Who can use which models?
Look for enforceable model/provider policies, scoped application credentials and revocation—not only a list of supported models.
The useful question is not "which gateway says GDPR?" It is whether the complete request path, access model, logs, provider retention and failover policy match your organization's requirements.
Look for enforceable model/provider policies, scoped application credentials and revocation—not only a list of supported models.
Useful auditability records the selected model, actual provider, retries/fallbacks, latency, cost and credential/application context without pretending that operational telemetry equals a certified audit product.
Check the gateway region, each allowed upstream provider, fallback routes and logging systems. A France- or EU-hosted gateway does not by itself prove end-to-end regional processing.
Evaluate gateway logs separately from upstream-provider retention. BYOK means the customer controls the provider account, but it does not automatically create zero-data-retention.
A fallback rule should not silently route a restricted workload to a provider, model or region the organization did not approve.
AetherGate currently provides technical controls including encrypted BYOK credential storage, hashed/revocable gateway keys, rate and spend constraints, configurable routing/failover, telemetry and common PII/secret redaction for logged prompt previews. AetherGate does not currently claim GDPR certification, guaranteed France/EU-only processing, universal ZDR, SOC 2 or ISO 27001.
Policy, access, audit, spend, data and failover.
Source-backed comparisons across 13 gateway products.
Implemented controls and explicit non-claims.
For authoritative French and EU data-protection guidance, consult CNIL and the European Data Protection Board. This page is a technical procurement framework, not legal advice or a compliance certification.