Verified October 2026

AI gateway security comparison: 13 major gateways

Security marketing is difficult to compare because vendors use different terms for key custody, zero-data retention, private deployment and compliance. This matrix normalizes the same seven dimensions across AetherGate and 13 major gateway products using public vendor documentation.

“Not publicly documented” is intentionally different from “not supported.” Certification claims are only repeated where the vendor publicly makes them, and infrastructure certifications are not treated as vendor certifications unless the vendor says so.

AetherGate security baseline

Provider credentials

Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.

Encryption

Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.

PII / guardrails

Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.

Retention / ZDR

AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.

Access / audit

Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.

Deployment

Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.

Compliance

No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.

Claims boundary: AetherGate is an early-stage product. Evaluate its controls against your own threat model and regulatory requirements rather than inferring enterprise certifications from technical safeguards.

Gateway-by-gateway security matrix

Each product card uses the same dimensions so differences are easier to evaluate.

LLM Gateway

Open-source gateway with a hosted option and full-stack self-hosting for teams that want the gateway, keys and request path inside their own infrastructure.

DimensionLLM GatewayAetherGate
Provider credentialsSelf-hosting can keep gateway credentials and configuration inside customer infrastructure; hosted-key implementation details are not fully described in the public sources reviewed.Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.
EncryptionSelf-host deployments can use cloud secret managers and customer-managed infrastructure controls; hosted encryption specifics were not clearly documented in the public pages reviewed.Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.
PII / guardrailsPublic materials emphasize self-hosting/data control more than a standardized built-in PII/prompt-injection security suite.Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.
Retention / ZDRSelf-hosting gives the operator control of request retention and data residency. Hosted-service retention details should be verified against current policy.AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.
Access / auditDeployment and access controls are largely determined by the self-hosted environment; a complete enterprise RBAC/audit matrix was not clearly documented in the public sources reviewed.Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.
DeploymentHosted cloud or self-hosted via Docker, Docker Compose, Kubernetes and major clouds.Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.
ComplianceSelf-hosting can support regulated architectures, but the public sources reviewed do not establish a broad LLM Gateway certification claim.No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.
Evaluation caveat

Self-hosting increases control but also moves patching, network hardening, backups, secret management and incident response to the operator.

OpenRouter

Managed model-routing marketplace with encrypted BYOK credentials, provider-retention visibility and organization guardrails for ZDR, prompt-injection and sensitive-data controls.

DimensionOpenRouterAetherGate
Provider credentialsOpenRouter documents BYOK provider credentials as encrypted at rest and write-only after creation; raw keys are not returned in API responses.Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.
EncryptionBYOK provider credentials are documented as encrypted at rest.Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.
PII / guardrailsOrganization guardrails can enforce provider/model allowlists, prompt-injection detection, sensitive-information redaction/blocking and custom filters.Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.
Retention / ZDRProvider retention varies by upstream. OpenRouter exposes provider retention information and guardrails can enforce Zero Data Retention for supported model/provider groups.AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.
Access / auditWorkspace/management keys, per-key budgets and guardrail assignments provide scoped controls. Public documentation reviewed here does not establish the same enterprise audit/RBAC breadth as dedicated governance platforms.Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.
DeploymentManaged service.Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.
ComplianceNo certification claim is made here; teams should verify OpenRouter's current trust/compliance documentation for regulated workloads.No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.
Evaluation caveat

ZDR is provider-dependent. A gateway-level setting cannot override a BYOK provider contract that allows retention unless the route is constrained appropriately.

Portkey / PRISMA AIRS AI Gateway

Enterprise-focused AI gateway with virtual-key custody, encryption, RBAC/SSO, audit logs, PII guardrails and private/on-prem deployment options.

DimensionPortkey / PRISMA AIRS AI GatewayAetherGate
Provider credentialsProvider keys can be held behind Portkey virtual keys, which can be rotated, revoked and monitored.Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.
EncryptionPortkey documents TLS 1.2+ in transit and AES-256 encryption at rest.Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.
PII / guardrailsBuilt-in guardrails include sensitive-data redaction, prompt-injection controls and broader policy enforcement.Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.
Retention / ZDRLog access and retention are configurable by plan; enterprise offerings include custom retention and private data-isolation options.AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.
Access / auditEnterprise features include SSO, RBAC, organization/workspace controls and centralized audit logs with user attribution.Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.
DeploymentSaaS plus private-cloud/on-prem enterprise deployment options.Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.
CompliancePortkey publishes SOC 2 Type 2, ISO 27001, GDPR and HIPAA compliance claims for its enterprise platform.No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.
Evaluation caveat

A number of governance and private-deployment capabilities are enterprise features rather than baseline hosted-plan behavior.

