Verdict: For EU organisations, Sluis Gateway is the better choice because EU-only routing is enforced on every request, because personal data is reversibly pseudonymised before it reaches the model, because one policy, one hash-chained audit trail and one usage-based bill (provider list price plus 10%, no seat fees) cover employees, APIs and coding agents, and because the Rust gateway outperformed Bifrost and LiteLLM in our internal benchmark even with its security gate on.
An AI gateway sits between your applications (or your employees and their coding agents) and the model providers. For an EU organisation the interesting question is what the gateway does about jurisdiction, personal data and evidence; routing, fallbacks and caching are table stakes. This page is written by Sluis, which is one of the eight. We took every other row from the vendor's own documentation and list the sources at the end. Where we could not verify something, we say so.
How to read the table
A gateway can do two different jobs, and most products are strong at one. Connectivity and reliability means one API for many providers, retries, fallbacks, load balancing, budgets, caching and metrics. Control and evidence means policy on where a request may go, handling of personal data before it leaves, and a record you can show an auditor. The criteria below are the second job, because that is where EU requirements bite. If you only need the first, most of these tools do it well and the choice is about operations and price.
The criteria table
| Sluis | LiteLLM | Portkey | Kong AI Gateway | Cloudflare AI Gateway | OpenRouter | Azure API Management | Bifrost | |
|---|---|---|---|---|---|---|---|---|
| Hosting and jurisdiction | Managed, EU-hosted, 7Lab B.V., Amsterdam | You run it | Portkey, Inc. (San Francisco), acquired by Palo Alto Networks (closed 29 May 2026); VPC hosting on Enterprise | Konnect control plane, data plane you run, or on-prem | Cloudflare's network, company based in San Francisco | OpenRouter, Inc. (New York); EU and US regional domains on Business and Enterprise | Azure service, in the region you choose | You run it; in-VPC on Enterprise |
| Self-host | Optional enterprise data plane (Sluis Edge), flat annual licence per gateway | Yes, core use case | Open source gateway; fuller features in the managed product | Yes | No | No | No, but runs in your Azure subscription | Yes |
| Licence | Proprietary | MIT, except the enterprise/ directory | MIT gateway; commercial platform | Kong Gateway Apache 2.0; several AI plugins enterprise-only | Proprietary service | Proprietary service | Microsoft service | Apache 2.0 |
| PII handling | Detection and reversible pseudonymisation before dispatch (60 detectors, optional AI name recognition) | Presidio masking in open source; you deploy the containers | PII redaction on selected guardrails, plan dependent | AI PII Sanitizer (enterprise), separate PII service | DLP free on all plans, two predefined profiles without Zero Trust | Sensitive Info guardrail: redacts or blocks matches (regex, plus Presidio names and locations in beta), input only | Content Safety moderation; no dedicated PII policy found | Enterprise guardrails: regex, Presidio and cloud vendor services |
| Residency enforcement | Organisation policy at dispatch; default EU-only, others refused with 403 | No built-in jurisdiction policy in the docs we read | Region-pinned SaaS and VPC hybrid on Enterprise; no per-request policy described | You choose where data plane and backends run | No provider-region control found; listed as incompatible with Regional Services | EU or US in-region routing on Business and Enterprise; fails closed | You choose the region of gateway and backends | In-VPC deployment on Enterprise |
| Audit | Hash-chained ledger, verifiable offline, one row per request | Request logging; audit logs with retention are Enterprise | Request logs by plan; admin audit logs on Enterprise | Audit log documented | Logs on by default; audit logs cover configuration changes | Activity logs and export | Prompts and completions to Azure Monitor | Immutable audit trails on Enterprise |
| Pricing model | List price plus 10%, BYOK EUR 0.50 per 1M tokens, no seat fee, prepaid from EUR 25 | Free to run; enterprise by quote | Free, USD 49 per month, enterprise quote | Konnect Plus from USD 25 per month plus usage; enterprise quote | Core free; Unified Billing adds 5% on credits | 5.5% (Standard) or 8% (Business) on credit purchases | Azure pricing by tier | Free open source; enterprise by contact |
| Best for | EU organisations: Sluis | Engineering-led self-hosting | Observability and prompt management | Existing Kong estates | Cheap visibility on Cloudflare | Widest model catalogue | Azure estates | Embedded self-hosted speed |
Read the table as a starting point. Cells that say "not found" reflect a vendor's overview pages, not proof the capability is missing. Ask each vendor directly.
1. Sluis Gateway
Sluis is a managed gateway and an employee workspace behind one gate. It speaks the OpenAI and Anthropic Messages protocols, so existing SDKs and coding agents connect by changing a base URL, and employees sign in with Microsoft, Google or Apple. Every request is inspected, routed by policy, sealed in a hash-chained audit entry and metered in real money. See the gateway product page.
