The short version
Cloudflare AI Gateway is a proxy on Cloudflare's network. You change one URL and get analytics, logging, caching, rate limits, retries and model fallback in front of providers such as OpenAI, Anthropic and Google. Its core features are free and it is available on all Cloudflare plans.
Sluis is a managed gateway hosted in the EU by 7Lab B.V. in Amsterdam. Every request passes Inspect, Route, Seal: sensitive values are detected and pseudonymized, a residency policy decides whether the destination is allowed, and the call is written to a hash-chained audit log. Sluis speaks the OpenAI and Anthropic Messages protocols; Cloudflare documents an OpenAI-compatible endpoint and an Anthropic provider endpoint.
At a glance
| Cloudflare AI Gateway | Sluis | |
|---|---|---|
| Operator | Cloudflare, Inc., San Francisco | 7Lab B.V., Amsterdam |
| Hosting | Cloudflare's global network | Managed service hosted in the EU; optional self-hosted Sluis Edge |
| Provider residency control | Not described in the AI Gateway docs we read; Data Localization Suite lists AI Gateway as incompatible with Regional Services | Organisation policy enforced at dispatch; default EU-only, others refused with 403 |
| Sensitive data | DLP flags or blocks matches in prompts and responses | Detects and reversibly pseudonymizes before dispatch; restores in the response |
| Safety checks | Guardrails (Llama Guard 3 8B), flag or block | Optional prompt-injection scan and workload scope guard, log or block |
| Logs | Prompts and responses logged by default, switchable per gateway or request | Audit entry per call, hash-chained, verifiable offline |
| Budgets | Spend-limit rules, up to 20 per gateway | Per-workload rate limits and budgets, debited before dispatch |
| MCP | Separate product (MCP server portals in Cloudflare One) | Tool calls pass the same gate as chat requests |
| Core price | Free; logs, guardrails and Logpush have separate pricing | Provider list price + 10%; BYOK EUR 0.50 per 1M tokens |
Data location and jurisdiction
Cloudflare's documentation describes AI Gateway as a proxy on its network. The Data Localization Suite compatibility table marks AI Gateway as not compatible with Regional Services or Geo Key Manager, and compatible with caveats for the Customer Metadata Boundary. We found no setting in the AI Gateway pages that restricts which provider region a request may reach.
Sluis treats residency as organisation policy. The default allows only the EU jurisdiction, and a request that would reach a provider outside the allowed set is refused with 403 before dispatch. EU ownership of the provider is a separate restriction, because an EU serving region does not imply an EU-owned provider. Widening the policy is an explicit, recorded decision. See residency and models.
On ownership: Cloudflare, Inc. is a US company. Under the CLOUD Act, a provider subject to US jurisdiction can be ordered to disclose data in its possession, custody or control wherever it is stored. Sluis is operated by a Dutch company, so EU law applies to it, but that is not immunity from every government, and if you allow a US model provider in your policy, that provider's jurisdiction applies to what it receives. Our CLOUD Act guide gives the balanced view.
Sensitive data and guardrails
Cloudflare's DLP scans prompts and responses with the same detection profiles as Cloudflare One and takes one of two actions, flag or block. It is free on all plans, with two predefined profiles (financial information, and social, insurance and national identifier numbers) unless the account has a Zero Trust subscription, which unlocks the full profile set. Documented limits: policies apply per gateway with no per-request profile selection, base64 content and attachments are not decoded, and with response scanning on, streamed responses are buffered in full before release.
Sluis acts on the request before it leaves. Sixty built-in detectors cover personal data and secrets, with a national-ID pack that checksum-validates 12 EU countries. Policy can block, mask, log or pseudonymize reversibly: each value becomes a typed token like «EMAIL_1», and the response is restored to the real values on the way back, streaming included. Detection is not perfect, and using Sluis does not by itself establish GDPR compliance. Per-workload overrides let different teams run different modes. Details are in data protection.
For content safety, Cloudflare Guardrails run Llama Guard 3 8B on Workers AI with per-category flag, ignore or block, plus prompt-injection detection. Its docs state typical added latency of about 500 ms per request and that streaming is not supported while Guardrails are on. Sluis offers a prompt-injection scan (off, log or block) and a per-workload scope guard that refuses out-of-scope calls. Sluis's own optional checks also add time: the Deep name-recognition tier adds substantial latency before the response starts.