LiteLLM

Self-hosted/open-source proxy with virtual keys and enterprise controls for SSO, JWT, RBAC, audit logs, secret managers and policy enforcement.

DimensionLiteLLMAetherGate
Provider credentialsSupports a master key, virtual keys, key rotation and secret-manager integrations; exact key custody depends on the deployment.Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.
EncryptionTransport/storage controls depend heavily on how the self-hosted proxy, database and secret manager are configured.Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.
PII / guardrailsSupports always-on/request-scoped guardrails, custom guardrails and Presidio-based PII masking.Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.
Retention / ZDRLogging and retention are operator-controlled in self-hosted deployments and can be routed to external observability systems.AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.
Access / auditEnterprise features document SSO, JWT authentication, RBAC and audit logs with retention policies.Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.
DeploymentSelf-hosted; multi-region/admin-worker enterprise deployment is available.Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.
ComplianceCompliance posture is deployment- and contract-dependent; do not infer a certification from the open-source package alone.No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.
Evaluation caveat

Security quality depends on operator configuration: network exposure, database security, master-key handling and upgrades are your responsibility.

Helicone

LLM observability/gateway platform with key-vault features, selective logging controls, prompt-security features and a self-hosting option.

DimensionHeliconeAetherGate
Provider credentialsHelicone publishes API-key vault/key-management capabilities in its own product comparisons and documentation.Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.
EncryptionExact encryption implementation should be verified against Helicone's current security/trust documentation for regulated use.Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.
PII / guardrailsVendor materials describe prompt-injection/jailbreak protections and the ability to omit sensitive request logging.Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.
Retention / ZDRRetention varies by plan in Helicone's published comparisons; self-hosting gives the operator greater control over storage.AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.
Access / auditTeam/enterprise controls exist, but a complete current RBAC/audit matrix should be verified against the current Helicone plan.Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.
DeploymentManaged cloud and self-hosted options.Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.
ComplianceHelicone's own published comparison materials state SOC 2, HIPAA and GDPR support/compliance; buyers should verify current scope in its trust materials.No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.
Evaluation caveat

Helicone is observability-first, so carefully configure what request/response content is logged for sensitive workloads.

Cloudflare AI Gateway

Managed edge gateway with Cloudflare Access identity controls, DLP integration, configurable payload logging and ZDR support for eligible Unified Billing routes.

DimensionCloudflare AI GatewayAetherGate
Provider credentialsGateway access can be protected with AI Gateway tokens or Cloudflare Access/OIDC-backed identity controls; BYOK provider credentials are supported.Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.
EncryptionTraffic runs over Cloudflare's managed edge platform. Specific key-at-rest details should be evaluated under Cloudflare's broader trust documentation.Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.
PII / guardrailsCloudflare DLP can scan incoming prompts and outgoing responses for sensitive information and apply policy actions.Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.
Retention / ZDRPayload logging can be disabled while retaining metadata. ZDR is available for eligible Unified Billing provider routes and is separate from AI Gateway logging.AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.
Access / auditCloudflare Access can require identity-provider authentication and attach verified user identity to AI Gateway traffic.Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.
DeploymentManaged Cloudflare service; private access can be integrated with the broader Cloudflare platform.Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.
ComplianceCloudflare has a broad enterprise compliance program, but this comparison does not treat every Cloudflare certification as automatically scoped to every AI Gateway configuration.No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.
Evaluation caveat

Cloudflare's ZDR setting and its logging setting are distinct; disabling provider retention does not automatically disable AI Gateway logs.

Amazon Bedrock

AWS-managed foundation-model platform with IAM, KMS, PrivateLink, CloudTrail/CloudWatch integration and configurable Bedrock Guardrails.

DimensionAmazon BedrockAetherGate
Provider credentialsUses AWS IAM/STS credentials and policies rather than distributing raw model-provider keys to applications.Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.
EncryptionAWS documents encryption in transit and at rest, KMS integration and private connectivity through AWS PrivateLink.Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.
PII / guardrailsBedrock Guardrails support content policies, sensitive-information/PII detection and redaction, denied topics and other safeguards.Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.
Retention / ZDRAWS states Bedrock inputs/outputs are not shared with model providers or used to train base models; regional routing behavior depends on selected inference options.AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.
Access / auditFine-grained IAM controls plus CloudTrail and CloudWatch provide mature enterprise identity and audit/monitoring primitives.Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.
DeploymentManaged AWS service with VPC/private connectivity and region-specific deployment choices.Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.
ComplianceAWS states Amazon Bedrock supports/participates in programs including GDPR, HIPAA, SOC and FedRAMP High, subject to service-scope and customer configuration.No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.
Evaluation caveat

AWS's shared-responsibility model still leaves identity policy, data classification, regional configuration and application security with the customer.