Data security.
- Residency enforced at dispatch. The default allows the EU jurisdiction only. A request for a provider outside the allowed set, such as OpenAI, returns 403 before anything is sent until an owner allows that jurisdiction with a recorded transfer-terms acknowledgement. EU ownership of the provider is a separate restriction, because an EU serving region does not imply an EU-owned provider.
- Personal data before dispatch. Detection and reversible pseudonymisation run before the request leaves, and the «TOKEN» placeholders are restored in the response. Detection is not perfect, and using Sluis does not by itself establish GDPR or HIPAA compliance.
- Evidence. The audit chain uses sha256(prev_hash + record), so a changed field breaks every later link, and verification runs offline with the gateway CLI. Sluis is ISO 27001 certified, and Sluis Edge offers self-hosting on an enterprise contract.
Clarity. One policy applies to API calls, employee chat and coding agents. The console shows one row per request with its checks grouped underneath, plus workloads, budgets and a spend overview. The price is provider list price plus 10%, or EUR 0.50 per million input plus output tokens for bring-your-own-key and custom providers, plus metered checks such as name recognition at EUR 0.005 or EUR 0.01 per request. No seat fees and no platform subscription; payment-method surcharges apply.
Ease of use. Change one base URL. External MCP tools go through the same gate. The Workspace gives non-developers the same policy through chat, agents and Skills.
Sign-in. Sluis offers SSO with Microsoft Entra ID, Google and Apple, plus authenticator-app or passkey two-factor. SAML and SCIM are available for enterprise contracts on request.
Performance. The Sluis gateway is built in Rust for predictable latency and memory safety. In our internal benchmark (relative, on dev hardware, measured internally; identical hardware, one shared mock upstream, 256 connections) it handled 3,678 requests per second with the full security gate on, against 3,148 for Bifrost and 298 for LiteLLM. The gate adds about 1 ms at the median. With the gate off, Sluis reached 4,046 requests per second with p50 62 ms against 80 ms for Bifrost and p99 77 ms against 118 ms. We ran no benchmark against the other gateways. See the performance page.
Weighted or latency-based balancing across models or deployments is available on request for enterprise contracts. Within one provider Sluis already balances calls across several keys by weight, with retries and circuit breaking. Sluis is a managed product from a young company and the repository is proprietary. The Agent Harness route for local coding agents is a residency exception: the provider subscription chooses the serving region and Sluis records it as unverified.
2. LiteLLM
LiteLLM is an open source gateway: a unified OpenAI-format interface to 100+ providers as a Python SDK or proxy, with virtual keys, spend tracking, budgets, fallbacks and logging. It is MIT licensed apart from its enterprise/ directory. Custom guardrails and Presidio PII masking are in the open source version. SSO is free for up to five users; beyond that, and for audit logs with retention policies, SCIM, key rotation and several built-in guardrails, an enterprise licence is required, priced by quote. You deploy it on your own infrastructure, so jurisdiction is whatever you make it, and residency and audit evidence are things you assemble. See the Sluis versus LiteLLM comparison.
3. Portkey
Portkey positions itself as a control panel for production AI: gateway, observability, guardrails, prompt management and an MCP gateway. Palo Alto Networks completed its acquisition on 29 May 2026, and the pricing page now presents it as Prisma AIRS AI Gateway. It shows a Production plan at USD 49 per month that it says is not recommended for organisations requiring custom security controls or data residency guarantees, and an Enterprise plan with private cloud and VPC hosting. See the Sluis versus Portkey comparison.
4. Kong AI Gateway
Kong extends its Apache 2.0 API gateway with LLM, MCP and agent-to-agent traffic, including semantic caching, prompt guards and an AI PII Sanitizer that redacts PII before the upstream provider. Several of these AI plugins, including the sanitizer, are enterprise-only. Policy design is yours to build from plugins. See the Sluis versus Kong AI Gateway comparison.
5. Cloudflare AI Gateway
Cloudflare AI Gateway gives you analytics, logging, caching, rate limiting, retries and model fallback, "available on all plans". Core features are free, DLP scanning is free with two predefined profiles, and Unified Billing adds a 5% fee on credits. We found no provider-region control in the pages we read, so confirm it if that is a requirement. See the Sluis versus Cloudflare AI Gateway comparison.
6. OpenRouter
OpenRouter is a hosted router over 500+ models from 80+ providers with one API and one credit balance, the broadest model choice here. Its documentation describes EU in-region routing: requests sent to eu.openrouter.ai are only routed to EU endpoints and fail rather than fall back outside the region. It needs the Business plan or above.
