Skip to content
Comparisons

Sluis vs Portkey: AI gateway comparison

Portkey is an AI gateway with observability and prompt tooling, now part of Palo Alto Networks as Prisma AIRS AI Gateway. Sluis is an independent, EU-based gateway built around residency policy, reversible pseudonymization and a sealed audit trail.

Last checked
1 October 2026
Reading time
6 min
Compared with
Portkey

The short version

Portkey and Sluis both sit between your applications and model providers, with keys, routing, guardrails, budgets and logs. They come from different starting points. For the other gateways on the shortlist, see AI gateways for EU organisations compared.

Portkey began as a developer platform for production LLM apps: an MIT-licensed gateway, observability, prompt management and a large guardrail ecosystem. On 29 May 2026 Palo Alto Networks completed its acquisition of Portkey, and Portkey's own pricing page now announces that it is Prisma AIRS AI Gateway. Sluis began from the compliance question: where may this data go, what was removed first, and can we prove it later. It is built by 7Lab B.V. in Amsterdam, and the managed service is hosted in the EU.

Sluis is not open source. It is proprietary, all rights reserved. Portkey's core gateway is MIT licensed.

At a glance

SluisPortkey
Vendor7Lab B.V., AmsterdamPortkey, Inc., acquired by Palo Alto Networks (closed 29 May 2026)
LicenceProprietary, all rights reservedMIT for the open source gateway; enterprise features commercial
DeploymentManaged, EU-hosted; self-hosted Edge (enterprise licence)Cloud, open source self-host, or enterprise hybrid with the data plane in your VPC
ResidencyPer-request policy, EU-only by default, optional EU-owned-onlyRegion-pinned SaaS shards (for example EU) on the enterprise plan; hybrid keeps data in your VPC
PIIBuilt-in detectors, block, mask, log or reversible pseudonymizationPII redaction toggle on selected guardrails, including partner providers
BudgetsPer workload, with rpm, tpm and model allow-listsBudget limits on Enterprise and select Pro customers
AuditHash-chained, verifiable offline, one row per requestRequest logs; audit logs for admin activity on Enterprise
MCPGoverned through the same gate, deny-by-default grantsMCP Gateway with registry, authentication, tool provisioning and guardrails
PriceProvider list price plus 10%, or €0.50 per 1M BYOK tokensFree developer tier, Production from $49 a month, Enterprise custom

Ownership and licence

Who owns your gateway vendor matters to a DPO. Portkey, Inc. is a San Francisco company; since May 2026 it belongs to Palo Alto Networks, a US-headquartered security company, which now sells the product as part of Prisma AIRS. That can be a plus if you already buy from Palo Alto. For sovereignty reviews it adds a layer to assess, and our CLOUD Act guide shows how.

The Portkey gateway repository is MIT licensed, and its README says the enterprise gateway is merging into open source with a 2.0 release. Sluis offers no source code. You get documented behaviour, a verifiable audit chain and a managed service instead.

Deployment and residency

Portkey documents three shapes. The SaaS enterprise plan runs the gateway in a region you choose, such as the EU, with region-specific data shards. The hybrid model runs the data plane in your VPC, so prompts, responses and logs stay with you while Portkey hosts the control plane. Open source self-hosting is also available. Portkey's own pricing page says the $49 Production plan is not recommended for organisations that need data residency guarantees, so residency is an enterprise conversation.

The Sluis managed service is hosted in the EU. Its residency engine enforces, per request, where data may go: EU-only by default, other jurisdictions only when you add them, and an EU-owned-only restriction when ownership matters as well as region. Every response discloses the route and model used. For your own servers, Sluis Edge runs the same data plane as one binary; prompts do not transit Sluis's cloud, and provider egress follows your policy. See residency.

Guardrails and PII

Portkey has a broad guardrail library: more than 20 deterministic checks, LLM-based checks and integrations with third parties such as Aporia and Pillar Security. Access depends on the plan. Its PII redaction replaces sensitive values in requests with standard identifiers before the model sees them. Its guardrails documentation says checks evaluate the last message in the request body, so test how that fits your multi-turn flows. We did not find a documented step that restores originals in the response.