Requesty

Managed gateway with scoped keys, EU residency, ZDR-capable routes, audit logs and a SOC 2 Type II program that Requesty explicitly says is still in progress.

DimensionRequestyAetherGate
Provider credentialsRequesty documents gateway API keys as hashed at rest, displayed in full only once, revocable and configurable with spend/access controls.Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.
EncryptionPublic security materials describe secure key handling; detailed encryption architecture should be verified in Requesty's trust materials.Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.
PII / guardrailsRouting, guardrails and governance are included in the managed gateway offering.Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.
Retention / ZDRRequesty advertises pinnable Zero Data Retention endpoints and EU data residency in Frankfurt.AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.
Access / auditAudit logs are included in the platform; Enterprise adds SSO/SCIM/private-region and procurement controls.Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.
DeploymentManaged service with EU regional routing and enterprise private-region options.Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.
ComplianceRequesty says SOC 2 Type II is in progress, not completed; it states GDPR compliance and offers a DPA on request.No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.
Evaluation caveat

Do not describe Requesty as SOC 2 Type II certified until its trust page says the audit has completed.

Vercel AI Gateway

Managed gateway with API-key/OIDC authentication, BYOK, gateway-level immediate deletion, provider-level ZDR controls, no-training controls and provider allowlists.

DimensionVercel AI GatewayAetherGate
Provider credentialsSupports AI Gateway API keys, Vercel OIDC tokens and team-level or request-scoped BYOK provider credentials.Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.
EncryptionRuns on Vercel's managed platform; BYOK credentials are stored/used by the team-level gateway configuration. Buyers should review Vercel's trust documentation for exact encryption scope.Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.
PII / guardrailsSecurity controls include provider allowlists, no-prompt-training controls and ZDR routing rather than a general regex PII-redaction engine.Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.
Retention / ZDRVercel states the gateway layer deletes prompts/outputs after inference. Provider-level ZDR is separately enforceable for providers under negotiated ZDR agreements.AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.
Access / auditOIDC reduces long-lived application secrets on Vercel. Team-wide security controls and routing metadata provide policy visibility.Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.
DeploymentManaged Vercel service.Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.
ComplianceThis page does not infer AI-Gateway-specific certification scope from Vercel's broader platform certifications; enterprise buyers should confirm current trust scope.No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.
Evaluation caveat

With BYOK, provider-level retention follows the customer's provider agreement unless the BYOK credential is explicitly marked/verified as ZDR-compliant.

Bifrost (Maxim AI)

Open-source/enterprise gateway with self-hosted, VPC and air-gapped deployment; virtual keys, SSO/RBAC, audit logs, secret/PII guardrails and enterprise compliance claims.

DimensionBifrost (Maxim AI)AetherGate
Provider credentialsVirtual keys, access profiles and external secret-store patterns support scoped access to upstream providers.Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.
EncryptionSecurity posture depends on deployment; enterprise deployments can keep data and secrets inside customer-controlled VPC/on-prem environments.Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.
PII / guardrailsBifrost documents native secrets detection/custom regex plus integrations for PII, prompt-injection and enterprise guardrails.Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.
Retention / ZDRSelf-hosted/air-gapped deployments allow customer-controlled retention and data boundaries.AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.
Access / auditEnterprise materials advertise SSO, role-based permissions and security/compliance audit logging.Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.
DeploymentSingle binary, Docker, Kubernetes/Helm, in-VPC, on-prem and air-gapped enterprise deployment.Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.
ComplianceBifrost enterprise pages state SOC 2 Type II, HIPAA and ISO 27001 compliance for relevant enterprise deployment offerings.No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.
Evaluation caveat

The open-source project's security advisories should be reviewed during deployment and upgrades; self-hosting transfers patch responsibility to the operator.

Orq.ai

Managed/enterprise AI platform with encryption, private deployment options and broader governance; its public security page distinguishes infrastructure certifications from product claims.

DimensionOrq.aiAetherGate
Provider credentialsEnterprise platform controls centralize model/provider access; exact provider-key custody details should be confirmed for the selected Orq deployment.Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.
EncryptionOrq documents AES-256 encryption at rest in GCP Cloud SQL and TLS 1.2 for data in transit.Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.
PII / guardrailsOrq's broader gateway/governance platform includes policy and data-protection capabilities; verify exact guardrail availability by plan.Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.
Retention / ZDRRetention and private-deployment behavior depend on plan/deployment; enterprise private networking options can narrow the data path.AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.
Access / auditEnterprise governance supports organization controls; buyers should verify exact SSO/RBAC/audit-log scope for the selected plan.Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.
DeploymentSaaS with enterprise VPC/on-prem options.Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.
ComplianceOrq's public security policy explicitly references ISO 27001/SOC 2-compliant data centers. Do not automatically convert that statement into an Orq corporate certification claim without current trust evidence.No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.
Evaluation caveat

Differentiate infrastructure certifications from vendor certifications when evaluating procurement requirements.

