Governed, audited, portable.
What security review asks for: SSO, RBAC, SCIM, audit logs, zero-retention routing, SOC 2 Type II, DPA and private cloud.
SAML & OIDC SSO
Okta, Entra ID, Google Workspace, Auth0, JumpCloud. Enforce SSO across your org.
SCIM provisioning
Sync users and groups from your IdP. Off-boarding revokes keys and audit access in real time.
Roles & permissions
Owner, admin, developer, viewer, billing — scoped to projects. Least-privilege by default.
Immutable audit log
Every key op, policy change and API call — signed, timestamped, exportable to your SIEM.
SOC 2 Type II
Report under NDA. GDPR DPA, HIPAA BAA on eligible plans, EU residency on request.
99.99% managed SLA
Service credits when we miss. Backed by multi-provider, multi-region failover.
Private cloud & VPC peering
Dedicated router in your AWS / GCP / Azure account. Keys and logs stay in your VPC.
White-label gateway
Ship a branded gateway and chat UI. Your domain, your logo, our routing.
Dedicated hosted capacity
Reserved replicas of open frontier models on llmcloud GPUs — pinned region and precision, your own rate limits, billed per GPU-hour.
Sovereign compliance pack
Residency pinning, EU AI Act artefacts, signed attestation bundles and per-jurisdiction policy enforcement.
Named account team
Solutions engineer, shared Slack, quarterly reviews, P1 on-call.
Can we self-host?+
Yes — see Self-host. The open-source router runs the same stack as the managed cloud.
How does data residency work?+
Enterprise plans pin routing and the audit-log store to a region. EU-only and US-only postures are both supported.
Do you sign a DPA?+
Yes. Standard DPA at signup; custom DPAs through your account team.
Can we bring our own upstream contracts?+
Yes — BYOK forwards to your accounts with your pricing and residency. The router still handles failover and observability.