Logging and audit
Cloudflare logs can include the prompt, response, provider, tokens, cost and duration. Logging is on by default and can be turned off per gateway or per request, or limited to metadata. Cloudflare's audit logs for AI Gateway cover configuration changes such as creating or deleting a gateway, not the individual requests.
Sluis writes one audit entry per call. Each hash is sha256(prev_hash + record), so altering a field breaks every later link, and sluis-gateway audit verify-chain checks it offline. Content retention is on by default, encrypted at rest, and can be purged while the metadata and hash links stay verifiable. For debugging, Cloudflare's logs are enough. For evidence that nobody edited the record, a hash chain is the stronger answer.
Routing, budgets and agents
Cloudflare's dynamic routing is a visual or JSON flow with conditionals, percentage splits for A/B tests, model nodes, rate-limit and budget nodes, versions and instant rollback. Spend limits apply per model, provider or metadata value and return 429 when exceeded. Dynamic routes can also branch on request body, headers or metadata, so you can build region-based rules yourself.
Sluis routes by policy and by managed aliases such as sluis/auto. Workloads own rate limits, budgets and model allow-lists; every request is priced from a live price book and debited before dispatch, and past the budget the call returns 402. MCP tool calls pass the same gate with deny-by-default grants. See budgets and MCP.
Pricing
Cloudflare's core features are free. Gateways created on or after 24 September 2026 use Workers Logs pricing for logs. Guardrails are billed as Workers AI inference. Unified Billing, where Cloudflare bills the provider usage, adds a 5% fee on credits bought.
Sluis has no subscription or seat fee. Managed usage costs the provider's list price + 10%. With your own provider keys, Sluis charges EUR 0.50 per 1M input plus output tokens. Self-service is prepaid with a EUR 25 minimum and no free tier, and payment-method surcharges apply. Name recognition costs EUR 0.005 or EUR 0.01 per inspected request and a completed injection scan EUR 0.01. See pricing.
If you only want to proxy your own keys, Cloudflare is cheaper. Sluis charges for the enforcement it adds. For the other gateways on the shortlist, see AI gateways for EU organisations compared.
When Cloudflare AI Gateway is the better choice
- You already run on Cloudflare and want AI traffic in the same dashboard.
- Your need is visibility, caching, rate limits and fallback, and you want it free and live in minutes.
- Your applications serve users worldwide and you value a global edge network in front of providers.
- You want visual dynamic routing with A/B splits and rollback.
When Sluis is the better choice
- You must stop a request from reaching a non-EU provider, not just observe it.
- You want personal data replaced before dispatch and restored on return, not only flagged or blocked.
- Auditors need a record you can show has not been altered since it was written.
- Employees, applications and coding agents should share one policy and one trail.
- You want a managed EU operator, or a self-hosted data plane through Sluis Edge.
FAQ
Does Cloudflare AI Gateway enforce EU-only routing?
We found no such control in the AI Gateway pages we read, and the Data Localization Suite table lists AI Gateway as incompatible with Regional Services. Dynamic routes can branch on metadata, so you can build your own rule. Confirm with Cloudflare if enforcement is a requirement.
Can I use Claude Code or the Anthropic SDK with both?
Yes. Cloudflare documents an Anthropic provider endpoint and a Claude Code integration. Sluis serves the Anthropic Messages API natively and can route those requests to any connected provider.
Is Sluis faster than Cloudflare AI Gateway?
We have not measured the two against each other. Sluis's internal benchmark only compares its own gate on and off; see performance. Cloudflare's network placement may matter more for globally spread clients.
Which is cheaper?
For pass-through of your own keys, Cloudflare, whose core features are free. Sluis costs provider list price + 10%, or EUR 0.50 per 1M tokens for BYOK, in exchange for enforced policy and sealed audit.
Sources
- Cloudflare AI Gateway overview
- Cloudflare AI Gateway pricing
- Cloudflare AI Gateway logging
- Cloudflare AI Gateway Data Loss Prevention
- Cloudflare AI Gateway Guardrails usage considerations
- Cloudflare AI Gateway dynamic routing
- Cloudflare AI Gateway spend limits
- Cloudflare AI Gateway audit logs
- Cloudflare Data Localization Suite compatibility
- Cloudflare MCP server portals
- 18 U.S.C. § 2713, added by the CLOUD Act of 2018