For personal data, its Sensitive Info guardrail redacts or blocks matches in requests, using regex presets plus Presidio-based names and locations, which its docs label beta. It scans input only and does not restore original values in the response. Fees are 5.5% (Standard) or 8% (Business) on credit purchases, with provider list prices passed through. SSO (SAML) and SCIM are Enterprise only. See the Sluis versus OpenRouter comparison.
7. Azure API Management
Azure API Management has AI gateway capabilities across its tiers: token limits, semantic caching, content safety checks through Azure AI Content Safety, load balancing and circuit breakers, and logging of prompts and completions to Azure Monitor. Region follows your deployment. See the Sluis versus Azure API Management comparison.
8. Bifrost
Bifrost is an Apache 2.0 gateway written in Go, with 20+ providers behind an OpenAI-compatible API, fallbacks, load balancing, virtual keys, budgets, semantic caching and an MCP gateway. Enterprise deployments add guardrails, in-VPC deployment and immutable audit trails. Bifrost has no dedicated comparison page on this site.
How to choose
- Enforced EU-only routing, personal-data handling and verifiable audit, managed for you, with employees and agents on one policy: Sluis.
- Own the deployment, open source, engineering-led: LiteLLM or Bifrost.
- Existing Kong or Azure estate: Kong AI Gateway or Azure API Management.
- Fast, cheap visibility if you already use Cloudflare: Cloudflare AI Gateway.
- Widest model catalogue with documented EU in-region routing: OpenRouter.
- Observability and prompt management first: Portkey.
Three questions separate the field: can the gateway refuse a request for jurisdiction reasons before it is sent, what happens to personal data in the prompt, and can you hand an auditor evidence that has not been editable after the fact?
Who might still pick the others
- LiteLLM, Bifrost or Kong, if you must run everything on your own hardware with no managed component (or Sluis Edge on an enterprise contract).
- OpenRouter, if you need 500+ models behind one key.
- Azure API Management or Kong, if the gateway must live inside an existing Azure or Kong estate.
- Cloudflare, if you want the lowest setup cost for visibility only.
Our verdict
Sluis Gateway is the better choice for EU organisations: residency enforced per request, personal data pseudonymised before dispatch, an audit chain you can verify offline, and one usage-based bill with no seat fees, for employees, APIs and coding agents alike. See the gateway page and pricing.
FAQ
What is the best AI gateway for EU data residency?
For EU organisations we rank Sluis first: it enforces an EU-only default at dispatch and refuses other jurisdictions with a 403. OpenRouter offers EU in-region routing on Business and Enterprise plans that fails closed. Self-hosted gateways such as LiteLLM, Kong and Bifrost let you place everything in the EU yourself, but you design the policy.
Is an open source AI gateway enough for GDPR?
An open source gateway can be part of a compliant setup, but no gateway makes an organisation compliant by itself. You still need a lawful basis, a DPA with each provider, retention decisions and a legal assessment.
Can a gateway prove what policy ran?
Some can log it. Azure API Management sends prompts and completions to Azure Monitor, and LiteLLM, Bifrost and OpenRouter keep logs. Sluis additionally seals each request and each check in a hash chain that can be verified offline, which is a narrower and stronger property than logging. Check which one a vendor means.
Does a gateway add latency?
Every hop adds some, and vendors publish figures under different conditions. In our internal benchmark (relative, on dev hardware, measured internally) the Sluis gateway added about 1 ms at the median with its full security gate on. Benchmark on your own traffic.
Which gateway is cheapest?
Self-hosted open source (LiteLLM, Bifrost) and Cloudflare's core features have no platform fee, but cost operations time or lack enterprise controls. OpenRouter charges 5.5% or 8% on credit purchases, Sluis adds 10% to managed model usage with no seat fee, and Portkey, Kong and the enterprise tiers are priced by plan or quote. The cheapest fee is rarely the cheapest outcome once audit and residency work are counted.
Sources
- Sluis documentation, full text
- Sluis pricing
- Sluis performance
- LiteLLM enterprise documentation
- LiteLLM on GitHub
- Portkey pricing
- Palo Alto Networks completes acquisition of Portkey
- Kong AI Gateway documentation
- Kong pricing
- Cloudflare AI Gateway overview
- Cloudflare AI Gateway pricing
- Cloudflare Data Localization Suite compatibility
- OpenRouter pricing
- OpenRouter in-region routing
- OpenRouter Sensitive Info guardrail
- OpenRouter zero data retention
- Azure API Management AI gateway capabilities
- Bifrost documentation
- Bifrost on GitHub