Skip to content
Comparisons

Sluis vs Cloudflare AI Gateway

Sluis is the stronger gateway for EU organisations: enforced EU routing, reversible pseudonymization and one console with one bill. Cloudflare AI Gateway is a free way to observe and cap traffic.

Last checked
4 October 2026
Reading time
8 min
Compared with
Cloudflare AI Gateway

Verdict: For EU organisations, Sluis is the better choice because it enforces EU-only routing on every request, replaces personal data with «TOKEN» placeholders before it reaches the model, gives you one console with workloads, budgets, audit grouped per request and a single usage-based bill, and runs on a gateway built in Rust for predictable latency and memory safety. You switch by changing the base_url.

The short version

Sluis is a managed gateway hosted in the EU by 7Lab B.V. in Amsterdam. Every request passes Inspect, Route, Seal: sensitive values are detected and pseudonymized, a residency policy decides whether the destination is allowed, and the call is written to a hash-chained audit log. It speaks the OpenAI and Anthropic Messages protocols, so adopting it means changing the base_url in your SDK. The same gateway also powers Sluis Workspace for employees, so people and applications share one policy and one trail. When you need the data plane on your own servers, Sluis Edge provides it.

Cloudflare AI Gateway is a proxy on Cloudflare's network. You change one URL and get analytics, logging, caching, rate limits, retries and model fallback in front of providers such as OpenAI, Anthropic and Google. Its core features are free and it is available on all Cloudflare plans.

At a glance

SluisCloudflare AI Gateway
Operator7Lab B.V., AmsterdamCloudflare, Inc., San Francisco
HostingManaged service hosted in the EU; optional self-hosted Sluis EdgeCloudflare's global network
Provider residency controlOrganisation policy enforced at dispatch; default EU-only, others refused with 403Not described in the AI Gateway docs we read; Data Localization Suite lists AI Gateway as incompatible with Regional Services
Sensitive dataDetects and reversibly pseudonymizes before dispatch; restores in the responseDLP flags or blocks matches in prompts and responses
Safety checksOptional prompt-injection scan and workload scope guard, log or blockGuardrails (Llama Guard 3 8B), flag or block
LogsAudit entry per call, hash-chained, verifiable offline, grouped per requestPrompts and responses logged by default, switchable per gateway or request
BudgetsPer-workload rate limits, budgets and model allow-lists, debited before dispatchSpend-limit rules, up to 20 per gateway
MCPTool calls pass the same gate as chat requestsSeparate product (MCP server portals in Cloudflare One)
Core priceProvider list price + 10%; BYOK EUR 0.50 per 1M tokensFree; logs, guardrails and Logpush have separate pricing
Best fit for EU organisationsSluis

Data location and jurisdiction

Sluis treats residency as organisation policy. The default allows only the EU jurisdiction, and a request that would reach a provider outside the allowed set is refused with 403 before dispatch. EU ownership of the provider is a separate restriction, because an EU serving region does not imply an EU-owned provider. Widening the policy is an explicit, recorded decision. See residency and models.

Cloudflare's documentation describes AI Gateway as a proxy on its network. The Data Localization Suite compatibility table marks AI Gateway as not compatible with Regional Services or Geo Key Manager, and compatible with caveats for the Customer Metadata Boundary. We found no setting in the AI Gateway pages that restricts which provider region a request may reach.

On ownership: Cloudflare, Inc. is a US company. Under the CLOUD Act, a provider subject to US jurisdiction can be ordered to disclose data in its possession, custody or control wherever it is stored. Sluis is operated by a Dutch company, so EU law applies to it, but that is not immunity from every government, and if you allow a US model provider in your policy, that provider's jurisdiction applies to what it receives. Our CLOUD Act guide gives the balanced view.

Sensitive data and guardrails

Sluis acts on the request before it leaves. Sixty built-in detectors cover personal data and secrets, with a national-ID pack that checksum-validates 12 EU countries. Policy can block, mask, log or pseudonymize reversibly: each value becomes a typed token like «EMAIL_1», and the response is restored to the real values on the way back, streaming included. Detection is not perfect, and using Sluis does not by itself establish GDPR compliance. Per-workload overrides let different teams run different modes. Details are in data protection.

Cloudflare's DLP scans prompts and responses with the same detection profiles as Cloudflare One and takes one of two actions, flag or block. It is free on all plans, with two predefined profiles (financial information, and social, insurance and national identifier numbers) unless the account has a Zero Trust subscription, which unlocks the full profile set. Documented limits: policies apply per gateway with no per-request profile selection, base64 content and attachments are not decoded, and with response scanning on, streamed responses are buffered in full before release.

