 per month, enterprise quote | Konnect Plus from USD 25 per month plus usage; enterprise quote | Core free; Unified Billing adds 5% on credits | 5.5% (Standard) or 8% (Business) on credit purchases | Azure pricing by tier | Free open source; enterprise by contact |
Read the table as a starting point. Cells that say "not found" reflect a vendor's overview pages, not proof the capability is missing. Ask each vendor directly.
Sluis
Sluis is a managed gateway and an employee workspace behind one gate. It speaks the OpenAI and Anthropic Messages protocols, so existing SDKs and coding agents connect by changing a base URL. Every request is inspected, routed by policy, sealed in a hash-chained audit entry and metered in real money. See the gateway product page.
- Residency enforced at dispatch. The default allows the EU jurisdiction only. A request for a provider outside the allowed set, such as OpenAI, returns 403 before anything is sent until an owner allows that jurisdiction with a recorded transfer-terms acknowledgement. EU ownership of the provider is a separate restriction, because an EU serving region does not imply an EU-owned provider.
- Personal data before dispatch. Detection and reversible pseudonymisation run before the request leaves. Detection is not perfect, and using Sluis does not by itself establish GDPR or HIPAA compliance.
- Evidence. The audit chain uses sha256(prev_hash + record), so a changed field breaks every later link, and verification runs offline with the gateway CLI. Sluis is ISO 27001 certified.
- Price. Provider list price plus 10%, or EUR 0.50 per million input plus output tokens for bring-your-own-key and custom providers, plus metered checks such as name recognition at EUR 0.005 or EUR 0.01 per request. No platform subscription; payment-method surcharges apply.
On throughput, our internal benchmark shows the gate adding about 1 ms at the median in a controlled run, with about 9% fewer requests per second under synthetic saturation. It is one harness on one developer machine, not a reproduced benchmark, and we build no ranking on it. See the performance page.
Honest limits: Sluis is a managed product from a young company and the repository is proprietary. Within one provider it balances calls across several keys by weight, with retries and circuit breaking, but it has no weighted or latency-based balancing across models or deployments. It has no SAML single sign-on or SCIM provisioning. The Agent Harness route for local coding agents is a residency exception: the provider subscription chooses the serving region and Sluis records it as unverified.
LiteLLM
LiteLLM is an open source gateway: a unified OpenAI-format interface to 100+ providers as a Python SDK or proxy, with virtual keys, spend tracking, budgets, fallbacks and logging. It is MIT licensed apart from its enterprise/ directory. Custom guardrails and Presidio PII masking are in the open source version. SSO is free for up to five users; beyond that, and for audit logs with retention policies, SCIM, key rotation and several built-in guardrails, an enterprise licence is required, priced by quote. You deploy it on your own infrastructure, so jurisdiction is whatever you make it.
Choose it when you have platform engineers and want to own the deployment. Residency and audit evidence are things you assemble. See the Sluis versus LiteLLM comparison.
Portkey
Portkey positions itself as a control panel for production AI: gateway, observability, guardrails, prompt management and an MCP gateway. On 29 May 2026 Palo Alto Networks completed its acquisition of Portkey, and the pricing page now presents the product as Prisma AIRS AI Gateway. That page shows a free Developer tier, a Production plan at USD 49 per month that it says is not recommended for organisations requiring custom security controls or data residency guarantees, and an Enterprise plan with private cloud and VPC hosting, SSO, configurable retention and compliance documentation. The MIT-licensed gateway is also offered for self-hosting.
Choose it when observability and prompt management are the centre of the job and you will negotiate an Enterprise plan, or when you already buy from Palo Alto Networks. See the Sluis versus Portkey comparison.
Kong AI Gateway
Kong extends its Apache 2.0 API gateway with LLM, MCP and agent-to-agent traffic. Its documentation lists provider routing and load balancing, semantic caching, prompt guards, an AI PII Sanitizer that redacts PII before the upstream provider, and integrations with AWS, Azure and Google guardrail services. Several of these AI plugins, including the sanitizer, are enterprise-only. It runs through Konnect with a local data plane or on-prem on self-hosted Kong Gateway, and documents FIPS 140-3 support.
Choose it when Kong already fronts your APIs and you want AI traffic governed by the same team. Policy design is yours to build from plugins. See the Sluis versus Kong AI Gateway comparison.
Cloudflare AI Gateway
Cloudflare AI Gateway gives you analytics, logging, caching, rate limiting, retries and model fallback in front of AI providers, "available on all plans". Core features are free. DLP scanning is free on all plans with two predefined profiles, with fuller profiles on a Zero Trust subscription. Guardrails use Llama Guard on Workers AI and are billed as inference. Unified Billing adds a 5% fee on credits, and logs follow Workers Logs pricing for gateways created from 24 September 2026.
Choose it when you already use Cloudflare, want fast setup and low cost, and need visibility and basic controls rather than enforced jurisdiction. We found no provider-region control in the pages we read, so confirm it if that is a requirement. See the Sluis versus Cloudflare AI Gateway comparison.
OpenRouter
OpenRouter is a hosted router over 500+ models from 80+ providers with one API and one credit balance. It is the broadest option here for model choice. Its documentation describes zero-data-retention routing and EU in-region routing: requests sent to eu.openrouter.ai are only routed to EU endpoints and fail with an error rather than falling back outside the region. In-region routing needs the Business plan or above, and web search, some server tools and the Batch API are not available on regional domains.
