Verdict: For EU organisations, Sluis is the better choice because personal data is pseudonymized and every request is routed EU-only before it leaves, one console shows workloads, budgets and audit grouped per request, you change a base_url instead of running a proxy, a database and a PII service, and in our internal benchmark the Rust gateway outperformed LiteLLM even with its security gate on.
The short version
Both put one OpenAI-compatible endpoint in front of many model providers, with virtual keys, budgets and logging. The difference is where the work lands. For the other gateways on the shortlist, see AI gateways for EU organisations compared.
Sluis ships the compliance layer as the product: every call is inspected, routed by an EU-first residency policy, sealed in a hash-chained audit log and metered, in a managed service hosted in the EU or on your own servers with Sluis Edge. It speaks the OpenAI and Anthropic APIs, so moving over means changing the base_url.
LiteLLM gives you a broad, MIT-licensed toolkit and leaves the operating model to you: you host it, run its database, wire up PII detection and decide how regions are pinned. Sluis is not open source: the code is all rights reserved, and the self-hosted Edge binary needs an enterprise licence.
At a glance
| Sluis | LiteLLM | |
|---|---|---|
| Licence | Proprietary, all rights reserved | MIT, except the enterprise/ directory under a commercial licence |
| Deployment | Managed service hosted in the EU, or self-hosted Edge (enterprise licence) | Self-hosted (Docker image or pip package) |
| API surface | OpenAI-compatible and native Anthropic Messages, plus an MCP gateway | OpenAI format, plus /responses, /embeddings, /messages, /batches and more |
| Providers | A defined catalog (EU, US and China providers) plus custom OpenAI-compatible endpoints | 100+ providers per its repository |
| PII handling | Built in: 60 detectors, optional name recognition, block, mask, log or reversible pseudonymization | Presidio guardrail (you deploy the Presidio containers): mask or block, optional restore |
| Residency | Per-request policy, EU-only by default, optional EU-owned-only | Configuration you build with deployments and routing |
| Budgets | Per workload: spend, requests and tokens per minute, model allow-list | Per key, user, team and team member; needs Postgres |
| Audit | Tamper-evident hash chain, verifiable offline | Request logging in OSS; audit logs with retention are an enterprise feature |
| Price | Provider list price plus 10%, or €0.50 per 1M tokens with your own keys | Free to run; enterprise licence on quote |
| Best fit for EU organisations | Sluis | Teams that self-host and build their own residency and PII controls |
Licence and hosting
Sluis gives you a managed service hosted in the EU, with nothing to install or patch. When you must run it yourself, Edge is one binary on your servers, managed from the same console: prompts do not transit Sluis's cloud, although model-provider egress still follows your configuration. Edge is enterprise-only, with a flat annual licence per gateway.
LiteLLM's repository is MIT licensed apart from the enterprise/ directory. Its enterprise licence adds SSO beyond five users, SCIM, audit logs with retention, key and team scoped guardrails and a support channel; 24/7 support SLAs cost extra. The documented way to run it is on your own infrastructure, and the vendor states that a self-hosted instance sends no telemetry or data to its servers.
Data protection and guardrails
Sluis's Inspect step is part of the gateway, so nothing extra is deployed. It runs 60 built-in detectors (email, IBAN, credit card, API keys and a national-ID pack that checksum-validates twelve EU countries), plus opt-in name recognition with two model tiers. Policy decides whether a value is blocked, masked, logged or replaced by a stable token such as «EMAIL_1» that is restored in the response. Prompt-injection scanning and a per-workload scope guard are optional. Detection is not a guarantee that every sensitive value is found, and using Sluis does not by itself establish GDPR compliance. See data protection.
LiteLLM's PII masking uses Microsoft Presidio. You deploy the analyzer and anonymizer containers, choose entity types and set each to MASK or BLOCK. A restore flag puts the original values back into the response. Several built-in moderation integrations, such as secret hiding and prompt-injection vendors, need an enterprise licence.
Routing and residency
Sluis routes by policy, enforced on every request. The default is EU-only, jurisdictions such as the US or China are added explicitly, and an EU-owned-only restriction is a separate switch because an EU region does not imply an EU-owned provider. Responses disclose the chosen route and model. Managed aliases such as sluis/auto resolve inside your policy. Within one provider, Sluis spreads calls across several keys by weight, with retries and circuit breaking; weighted or latency-based balancing across models and deployments is available on request for enterprise contracts. See residency and models.
