Skip to content
Sourced & dated buyer's guide

AI Gateway & Eval Buyer's Guide. 

Side-by-side capability matrix for the 8 most common platforms in AI gateway, eval, and red-team RFPs. Real numbers from each vendor's public docs and source — Portkey and LiteLLM re-derived 2026-08-09, the rest verified 2026-05-07.

SOC 2 evidence engineISO 42001 mappedEU AI ActGDPR
Portkey and LiteLLM cells re-derived from their source on 2026-08-09; the rest were last checked 2026-05-07 and are marked ?where we could not verify them. Vendor comparison pages — including this one — are the weakest kind of source; every cell here is meant to be checkable against the vendor's own repo or docs.

Capability matrix

Eight platforms, one honest scorecard.

CapabilityEvalGuardPortkeyLangfuseHeliconeLangSmithLiteLLMOpenRouterVercel AI Gateway
Eval scorers (built-in)200+0 (evals SDK is OpenAI passthrough)Evaluator Library (Ragas) + custom7 presets + custom LLM-as-judgeCustom + LLM-as-judge0 (Evals API proxies OpenAI)n/an/a
Red-team plugins300+0 (delegated to partners)000000
Attack strategies100+0000000
Compliance frameworks (in-product mappings, not certifications)50 (EU AI Act, ISO 42001, NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS, +45)0 framework code mappings (SOC2 / ISO / HIPAA service certs only)0 mappings (SOC 2 Type II + ISO 27001 certified)0 mappings0 mappings (SOC 2 + ISO 27001 certified)000
Total guardrails (scorers + red-team)590~39 (20 deterministic + 19 partner)Evaluator Library + custom7 evaluator presetsCustom51 integrations + own content filter00
LLM firewall p953.67ms (published, /trust/latency)No published numbern/an/an/an/an/an/a
Provider integrations90+ typed71 typed ('1,600+ models via aliases')via LiteLLM (100+)Proxy-based (broad, per their docs)via LangChain100+200+OpenAI + Anthropic + Google
Self-hosted (Docker + Helm)Yes (full platform)OSS gateway only — observability, prompt mgmt, RBAC, LLM-response cache, OTel exporter, PII model are SaaS-lockedYesYes (per their docs)Enterprise tier onlyYesNo (SaaS-only)No (Vercel-tied)
OSS licenseApache 2.0 (SDKs + CLI; hosted service proprietary)Apache 2.0 (gateway frame; control plane closed)MITApache 2.0 (per their repo)Closed-sourceMIT core; enterprise/ under BerriAI ELClosed-sourceClosed-source
OwnershipIndependent, bootstrappedIndependent, venture-backedYC W23, independentYC W23, independent (per their site)LangChain Inc subsidiaryIndependentIndependentVercel platform-tied
Cache key normalizationField-aware by default (role+content+model+tenantId)SHA256(entire body + URL) — a changed top_p or user forces a missn/an/an/aBasicn/an/a
Conditional/metadata routing DSL$eq, $ne, $gt, $lt, $in, $nin, $regex, $exists, $contains, $and, $or, $notSame MongoDB-ish DSLn/an/an/aBasic config rulesProvider preferencesLimited
Budget caps with auto-disableYes (per-tenant dailyBudgetUsd, enforced inline)Enterprise tier onlyn/a (observability only)Cost tracking, no auto-disablen/aYesPer-key spending limitVercel platform billing
Sticky load balancingYes (per-tenant session affinity)Yes (hosted)n/an/an/aNot foundNoNo
Quality-cost routing (auto-downgrade for simple queries)Yes (gateway/quality-cost-router.ts)No first-class primitiven/an/an/aCost-aware routing; no quality-based downgrade foundManual model preferencesNo
SDK languagesTS, Python, Go, JavaTS, PythonTS, PythonTS, PythonTS, Python, Go, JavaPythonREST onlyTS only
Public head-to-head benchmarksYes (/trust/latency 20K runs, NeMo head-to-head)None publishedNoneNoneNoneNoneNoneNone
Pricing transparencyPublic ($49/mo Pro, $199/mo Team, /pricing)Public + Enterprise quote (PII anonymizer + BAA quote-only)PublicPublicPublic + Enterprise quotePublic + EnterprisePay-per-tokenVercel platform pricing

Methodology

  • EvalGuard numbers are drift-checked at build time against the live registries (packages/core/src/counts.ts). Latency is measured at /trust/latency with reproducible scripts.
  • Portkey numbers come from a code audit of Portkey-AI/gateway at commit 669825cbe (2026-08-09) — including the grep-confirmed absence of red-team and compliance-mapping code, and a recount that moved their provider total from 89 to 71.
  • LiteLLM numbers come from the same kind of audit, re-run 2026-08-09. It corrected this page in LiteLLM's favour: they ship 51 guardrail integrations and a real OpenTelemetry exporter, both of which earlier revisions of this table understated.
  • Other competitors are from their public docs + GitHubREADMEs. Where marketing was vague (e.g. "1,600+ models"), we counted actual provider directories in their codebases. Helicone has no clone available to us, so its cells rest on their published docs alone.
  • Corrections we made against ourselves. A previous revision of this page asserted an acquisition of Portkey by Palo Alto Networks, with a date and a press-release link. No primary source supported it and the claim has been removed. If you find a cell here that is wrong, tell us and we will correct it.
Try EvalGuard Free

No credit card required. Apache 2.0 SDKs + CLI, self-hosted in 5 minutes.