For content safety, Sluis offers a prompt-injection scan (off, log or block) and a per-workload scope guard that refuses out-of-scope calls. Sluis's own optional checks also add time: the Deep name-recognition tier adds substantial latency before the response starts. Cloudflare Guardrails run Llama Guard 3 8B on Workers AI with per-category flag, ignore or block, plus prompt-injection detection. Its docs state typical added latency of about 500 ms per request and that streaming is not supported while Guardrails are on.

Logging and audit

Sluis writes one audit entry per call and groups the entries per request in the console. Each hash is sha256(prev_hash + record), so altering a field breaks every later link, and sluis-gateway audit verify-chain checks it offline. Content retention is on by default, encrypted at rest, and can be purged while the metadata and hash links stay verifiable. For evidence that nobody edited the record, a hash chain is the stronger answer.

Cloudflare logs can include the prompt, response, provider, tokens, cost and duration. Logging is on by default and can be turned off per gateway or per request, or limited to metadata. Cloudflare's audit logs for AI Gateway cover configuration changes such as creating or deleting a gateway, not the individual requests. For debugging, they are enough.

One console: routing, budgets and agents

Sluis gives you one console. Workloads own rate limits, budgets and model allow-lists; every request is priced from a live price book and debited before dispatch, and past the budget the call returns 402. Routing follows policy and managed aliases such as sluis/auto. MCP tool calls pass the same gate with deny-by-default grants. See budgets and MCP.

Cloudflare's dynamic routing is a visual or JSON flow with conditionals, percentage splits for A/B tests, model nodes, rate-limit and budget nodes, versions and instant rollback. Spend limits apply per model, provider or metadata value and return 429 when exceeded. Dynamic routes can also branch on request body, headers or metadata, so you can build region-based rules yourself.

Pricing

Sluis has no subscription or seat fee, and you get one usage-based bill. Managed usage costs the provider's list price + 10%. With your own provider keys, Sluis charges EUR 0.50 per 1M input plus output tokens. Self-service is prepaid with a EUR 25 minimum and no free tier, and payment-method surcharges apply. Name recognition costs EUR 0.005 or EUR 0.01 per inspected request and a completed injection scan EUR 0.01. See pricing.

Cloudflare's core features are free. Gateways created on or after 24 September 2026 use Workers Logs pricing for logs. Guardrails are billed as Workers AI inference. Unified Billing, where Cloudflare bills the provider usage, adds a 5% fee on credits bought. If you only want to proxy your own keys, Cloudflare is cheaper; Sluis charges for the enforcement it adds. For the other gateways on the shortlist, see AI gateways for EU organisations compared.

Performance

The Sluis gateway is built in Rust for predictable latency and memory safety. In our internal benchmark (relative, on dev hardware, measured internally; identical hardware, one shared mock upstream, 256 connections) it handled 3,678 requests per second with the full security gate on, against 3,148 for Bifrost and 298 for LiteLLM, and the gate adds about 1 ms at the median. With the gate off it reached 4,046 requests per second, p50 62 ms against 80 ms for Bifrost and p99 77 ms against 118 ms. We did not benchmark Cloudflare AI Gateway. See performance.

Who might still pick Cloudflare AI Gateway

  • Teams already on Cloudflare that want AI traffic in the same dashboard.
  • Projects that only need visibility, caching, rate limits and fallback, free and live in minutes.
  • Globally spread applications that value a global edge network in front of providers.
  • Teams that want visual dynamic routing with A/B splits and rollback.

Our verdict

Sluis wins for EU organisations because it enforces what Cloudflare AI Gateway only lets you observe: EU-only routing refused before dispatch, personal data pseudonymized and restored, and an audit chain you can verify offline, all in one console with one bill and a self-hosted option in Sluis Edge. The same gateway also powers Sluis Workspace for your employees. See Sluis Gateway and pricing.

FAQ

Does Cloudflare AI Gateway enforce EU-only routing?

We found no such control in the AI Gateway pages we read, and the Data Localization Suite table lists AI Gateway as incompatible with Regional Services. Dynamic routes can branch on metadata, so you can build your own rule. Sluis enforces EU-only by default, per request.

Can I use Claude Code or the Anthropic SDK with both?

Yes. Sluis serves the Anthropic Messages API natively and can route those requests to any connected provider. Cloudflare documents an Anthropic provider endpoint and a Claude Code integration.

Is Sluis faster than Cloudflare AI Gateway?

We have not measured the two against each other. Sluis's internal benchmark only compares its own gate on and off; see performance. Cloudflare's network placement may matter more for globally spread clients.

Which is cheaper?

For pass-through of your own keys, Cloudflare, whose core features are free. Sluis costs provider list price + 10%, or EUR 0.50 per 1M tokens for BYOK, in exchange for enforced policy and sealed audit.

Sources

All comparisonsNext comparisonSluis vs OpenRouter

Not sure what fits?

Tell us your requirements and we show you how Sluis covers them.

Talk to our team