LiteLLM's router is stronger on traffic engineering: weighted and latency-based strategies, cost-based routing, retries, cooldowns and fallbacks across deployments. Keeping traffic in the EU means choosing EU deployments and maintaining that configuration yourself.
Budgets, limits and access
In Sluis, one console object does the work. A workload owns requests per minute, tokens per minute, a model allow-list and a total, daily or monthly budget shared by its keys, and an organisation cap sits above all workloads. Past the rate limit a call returns 429, past the budget 402, and the request never reaches a provider. If the counters are unreachable the check fails closed. MCP tools pass through the same gate: grants are per key and deny-by-default, and each call is inspected, routed, sealed and metered. See budgets and limits.
Both enforce spend before the call. LiteLLM budgets attach to keys, users, teams and team members, and they require a database: without one, budget checks are skipped.
Audit and logging
Sluis writes every call to a hash-chained ledger that you can verify offline with audit verify-chain, with optional encrypted request and response bodies under a retention period. The audit log shows one row per request, and the same ledger is the billing record, so audit and bill agree.
LiteLLM logs requests and responses and exports to observability tools. Its audit logs, which record admin actions and key changes, are listed as an enterprise feature.
Performance
Sluis is written in Rust for predictable latency and memory safety. In our internal benchmark, on identical hardware with one shared mock upstream at 256 connections, the Sluis gateway handled 3,678 requests per second with the full security gate on, against 298 for LiteLLM (and 3,148 for Bifrost). The gate adds about 1 ms at the median. With the gate off, Sluis reached 4,046 requests per second. These figures are relative, on dev hardware, and measured internally. LiteLLM's own figure, 8 ms P95 at 1,000 RPS, comes from a different harness and does not compare directly. Details are on the performance page.
Pricing
Sluis has no platform subscription or seat fee and no free tier. Self-service is prepaid, from a €25 credit purchase, with payment-method surcharges. Managed model usage costs the provider's list price plus 10%. With your own keys, the Sluis fee is €0.50 per 1M input and output tokens, with provider charges billed separately. See pricing.
LiteLLM is free to run, so your cost is infrastructure, a Postgres database and engineering time; the enterprise licence is priced on quote.
Who might still pick LiteLLM
- You need open source you can read, fork and audit.
- You want one Python SDK and a proxy with the widest provider and model coverage, including day-zero models.
- You need fine-grained traffic engineering: latency-based or cost-based routing, weighted pools and custom fallbacks.
- Your team already runs Postgres and Kubernetes and prefers to own the whole stack.
Our verdict
Sluis wins for EU organisations on the four things a gateway is for. Data security: EU-only routing enforced per request, reversible pseudonymization and an audit chain you verify offline, with ISO 27001 certification. Clarity: one console with workloads, budgets and model allow-lists, one audit row per request, one usage-based bill. Ease of use: point an OpenAI or Anthropic client at a new base_url, with a managed EU-hosted service and nothing to operate, or Sluis Edge when you must self-host. Performance: a Rust gateway that outperformed LiteLLM in our internal benchmark, security gate on. The same gateway also powers Sluis Workspace for employees, so people and applications share one policy. See pricing.
FAQ
Can I move from LiteLLM to Sluis by changing the base URL?
For most OpenAI-compatible clients, yes. Point the client at Sluis and use a new key. Model ids on the OpenAI surface are provider-prefixed, such as mistral/mistral-large-latest, and bare ids return 400. Confirm that your providers are in the Sluis catalog; others are available on request for enterprise contracts.
Can LiteLLM keep data in the EU?
Yes, if you deploy it in the EU, route to EU model deployments and keep the configuration accurate. We found no policy setting for provider jurisdiction or ownership in its documentation, so that discipline is yours.
Is Sluis open source?
No. The source is proprietary and all rights are reserved. You can inspect behaviour through the published API documentation, the audit chain and the console, but not the code.
Does the Sluis gate add latency?
In our internal benchmark, about 1 ms at the median with the full security gate on, and the Rust gateway still handled 3,678 requests per second against 298 for LiteLLM. These are relative figures, on dev hardware, measured internally. Against a live model the gate sits inside provider variance, so measure your own workload.
Can I run both?
Possibly. Sluis accepts custom OpenAI-compatible providers and the LiteLLM proxy exposes an OpenAI-compatible API. Test the pairing; the custom-provider fee of €0.50 per 1M tokens applies.