TrueFoundry AI Gateway

Enterprise AI/agent gateway with private-cloud/on-prem deployment, OAuth/RBAC policy controls, audit logs and guardrails for tool/model traffic.

DimensionTrueFoundry AI GatewayAetherGate
Provider credentialsEnterprise deployments can centralize provider/tool credentials and govern access through identity and policy controls.Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.
EncryptionPrivate/VPC/on-prem deployment can keep sensitive data inside customer-controlled infrastructure; verify encryption-key management for the selected architecture.Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.
PII / guardrailsTrueFoundry advertises PII filtering, restricted-action policies and custom guardrails for model/agent traffic.Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.
Retention / ZDRRetention is deployment- and configuration-dependent, with private infrastructure options for organizations needing tighter data control.AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.
Access / auditOAuth2, RBAC, metadata policies and full audit trails are documented for agent/tool access.Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.
DeploymentSaaS, VPC, on-prem and enterprise private deployment options.Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.
ComplianceTrueFoundry's enterprise materials display/claim support for SOC 2, HIPAA and GDPR standards; procurement teams should verify current attestation scope.No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.
Evaluation caveat

TrueFoundry has a broader enterprise platform surface than a narrow gateway, so security evaluation should include the specific control-plane and agent/tool components you enable.

Kong AI Gateway

Enterprise API/AI gateway built on Kong's mature policy platform with self-hosting, RBAC/audit capabilities and extensible logging/governance.

DimensionKong AI GatewayAetherGate
Provider credentialsCredential handling and secret storage depend on Kong deployment and plugins; enterprise deployments can integrate with broader secret-management patterns.Provider API keys are encrypted before storage with AES-256-GCM and are not returned raw after storage. Application-facing gateway keys are stored as hashes and can be scoped with rate and spend controls.
EncryptionTransport/storage controls depend on Kong Gateway deployment architecture and the surrounding infrastructure.Provider credentials use application-level AES-256-GCM encryption before database storage. Production traffic is served over HTTPS by the hosting layer.
PII / guardrailsKong's AI Gateway uses policy/plugin controls around model traffic; specific PII/prompt-security behavior depends on enabled policies and integrations.Request previews are redacted for common PII and secret patterns before logging. The gateway also validates outbound provider targets and blocks private/internal destinations before dispatch.
Retention / ZDRAI Gateway logging is configurable and can be routed to external systems; retention is largely deployment/logging-pipeline dependent.AetherGate stores request telemetry for observability; it does not currently claim a universal zero-data-retention mode. Upstream provider retention remains governed by the connected provider account and contract.
Access / auditKong Gateway supports RBAC and audit logs for administrative changes; AI Gateway also emits structured logs for AI policies.Production sessions use HTTPOnly Secure cookies. Gateway keys can be revoked and constrained with rate/spend limits. Request and mission telemetry provide operational traces, but AetherGate does not claim a formal enterprise audit-log product today.
DeploymentKonnect-managed and self-hosted Gateway Enterprise options.Managed AetherGate control plane today. Provider inference is sent to the upstream providers configured by the customer.
ComplianceKong maintains an enterprise trust/compliance program, but buyers should verify which attestations apply to their exact Konnect or self-hosted deployment.No SOC 2, ISO 27001, HIPAA, FedRAMP or similar certification is claimed today.
Evaluation caveat

Kong is a broad API platform. Security posture is strongly affected by which gateway mode, plugins, policies and external log/secret systems you deploy.

How to evaluate an AI gateway securely

Separate key custody from app authentication

Your application should not need to carry every upstream provider root key. Look for scoped gateway credentials, revocation and spend/rate boundaries.

Separate gateway retention from provider retention

A gateway can delete its copy while the upstream provider still retains the prompt. BYOK can also change which contract controls retention.

Treat self-hosting as responsibility, not automatic security

Private deployment can reduce third-party exposure, but your team inherits patching, network hardening, secret storage, database security and incident response.

Read certification scope precisely

SOC 2, ISO 27001, HIPAA and FedRAMP statements may apply to a company, service, infrastructure provider or specific enterprise deployment. Verify the exact scope.