The short version
Portkey and Sluis both sit between your applications and model providers, with keys, routing, guardrails, budgets and logs. They come from different starting points. For the other gateways on the shortlist, see AI gateways for EU organisations compared.
Portkey began as a developer platform for production LLM apps: an MIT-licensed gateway, observability, prompt management and a large guardrail ecosystem. On 29 May 2026 Palo Alto Networks completed its acquisition of Portkey, and Portkey's own pricing page now announces that it is Prisma AIRS AI Gateway. Sluis began from the compliance question: where may this data go, what was removed first, and can we prove it later. It is built by 7Lab B.V. in Amsterdam, and the managed service is hosted in the EU.
Sluis is not open source. It is proprietary, all rights reserved. Portkey's core gateway is MIT licensed.
At a glance
| Sluis | Portkey | |
|---|---|---|
| Vendor | 7Lab B.V., Amsterdam | Portkey, Inc., acquired by Palo Alto Networks (closed 29 May 2026) |
| Licence | Proprietary, all rights reserved | MIT for the open source gateway; enterprise features commercial |
| Deployment | Managed, EU-hosted; self-hosted Edge (enterprise licence) | Cloud, open source self-host, or enterprise hybrid with the data plane in your VPC |
| Residency | Per-request policy, EU-only by default, optional EU-owned-only | Region-pinned SaaS shards (for example EU) on the enterprise plan; hybrid keeps data in your VPC |
| PII | Built-in detectors, block, mask, log or reversible pseudonymization | PII redaction toggle on selected guardrails, including partner providers |
| Budgets | Per workload, with rpm, tpm and model allow-lists | Budget limits on Enterprise and select Pro customers |
| Audit | Hash-chained, verifiable offline, one row per request | Request logs; audit logs for admin activity on Enterprise |
| MCP | Governed through the same gate, deny-by-default grants | MCP Gateway with registry, authentication, tool provisioning and guardrails |
| Price | Provider list price plus 10%, or €0.50 per 1M BYOK tokens | Free developer tier, Production from $49 a month, Enterprise custom |
Ownership and licence
Who owns your gateway vendor matters to a DPO. Portkey, Inc. is a San Francisco company; since May 2026 it belongs to Palo Alto Networks, a US-headquartered security company, which now sells the product as part of Prisma AIRS. That can be a plus if you already buy from Palo Alto. For sovereignty reviews it adds a layer to assess, and our CLOUD Act guide shows how.
The Portkey gateway repository is MIT licensed, and its README says the enterprise gateway is merging into open source with a 2.0 release. Sluis offers no source code. You get documented behaviour, a verifiable audit chain and a managed service instead.
Deployment and residency
Portkey documents three shapes. The SaaS enterprise plan runs the gateway in a region you choose, such as the EU, with region-specific data shards. The hybrid model runs the data plane in your VPC, so prompts, responses and logs stay with you while Portkey hosts the control plane. Open source self-hosting is also available. Portkey's own pricing page says the $49 Production plan is not recommended for organisations that need data residency guarantees, so residency is an enterprise conversation.
The Sluis managed service is hosted in the EU. Its residency engine enforces, per request, where data may go: EU-only by default, other jurisdictions only when you add them, and an EU-owned-only restriction when ownership matters as well as region. Every response discloses the route and model used. For your own servers, Sluis Edge runs the same data plane as one binary; prompts do not transit Sluis's cloud, and provider egress follows your policy. See residency.
Guardrails and PII
Portkey has a broad guardrail library: more than 20 deterministic checks, LLM-based checks and integrations with third parties such as Aporia and Pillar Security. Access depends on the plan. Its PII redaction replaces sensitive values in requests with standard identifiers before the model sees them. Its guardrails documentation says checks evaluate the last message in the request body, so test how that fits your multi-turn flows. We did not find a documented step that restores originals in the response.
