Skip to content
Comparisons

Sluis vs OpenRouter

OpenRouter is the widest catalogue of models behind one API, with credible EU in-region routing on paid plans. Sluis is a managed EU gateway built around policy and evidence. Here is how to choose.

Last checked
1 October 2026
Reading time
7 min
Compared with
OpenRouter

The short version

OpenRouter is a hosted router: one API, one credit balance and one set of keys in front of 500+ models from 80+ providers. Its strengths are breadth, fallbacks, an auto-router and a pricing model with no per-request markup. For EU customers it also offers in-region routing on the Business and Enterprise plans.

Sluis is a managed gateway hosted in the EU by 7Lab B.V. in Amsterdam. It speaks the OpenAI and Anthropic Messages protocols and puts every request through Inspect, Route, Seal: detect and pseudonymize sensitive values, route by a residency and ownership policy, and write a tamper-evident audit entry.

Both are real answers to "I want one endpoint for many models". They differ in what happens around the model call. For the wider field, see AI gateways for EU organisations compared.

At a glance

OpenRouterSluis
OperatorOpenRouter, Inc., New York7Lab B.V., Amsterdam
Model catalogue500+ models, 80+ providersMistral, Scaleway, Nebius, Google Vertex, OpenAI, Anthropic, xAI and more; BYOK and custom OpenAI-compatible providers
EU routingEU in-region domain on Business and Enterprise; fails closedEU-only by default on every account; refused with 403 before dispatch
Provider ownershipProvider allow-lists you maintainEU-owned-only is its own policy switch
PII handlingSensitive Info guardrail redacts or blocks matches in requestsDetects and reversibly pseudonymizes; restores in the response
Prompt loggingOff unless you opt in; skipped on regional endpointsAudit entry per call; content retention encrypted and configurable
AuditActivity logs and exportHash-chained ledger, verifiable offline
Self-hostingNoOptional Sluis Edge
Fees5.5% (Standard) or 8% (Business) on credit purchasesProvider list price + 10%; BYOK EUR 0.50 per 1M tokens

Models and routing

OpenRouter's catalogue is its main advantage. Routing and fallback can try alternative models and providers when one fails, failed attempts are not billed, and the Auto Router picks a model per prompt.

Sluis has a smaller, curated catalogue that you can extend: connect your own keys or any OpenAI-compatible endpoint. A provider/model id or a sluis/* alias reaches any connected provider. The managed aliases (sluis/auto, sluis/code, sluis/sovereign and others) always resolve inside your residency policy, and the chosen route is disclosed in response headers. The full list is in residency and models.

Where data goes

With OpenRouter's EU in-region routing, requests sent to eu.openrouter.ai are decrypted in the EU and routed only to endpoints OpenRouter has onboarded in the EU. It fails with an error instead of falling back outside the region, and a guardrail can enforce the allowed regions for a whole workspace. Documented limits: it needs the Business plan or above; the Auto Router, web search (except Exa on the US domain), web fetch, several server tools and the Batch API are unavailable on regional domains; and with your own cloud keys you must provision the matching region yourself.

An EU region is not the same as an EU owner: the OpenRouter docs mention endpoints on Amazon Bedrock, Azure and Google Vertex, which are US-owned clouds, and OpenRouter, Inc. is itself a US company. Under the CLOUD Act a provider subject to US jurisdiction can be ordered to disclose data in its control wherever it sits.

Sluis makes EU-only the default. The default allows only the EU jurisdiction, and widening it is an explicit, recorded decision that unlocks non-EU providers after a transfer-terms acknowledgement. Provider ownership is a separate restriction, so you can require EU-owned providers on top. Sluis is operated from the Netherlands, which brings EU law rather than immunity from every government. See our CLOUD Act guide for the balanced view.

Personal data

OpenRouter's Sensitive Info guardrail scans request content, tool-call arguments and prompt strings before they reach the provider. Presets use regex for email, phone, social security numbers, card numbers, IP addresses and API keys, plus Presidio-based detection of person names and locations, which the docs label beta. Matches are redacted to a placeholder such as [EMAIL] or the request is blocked with 403. It scans input only, not responses, name detection adds latency, and if the name check times out the request proceeds. The docs describe replacement, not restoring the original values in the answer.