Sluis builds data protection into the gateway. Sixty detectors cover emails, IBANs, cards, keys and national IDs, with opt-in name recognition. Each detected value becomes a stable token such as «EMAIL_1» that is restored on the response at the single client egress. Policy can also block, mask or log, and per-workload overrides are governed by owners and admins. Detection is not a guarantee that every sensitive value is found. See data protection.

Budgets, routing and MCP

Portkey is the more mature routing toolkit: configs with retries, fallbacks, load balancing and conditional routing, plus caching, including semantic caching. Budget limits are available on Enterprise and selected Pro customers.

Sluis routes by residency policy and managed aliases. Within one provider it spreads calls across several keys by weight, with retries and circuit breaking, but it has no weighted or latency-based balancing across models or deployments. Each workload carries requests per minute, tokens per minute, a model allow-list and a total, daily or monthly budget, with an organisation cap above. Past the limit the call returns 429 or 402 before dispatch. See budgets and limits.

For MCP, both govern tool calls. Portkey's MCP Gateway adds a registry, OAuth, tool provisioning and guardrails. In Sluis, every tool call clears the same Inspect, Route, Seal and Meter gate, and grants are per key and deny-by-default.

Audit

Portkey's request logs feed its observability product, with retention set by plan. Its audit logs, which track administrative activity such as key and config changes, are an Enterprise feature. Sluis writes every call to a hash-chained ledger that can be verified offline, with optional encrypted bodies under a retention period. Sluis is ISO 27001 certified; Portkey lists SOC 2, ISO 27001, GDPR and HIPAA on its trust portal.

Performance and pricing

Sluis measured its gate internally at about +1 ms at the median against a mock upstream, and 9% lower throughput at synthetic saturation. These numbers are relative, from developer hardware, and we did not test Portkey. See performance.

Portkey is free for developers up to 10k recorded logs a month, $49 a month for Production, then custom. Sluis has no platform subscription, no seat fee and no free tier. Managed usage costs list price plus 10%; with your own keys the fee is €0.50 per 1M tokens; payment-method surcharges apply. See pricing.

When Portkey is the better choice

  • You want an open source gateway under MIT that you can modify.
  • Prompt management, evaluation and deep request observability matter as much as governance.
  • You need advanced routing: fallbacks, load balancing, conditional routes and semantic caching.
  • You are a Palo Alto Networks customer and want Prisma AIRS in the same estate.
  • You want the data plane in your own cloud account under a hybrid model.

When Sluis is the better choice

  • EU-first routing and EU-owned-only provider rules must be enforced per request.
  • You want a vendor based in the EU and a managed service hosted there.
  • Reversible pseudonymization and an offline-verifiable audit chain are requirements.
  • One policy should cover employees, agents and MCP tools.

FAQ

Is Portkey still independent?

No. Palo Alto Networks completed the acquisition on 29 May 2026, and Portkey's site now presents the product as Prisma AIRS AI Gateway. Check current terms with the vendor.

Does Portkey offer EU data residency?

Its documentation describes region-pinned SaaS for enterprise customers, including EU shards, and a hybrid model that keeps data in your VPC. Confirm availability for your plan in writing.

Is Sluis open source like the Portkey gateway?

No. Sluis is proprietary and all rights are reserved. The Portkey gateway repository is MIT licensed.

Can Sluis replace Portkey for prompt management?

Not as a like-for-like swap. Sluis covers gateway governance, Skills and Knowledge inside Sluis Workspace; Portkey ships a dedicated prompt management studio.

Do both support Claude Code and other agents?

Portkey lists a Claude Code gateway use case. Sluis exposes the native Anthropic Messages API and purpose-isolated agent keys for Claude Code, Codex and Cursor, with the Agent Harness exception that region is recorded rather than enforced there.

Sources

All comparisonsNext comparisonSluis vs Kong AI Gateway: comparison

Not sure what fits?

Tell us your requirements and we will say honestly whether Sluis is the right choice.

Talk to our team