For personal data, its Sensitive Info guardrail redacts or blocks matches in requests, using regex presets plus Presidio-based names and locations, which its docs label beta. It scans input only and does not restore original values in the response. Fees are 5.5% (Standard) or 8% (Business) on credit purchases, with provider list prices passed through. SSO (SAML) and SCIM are Enterprise only.
Choose it when you want maximum model choice and credible EU routing, and input-side redaction meets your personal-data needs. See the Sluis versus OpenRouter comparison.
Azure API Management
Azure API Management has AI gateway capabilities across its tiers: token limits and quotas, semantic caching, managed-identity authentication, content safety checks through Azure AI Content Safety, load balancing and circuit breakers, MCP server exposure and logging of prompts and completions to Azure Monitor. It can front Microsoft Foundry, Amazon Bedrock and self-hosted models. Region follows your deployment, and Microsoft's guidance is to deploy AI backends in the same regions as the gateway.
Choose it when your estate is on Azure and you want AI governance inside existing identity, networking and monitoring. See the Sluis versus Azure API Management comparison.
Bifrost
Bifrost is an Apache 2.0 gateway written in Go, with 20+ providers behind an OpenAI-compatible API, fallbacks, load balancing, virtual keys, budgets, semantic caching, an MCP gateway and Prometheus metrics. Enterprise deployments add guardrails through AWS, Azure, Google and Patronus services, clustering, adaptive load balancing, identity provider integration, in-VPC deployment and immutable audit trails. The project reports very low per-request overhead in its own benchmarks.
Choose it when you want a fast self-hosted open source gateway you can embed. Evidence and residency features sit in the enterprise tier. Bifrost has no dedicated comparison page on this site.
How to choose
- Enforced EU-only routing, personal-data handling and verifiable audit, managed for you, with employees and agents on one policy: Sluis.
- Own the deployment, open source, engineering-led: LiteLLM or Bifrost.
- Existing Kong or Azure estate: Kong AI Gateway or Azure API Management.
- Fast, cheap visibility if you already use Cloudflare: Cloudflare AI Gateway.
- Widest model catalogue with documented EU in-region routing: OpenRouter.
- Observability and prompt management first: Portkey.
Three questions separate the field: can the gateway refuse a request for jurisdiction reasons before it is sent, what happens to personal data in the prompt, and can you hand an auditor evidence that has not been editable after the fact?
When the other products are the better choice
Sluis is not the better choice if you must run everything on your own hardware without any managed component (use LiteLLM, Bifrost or Kong, or Sluis Edge on an enterprise licence), if you need 500+ models behind one key (OpenRouter), if your gateway must live inside an existing Azure or Kong estate, or if you want the lowest setup cost for visibility only (Cloudflare). Sluis also has no SAML single sign-on or SCIM provisioning, which several enterprise tiers above list.
FAQ
What is the best AI gateway for EU data residency?
It depends on what you need enforced. Sluis enforces an EU-only default at dispatch and refuses other jurisdictions with a 403. OpenRouter offers EU in-region routing on Business and Enterprise plans that fails closed. Self-hosted gateways such as LiteLLM, Kong and Bifrost let you place everything in the EU yourself, but you design the policy.
Is an open source AI gateway enough for GDPR?
An open source gateway can be part of a compliant setup, but no gateway makes an organisation compliant by itself. You still need a lawful basis, a DPA with each provider, retention decisions and a legal assessment.
Does LiteLLM mask personal data?
Its documentation says Presidio PII masking is included in the open source guardrail framework, and that key and team scoped guardrails and several built-in moderation callbacks need an enterprise licence. Masking quality depends on the detectors you configure and is not a guarantee.
Can a gateway prove what policy ran?
Some can log it. Azure API Management sends prompts and completions to Azure Monitor, and LiteLLM, Bifrost and OpenRouter keep logs. Sluis additionally seals each request and each check in a hash chain that can be verified offline. Tamper evidence is a narrower property than logging, so check which one a vendor means.
Does a gateway add latency?
Every hop adds some. Vendors publish different figures under different conditions, and none are directly comparable. Sluis's own measurement shows about 1 ms at the median under controlled load, from an internal harness we do not present as independent. Benchmark on your own traffic.
Which gateway is cheapest?
Self-hosted open source (LiteLLM, Bifrost) and Cloudflare's core features have no platform fee, but cost operations time or lack enterprise controls. OpenRouter charges 5.5% or 8% on credit purchases, Sluis adds 10% to managed model usage with no seat fee, and Portkey, Kong and the enterprise tiers are priced by plan or quote. The cheapest fee is rarely the cheapest outcome once audit and residency work are counted.
Sources
- Sluis documentation, full text
- Sluis pricing
- Sluis performance
- LiteLLM enterprise documentation
- LiteLLM on GitHub
- Portkey pricing
- Palo Alto Networks completes acquisition of Portkey
- Kong AI Gateway documentation
- Kong pricing
- Cloudflare AI Gateway overview
- Cloudflare AI Gateway pricing
- Cloudflare Data Localization Suite compatibility
- OpenRouter pricing
- OpenRouter in-region routing
- OpenRouter Sensitive Info guardrail
- OpenRouter zero data retention
- Azure API Management AI gateway capabilities
- Bifrost documentation
- Bifrost on GitHub