Sluis builds data protection into the gateway. Sixty detectors cover emails, IBANs, cards, keys and national IDs, with opt-in name recognition. Each detected value becomes a stable token such as «EMAIL_1» that is restored on the response at the single client egress. Policy can also block, mask or log, and per-workload overrides are governed by owners and admins. Detection is not a guarantee that every sensitive value is found. See data protection.
Budgets, routing and MCP
Portkey is the more mature routing toolkit: configs with retries, fallbacks, load balancing and conditional routing, plus caching, including semantic caching. Budget limits are available on Enterprise and selected Pro customers.
Sluis routes by residency policy and managed aliases. Within one provider it spreads calls across several keys by weight, with retries and circuit breaking, but it has no weighted or latency-based balancing across models or deployments. Each workload carries requests per minute, tokens per minute, a model allow-list and a total, daily or monthly budget, with an organisation cap above. Past the limit the call returns 429 or 402 before dispatch. See budgets and limits.
For MCP, both govern tool calls. Portkey's MCP Gateway adds a registry, OAuth, tool provisioning and guardrails. In Sluis, every tool call clears the same Inspect, Route, Seal and Meter gate, and grants are per key and deny-by-default.
Audit
Portkey's request logs feed its observability product, with retention set by plan. Its audit logs, which track administrative activity such as key and config changes, are an Enterprise feature. Sluis writes every call to a hash-chained ledger that can be verified offline, with optional encrypted bodies under a retention period. Sluis is ISO 27001 certified; Portkey lists SOC 2, ISO 27001, GDPR and HIPAA on its trust portal.
Performance and pricing
Sluis measured its gate internally at about +1 ms at the median against a mock upstream, and 9% lower throughput at synthetic saturation. These numbers are relative, from developer hardware, and we did not test Portkey. See performance.
Portkey is free for developers up to 10k recorded logs a month, $49 a month for Production, then custom. Sluis has no platform subscription, no seat fee and no free tier. Managed usage costs list price plus 10%; with your own keys the fee is €0.50 per 1M tokens; payment-method surcharges apply. See pricing.
When Portkey is the better choice
- You want an open source gateway under MIT that you can modify.
- Prompt management, evaluation and deep request observability matter as much as governance.
- You need advanced routing: fallbacks, load balancing, conditional routes and semantic caching.
- You are a Palo Alto Networks customer and want Prisma AIRS in the same estate.
- You want the data plane in your own cloud account under a hybrid model.
When Sluis is the better choice
- EU-first routing and EU-owned-only provider rules must be enforced per request.
- You want a vendor based in the EU and a managed service hosted there.
- Reversible pseudonymization and an offline-verifiable audit chain are requirements.
- One policy should cover employees, agents and MCP tools.
FAQ
Is Portkey still independent?
No. Palo Alto Networks completed the acquisition on 29 May 2026, and Portkey's site now presents the product as Prisma AIRS AI Gateway. Check current terms with the vendor.
Does Portkey offer EU data residency?
Its documentation describes region-pinned SaaS for enterprise customers, including EU shards, and a hybrid model that keeps data in your VPC. Confirm availability for your plan in writing.
Is Sluis open source like the Portkey gateway?
No. Sluis is proprietary and all rights are reserved. The Portkey gateway repository is MIT licensed.
Can Sluis replace Portkey for prompt management?
Not as a like-for-like swap. Sluis covers gateway governance, Skills and Knowledge inside Sluis Workspace; Portkey ships a dedicated prompt management studio.
Do both support Claude Code and other agents?
Portkey lists a Claude Code gateway use case. Sluis exposes the native Anthropic Messages API and purpose-isolated agent keys for Claude Code, Codex and Cursor, with the Agent Harness exception that region is recorded rather than enforced there.
Sources
- Portkey pricing
- Portkey gateway on GitHub (MIT)
- Palo Alto Networks completes acquisition of Portkey
- Portkey security: SaaS and hybrid
- Portkey enterprise architecture
- Portkey guardrails
- Portkey PII redaction
- Portkey budget limits
- Portkey audit logs
- Portkey documentation index
- Portkey Claude Code gateway