Enterprise

The gateway your security and
procurement teams sign off on.

Dedicated tenancy, VPC and private networking, BYO provider contracts, SSO/SAML, audit logs, residency pinning, a named CSM — and the paperwork published before the first call.

SOC 2 controls · GDPR · HIPAA BAA · ISO 27001-aligned

  • CustomEnterprise termsPriced per contract — contact sales
  • 99.9%Uptime SLASame SLA every tier
  • 8Residency regionsUS GA, EU + more on request
  • < 2 weeksTypical go-liveSSO, security review, DPA
Capabilities

Every enterprise control on every tier.

SSO, audit logs, guardrails, and RBAC are not an upsell. They ship to every customer from day one. Enterprise adds deployment, contract, residency, and support depth on top.

Routing, fallback & retry

Usage/latency/cost routing across 169+ models, fallback chains, and per-org retry, timeout, and cooldown tuning.

SSO & SAML

SAML 2.0 and OIDC against Okta, Azure AD, Google Workspace, or any compatible IdP, with SCIM provisioning and IdP-enforced MFA.

Audit logging

Append-only trail of every key, guardrail, budget, and team change: actor, timestamp, source IP, payload diff. CSV/JSON export for SIEM.

Guardrails on every request

PII redaction (built-in scanner), prompt-injection detection, and keyword content filtering, scoped org > team > key, on every plan.

RBAC & team management

Org → team → member hierarchy with four roles, enforced by Postgres Row-Level Security — not application checks alone.

White-label branding

Your logo, your colors, your domain via CNAME. A branded key portal for downstream users, nRouter branding removed.

Deployment

Deploy it the way your architecture demands.

Most teams run on the managed multi-tenant gateway. Regulated organizations can run dedicated, in their own VPC, or (on the roadmap) fully air-gapped. We are precise about what is GA today and what is a scoped engagement.

Generally available

Managed multi-tenant

Shared, autoscaling infrastructure with database-level tenant isolation. US default with regional pins on request.

Enterprise

Dedicated tenancy

Isolated database, dedicated routing engine, and provisioned throughput pinned to your region of choice.

Enterprise

VPC / BYO-cloud

Deployed directly inside your GCP, AWS, or Azure perimeter. Your data plane, our managed control plane.

Roadmap

On-premise / air-gapped

Self-hosted, air-gapped deployment for strictly regulated environments. Scoped per engagement.

Dedicated, VPC, and on-premise deployments are scoped engagement-by-engagement. Talk to sales and we will design the topology with your cloud team. No over-promised timelines.

BYO provider contracts · Enterprise-only

Already have committed provider spend? Route it through nRouter.

The standard managed product is intentionally no-BYOK. You never touch a provider key. For Enterprise customers with existing committed-spend contracts (your reserved capacity or dedicated throughput commitments with a model provider), nRouter routes through that capacity while your pricing and your provider relationship stay yours.

  • Your committed pricing preserved; we add routing, guardrails, observability, and credit governance on top
  • Provider credentials scoped to your dedicated deployment in an isolated secret store
  • Never co-mingled with the managed multi-tenant key pool

Your contract

Reserved capacity · dedicated throughput

Committed spend, your pricing, your provider relationship

nRouter enterprise layer

Routing · guardrails · governance

Credit reserve+settle, audit trail, RBAC on top of your capacity

Your teams

One key, one bill

sk-nrouter-… virtual keys — no provider key ever handled

Private networking & residency

Keep traffic off the public internet. Pin where data lives.

TLS 1.2+ is the baseline on every plan. Enterprise adds IP allowlisting, private connectivity, and a residency pin. Customer data is replicated within a single region and never moved without an explicit migration request.

TLS 1.2+ & HSTS

Enforced across all public endpoints with preloaded HSTS headers.

IP allowlisting

Restrict dashboard and API access to corporate egress IP ranges.

PrivateLink & PSC

AWS PrivateLink, GCP PSC, and Azure Private Endpoint for zero-internet transit.

All 8 residency regions
US East (Virginia)GA
European Union (Netherlands)On request
EU North (Stockholm)On request
United Kingdom (London)On request
Canada (Montréal)On request
Australia (Sydney)On request
SingaporeOn request
India (Mumbai)On request

Need a region not listed? Most major cloud regions can be supported on a dedicated deployment — ask sales.

Compliance

Honest status on every framework.

We state precisely where each framework stands: achieved, in progress, or available on request. We never imply a certification nRouter does not hold.

Audit in progress · Q3 2026

SOC 2 Type II

nRouter operates SOC 2-aligned security, availability, and confidentiality controls today — encryption, access control, change management, audit logging, tenant isolation. A formal SOC 2 Type II observation period is underway; the audited report is targeted for Q3 2026. Our infrastructure substrate (Microsoft Azure, Supabase) is already SOC 2 Type II certified.

Controls walkthrough
Aligned — certification planned

ISO/IEC 27001

Information security management practices aligned to ISO/IEC 27001 Annex A controls — asset management, access control, cryptography, operations security, supplier relationships. A formal ISO 27001 certification is on the roadmap; the infrastructure substrate (Microsoft Azure, Supabase) is independently ISO 27001 certified.

