Skip to content
Sourced & dated buyer's guide

AI Gateway & Eval Buyer's Guide. 

Side-by-side capability matrix for the 8 most common platforms in AI gateway, eval, and red-team RFPs. Real numbers from each vendor's public docs and GitHub — verified 2026-05-07.

SOC 2 evidence engineISO 42001 mappedEU AI ActGDPR
Last verified 2026-05-07. Portkey was acquired by Palo Alto Networks on 2026-04-30 — buyers should weigh acquisition risk + future bundling under Prisma AIRS.

Capability matrix

Eight platforms, one honest scorecard.

CapabilityEvalGuardPortkeyLangfuseHeliconeLangSmithLiteLLMOpenRouterVercel AI Gateway
Eval scorers (built-in)200+0 (evals SDK is OpenAI passthrough)Custom (no library)CustomCustom + LLM-as-judgen/an/an/a
Red-team plugins300+0 (delegated to partners)000000
Attack strategies100+0000000
Compliance frameworks50 (EU AI Act, ISO 42001, NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS, +45)0 framework code mappings (SOC2 / ISO / HIPAA service certs only)000000
Total guardrails (scorers + red-team)588~40 (20 deterministic + 21 partner)Custom0Custom000
LLM firewall p952.57ms (published, /trust/latency)No published numbern/an/an/an/an/an/a
Provider integrations90+ typed89 directories ('1,600+ via aliases')via LiteLLM (100+)Proxy-based (broad)via LangChain100+200+OpenAI + Anthropic + Google
Self-hosted (Docker + Helm)Yes (full platform)OSS gateway only — observability, prompt mgmt, RBAC, persistent cache, OTel exporter, PII model are SaaS-lockedYesYesEnterprise tier onlyYesNo (SaaS-only)No (Vercel-tied)
OSS licenseApache 2.0 (full)Apache 2.0 (gateway frame; persistence/SaaS closed)MITApache 2.0Closed-sourceMITClosed-sourceClosed-source
Acquisition / vendor riskIndependent, bootstrapped⚠️ Acquired by Palo Alto Networks (Apr 30, 2026)YC W23, independentYC W23, independentLangChain Inc subsidiaryIndependentIndependentVercel platform-tied
Cache key normalizationField-aware by default (role+content+model+tenantId)SHA256(entire body) — top_p/user/stream all force missesn/an/an/aBasicn/an/a
Conditional/metadata routing DSL$eq, $ne, $gt, $lt, $in, $nin, $regex, $exists, $contains, $and, $or, $notSame MongoDB-ish DSLn/an/an/aBasic config rulesProvider preferencesLimited
Budget caps with auto-disableYes (per-tenant dailyBudgetUsd, enforced inline)Enterprise tier onlyn/a (observability only)Cost tracking, no auto-disablen/aYesPer-key spending limitVercel platform billing
Sticky load balancingYes (per-tenant session affinity)Yes (Feb 2026)n/an/an/aNoNoNo
Quality-cost routing (auto-downgrade for simple queries)Yes (gateway/quality-cost-router.ts)No first-class primitiven/an/an/aNoManual model preferencesNo
SDK languagesTS, Python, GoTS, PythonTS, PythonTS, PythonTS, Python, Go, JavaPythonREST onlyTS only
Public head-to-head benchmarksYes (/trust/latency 20K runs, NeMo head-to-head)None publishedNoneNoneNoneNoneNoneNone
Pricing transparencyPublic ($49/mo Pro, $199/mo Team, /pricing)Public + Enterprise quote (PII anonymizer + BAA quote-only)PublicPublicPublic + Enterprise quotePublic + EnterprisePay-per-tokenVercel platform pricing

Methodology

  • EvalGuard numbers are drift-checked at build time against the live registries (packages/core/src/counts.ts). Latency is measured at /trust/latency with reproducible scripts.
  • Portkey numbers are from a code audit of all 33 Portkey-AI repos on GitHub (verified 2026-05-07) — including the grep-confirmed absence of red-team and compliance-mapping code.
  • Other competitors are from their public docs + GitHub READMEs. Where marketing was vague (e.g. "1,600+ models"), we counted actual provider directories in their codebases.
  • Acquisition riskis a procurement consideration we surface explicitly. Portkey's announced acquisition by Palo Alto Networks (closes Q4 FY26) is documented at paloaltonetworks.com.
Try EvalGuard Free

No credit card required. Apache 2.0, self-hosted in 5 minutes.