Sluis detects with 60 built-in detectors, including a national-ID pack that checksum-validates 12 EU countries, and optional name recognition. It can block, mask, log or pseudonymize reversibly: values become typed tokens like «EMAIL_1» and are restored in the response, streaming included. Detection is not perfect and using Sluis does not by itself establish GDPR compliance. See data protection and our guide on personal data in prompts.

Logging and audit

OpenRouter says it does not store prompts or responses unless you opt in to private logging, which is off by default and, on regional domains, currently skipped. It does store request metadata such as token counts and latency, and it samples a small number of prompts for anonymous categorization unless you opt in to its use of inputs and outputs. Zero Data Retention routing is available on every plan.

Sluis seals every call in a hash-chained ledger: each hash is sha256(prev_hash + record), so any edit breaks the chain, and the chain can be verified offline. Request and response bodies are retained encrypted by default under a TTL you set, or you can run metadata-only. The two models answer different needs: OpenRouter minimizes what it keeps, Sluis keeps evidence you can prove has not changed.

Budgets, workloads and agents

OpenRouter workspaces and guardrails set daily, weekly or monthly budgets, model and provider allow-lists and Zero Data Retention per key or member, and the strictest rule wins. SSO (SAML) and SCIM are available on Enterprise plans only. Sluis has no SAML single sign-on or SCIM provisioning; members sign in with Microsoft, Google or Apple, and owners can require two-factor authentication.

Sluis workloads own rate limits, a budget (total, daily or monthly), model allow-lists and policy overrides, plus an optional scope guard that refuses calls outside a plain-language scope. MCP tool calls pass the same gate with deny-by-default grants, and Claude Code, Codex and Cursor can run under organisation policy through the Agent Harness. See budgets and MCP.

Pricing

OpenRouter charges provider list price for inference. Its fee applies to credit purchases: 5.5% on Standard and 8% on Business, which is the lowest tier with EU in-region routing. With your own keys, the first USD 25,000 of list-price inference per month carries no OpenRouter fee on Standard and Business, then 5%.

Sluis charges provider list price + 10% for managed usage and EUR 0.50 per 1M input plus output tokens for BYOK and custom providers, with no subscription or seat fee. Self-service is prepaid, EUR 25 minimum, no free tier, plus payment-method surcharges. Optional checks are metered: name recognition EUR 0.005 or EUR 0.01 per request, injection scan EUR 0.01. See pricing.

On fees alone OpenRouter is cheaper, especially for BYOK at volume. Sluis's fee pays for enforcement and evidence included from the first request.

When OpenRouter is the better choice

  • You need the broadest, fastest-moving model catalogue and one balance for all of it.
  • Your requirement is EU or US processing location, which in-region routing covers, rather than EU ownership or pre-dispatch pseudonymization.
  • You want free models for experiments, an auto-router and automatic fallbacks.
  • You bring your own provider keys at volume and want the lowest platform fee.
  • You want a hosted service and do not need a self-hosted option.

When Sluis is the better choice

  • EU-only routing should be the default for every key, with provider ownership as a separate control.
  • You want sensitive values replaced before dispatch and restored in the answer.
  • You need an audit chain an auditor can verify offline.
  • Employees, services and coding agents should sit under one policy and one trail.
  • You want a self-hosted data plane through Sluis Edge.

FAQ

Does OpenRouter offer EU-only routing?

Yes, on the Business and Enterprise plans, through eu.openrouter.ai, with a guardrail to enforce it for a workspace. The docs list the exclusions, such as the Auto Router and the Batch API. Sluis applies EU-only by default on all accounts.

Does OpenRouter redact personal data?

It has a Sensitive Info guardrail that redacts or blocks matches in requests. It scans input only, and the docs describe no restoration of the original values in the response. Sluis pseudonymizes reversibly and restores them.

Can I use both?

Possibly. Sluis connects any custom OpenAI-compatible provider, so OpenRouter could be one for long-tail models. Sluis would apply pseudonymization and policy before the request leaves. We have not tested this setup; check how the endpoint is classified under your residency policy.

Which is cheaper?

OpenRouter on pure fees. For managed usage Sluis is list + 10% against 5.5% or 8% on credit purchases, and for BYOK EUR 0.50 per 1M tokens against no fee for the first USD 25,000 a month.

Sources

All comparisonsNext comparisonSluis vs Azure API Management AI gateway

Not sure what fits?

Tell us your requirements and we will say honestly whether Sluis is the right choice.

Talk to our team