LLM Gateway
Open-source gateway with a hosted option and full-stack self-hosting for teams that want the gateway, keys and request path inside their own infrastructure.
| Dimension | LLM Gateway | AetherGate |
|---|---|---|
| Provider credentials | Self-hosting can keep gateway credentials and configuration inside customer infrastructure; hosted-key implementation details are not fully described in the public sources reviewed. | Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls. |
| Encryption | Self-host deployments can use cloud secret managers and customer-managed infrastructure controls; hosted encryption specifics were not clearly documented in the public pages reviewed. | Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer. |
| PII / guardrails | Public materials emphasize self-hosting/data control more than a standardized built-in PII/prompt-injection security suite. | Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch. |
| Retention / ZDR | Self-hosting gives the operator control of request retention and data residency. Hosted-service retention details should be verified against current policy. | AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract. |
| Access / audit | Deployment and access controls are largely determined by the self-hosted environment; a complete enterprise RBAC/audit matrix was not clearly documented in the public sources reviewed. | Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today. |
| Deployment | Hosted cloud or self-hosted via Docker, Docker Compose, Kubernetes and major clouds. | Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer. |
| Compliance | Self-hosting can support regulated architectures, but the public sources reviewed do not establish a broad LLM Gateway certification claim. | No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today. |
Self-hosting increases control but also moves patching, network hardening, backups, secret management and incident response to the operator.