Controls walkthrough
Compliant — DPA available

GDPR

Compliant with the EU General Data Protection Regulation. Data Processing Addendum available for signature, EU Standard Contractual Clauses with subprocessors, data-subject access and erasure tooling built into the dashboard, and EU data residency available on Enterprise.

Read the DPA
BAA available on Enterprise

HIPAA

nRouter supports HIPAA-eligible workloads. A Business Associate Agreement (BAA) is available for healthcare customers processing protected health information — request one through the Enterprise team. PII redaction guardrails run on every request at no extra cost.

Request a BAA
Stripe PCI L1 — no card data on our servers

PCI DSS

nRouter never touches raw cardholder data. All payments are processed by Stripe, a PCI DSS Level 1 certified service provider; card numbers are tokenized client-side and never reach our servers or database. Your PCI scope for using nRouter is therefore minimal.

How payments work
US GA · EU + more on request

Data residency

Pin where customer data is processed and stored. US is the default footprint; EU, UK, Canada, Australia, Singapore, and India are available on request on Enterprise for residency-sensitive workloads.

Residency map

Full controls detail in the Security overview and the trust center. Vendor questionnaires: security@nrouter.ai.

Enterprise people

An implementation team, not just a login.

Enterprise engagements come with people: an onboarding engineer, a migration plan, a security review, and a named CSM who knows your deployment — not a rotating inbox.

Guided onboarding

Dedicated engineer setup for SSO, routing policies, and budgets.

Migration assistance

Direct mapping of existing models and fallback chains for seamless cutover.

Security review

Controls walkthrough, architecture audit, and completed vendor questionnaires.

Named CSM

Single point of contact, private Slack/Teams channel, and priority SLAs.

Pricing

Self-serve for most teams. Talk to Sales for the rest.

Start self-serve with transparent pricing, or scope a custom Enterprise deployment for dedicated infrastructure, residency pins, and a named CSM.

Self-serve

Pay as you go & Subscriptions

Transparent usage-based pricing with all core platform features included.

  • 4% platform fee on credits, every plan
  • Managed multi-tenant infrastructure
  • Full core platform: SSO, audit logs, guardrails
EnterpriseCustom volume

Dedicated & Managed VPC

Custom-quoted for committed volume, dedicated capacity, and private cloud.

  • Dedicated tenancy or BYO-cloud VPC
  • Regional residency pin across 9+ regions
  • Named CSM, custom SLA & legal terms (MSA/BAA)

Committed volume above $10K/month, private VPC, or custom contracts? Contact sales to scope.

FAQ

Enterprise questions, answered.

For tier details, see the pricing page.

What's the minimum enterprise commitment?

Self-serve features (SSO, audit logs, guardrails, RBAC, custom branding) are included on every tier at no extra cost. Enterprise is for teams that need dedicated capacity, dedicated or VPC deployment, a named CSM, custom contracts, or a residency pin. It is custom-priced based on volume; talk to sales to scope it.

What deployment options do you offer?

Managed multi-tenant is generally available and the default. Dedicated single-tenant deployments and VPC / BYO-cloud deployments are Enterprise engagements scoped with your cloud team. Fully air-gapped on-premise is on the roadmap, not GA — we will be candid about timelines on a call rather than over-promising.

Can we use our own provider contracts (BYOK)?

The standard managed product is intentionally no-BYOK. You never handle a provider key. For Enterprise customers with existing committed-spend contracts (your reserved capacity or dedicated throughput commitments with a model provider), nRouter can route through that capacity on a dedicated deployment, with your provider pricing preserved. This is an Enterprise-only capability. Talk to us about your existing commitments.

Where can our data be processed?

United States is the default footprint. EU, UK, Canada, Australia, Singapore, and India are available on request for residency-sensitive workloads; a region other than the default is pinned at provision time and generally requires a dedicated deployment. Customer data is replicated within a single region and never moved without an explicit migration request.

Which compliance documents can procurement get?

The Data Processing Addendum (DPA) and SLA are published and linkable directly. The MSA and a HIPAA BAA are provided on request through the sales team. nRouter operates SOC 2-aligned and ISO 27001-aligned controls; as of August 2026 a formal SOC 2 Type II audit is in progress with a Q3 2026 target. Any customer can request a controls walkthrough or a completed vendor security questionnaire from security@nrouter.ai.

What's your SLA and support model?

A 99.9% uptime SLA applies on every tier; Enterprise adds priority incident response, a named Customer Success Manager, a private support channel, and quarterly business reviews. We monitor every provider endpoint and fail over automatically when an issue is detected.

Enterprise · scoped in days

Bring us your security review, your residency map, and your timeline.

We walk your team through deployment options, the controls, and the DPA. Typically scoped within days, live within two weeks. Auditors welcome on the call.

SOC 2 Type II audit in progress (status as of August 2026) · GDPR-compliant · HIPAA BAA available · ISO 27001-aligned controls