Managed multi-tenant
Shared, autoscaling infrastructure with database-level tenant isolation. US default with regional pins on request.
Enterprise
Dedicated tenancy, VPC and private networking, BYO provider contracts, SSO/SAML, audit logs, residency pinning, a named CSM — and the paperwork published before the first call.
SOC 2 controls · GDPR · HIPAA BAA · ISO 27001-aligned
SSO, audit logs, guardrails, and RBAC are not an upsell. They ship to every customer from day one. Enterprise adds deployment, contract, residency, and support depth on top.
Usage/latency/cost routing across 169+ models, fallback chains, and per-org retry, timeout, and cooldown tuning.
SAML 2.0 and OIDC against Okta, Azure AD, Google Workspace, or any compatible IdP, with SCIM provisioning and IdP-enforced MFA.
Append-only trail of every key, guardrail, budget, and team change: actor, timestamp, source IP, payload diff. CSV/JSON export for SIEM.
PII redaction (built-in scanner), prompt-injection detection, and keyword content filtering, scoped org > team > key, on every plan.
Org → team → member hierarchy with four roles, enforced by Postgres Row-Level Security — not application checks alone.
Your logo, your colors, your domain via CNAME. A branded key portal for downstream users, nRouter branding removed.
Most teams run on the managed multi-tenant gateway. Regulated organizations can run dedicated, in their own VPC, or (on the roadmap) fully air-gapped. We are precise about what is GA today and what is a scoped engagement.
Shared, autoscaling infrastructure with database-level tenant isolation. US default with regional pins on request.
Isolated database, dedicated routing engine, and provisioned throughput pinned to your region of choice.
Deployed directly inside your GCP, AWS, or Azure perimeter. Your data plane, our managed control plane.
Self-hosted, air-gapped deployment for strictly regulated environments. Scoped per engagement.
Dedicated, VPC, and on-premise deployments are scoped engagement-by-engagement. Talk to sales and we will design the topology with your cloud team. No over-promised timelines.
The standard managed product is intentionally no-BYOK. You never touch a provider key. For Enterprise customers with existing committed-spend contracts (your reserved capacity or dedicated throughput commitments with a model provider), nRouter routes through that capacity while your pricing and your provider relationship stay yours.
Your contract
Reserved capacity · dedicated throughput
Committed spend, your pricing, your provider relationship
nRouter enterprise layer
Routing · guardrails · governance
Credit reserve+settle, audit trail, RBAC on top of your capacity
Your teams
One key, one bill
sk-nrouter-… virtual keys — no provider key ever handled
TLS 1.2+ is the baseline on every plan. Enterprise adds IP allowlisting, private connectivity, and a residency pin. Customer data is replicated within a single region and never moved without an explicit migration request.
Enforced across all public endpoints with preloaded HSTS headers.
Restrict dashboard and API access to corporate egress IP ranges.
AWS PrivateLink, GCP PSC, and Azure Private Endpoint for zero-internet transit.
Need a region not listed? Most major cloud regions can be supported on a dedicated deployment — ask sales.
We state precisely where each framework stands: achieved, in progress, or available on request. We never imply a certification nRouter does not hold.
nRouter operates SOC 2-aligned security, availability, and confidentiality controls today — encryption, access control, change management, audit logging, tenant isolation. A formal SOC 2 Type II observation period is underway; the audited report is targeted for Q3 2026. Our infrastructure substrate (Microsoft Azure, Supabase) is already SOC 2 Type II certified.
Controls walkthroughInformation security management practices aligned to ISO/IEC 27001 Annex A controls — asset management, access control, cryptography, operations security, supplier relationships. A formal ISO 27001 certification is on the roadmap; the infrastructure substrate (Microsoft Azure, Supabase) is independently ISO 27001 certified.
Controls walkthroughCompliant with the EU General Data Protection Regulation. Data Processing Addendum available for signature, EU Standard Contractual Clauses with subprocessors, data-subject access and erasure tooling built into the dashboard, and EU data residency available on Enterprise.
Read the DPAnRouter supports HIPAA-eligible workloads. A Business Associate Agreement (BAA) is available for healthcare customers processing protected health information — request one through the Enterprise team. PII redaction guardrails run on every request at no extra cost.
Request a BAAnRouter never touches raw cardholder data. All payments are processed by Stripe, a PCI DSS Level 1 certified service provider; card numbers are tokenized client-side and never reach our servers or database. Your PCI scope for using nRouter is therefore minimal.
How payments workPin where customer data is processed and stored. US is the default footprint; EU, UK, Canada, Australia, Singapore, and India are available on request on Enterprise for residency-sensitive workloads.
Residency mapFull controls detail in the Security overview and the trust center. Vendor questionnaires: security@nrouter.ai.
No back-and-forth chasing documents. The DPA and SLA are published and linkable. The MSA and a HIPAA BAA are issued on request through the Enterprise team.
Enterprise engagements come with people: an onboarding engineer, a migration plan, a security review, and a named CSM who knows your deployment — not a rotating inbox.
Dedicated engineer setup for SSO, routing policies, and budgets.
Direct mapping of existing models and fallback chains for seamless cutover.
Controls walkthrough, architecture audit, and completed vendor questionnaires.
Single point of contact, private Slack/Teams channel, and priority SLAs.
Start self-serve with transparent pricing, or scope a custom Enterprise deployment for dedicated infrastructure, residency pins, and a named CSM.
Transparent usage-based pricing with all core platform features included.
Custom-quoted for committed volume, dedicated capacity, and private cloud.
Committed volume above $10K/month, private VPC, or custom contracts? Contact sales to scope.
Self-serve features (SSO, audit logs, guardrails, RBAC, custom branding) are included on every tier at no extra cost. Enterprise is for teams that need dedicated capacity, dedicated or VPC deployment, a named CSM, custom contracts, or a residency pin. It is custom-priced based on volume; talk to sales to scope it.
Managed multi-tenant is generally available and the default. Dedicated single-tenant deployments and VPC / BYO-cloud deployments are Enterprise engagements scoped with your cloud team. Fully air-gapped on-premise is on the roadmap, not GA — we will be candid about timelines on a call rather than over-promising.
The standard managed product is intentionally no-BYOK. You never handle a provider key. For Enterprise customers with existing committed-spend contracts (your reserved capacity or dedicated throughput commitments with a model provider), nRouter can route through that capacity on a dedicated deployment, with your provider pricing preserved. This is an Enterprise-only capability. Talk to us about your existing commitments.
United States is the default footprint. EU, UK, Canada, Australia, Singapore, and India are available on request for residency-sensitive workloads; a region other than the default is pinned at provision time and generally requires a dedicated deployment. Customer data is replicated within a single region and never moved without an explicit migration request.
The Data Processing Addendum (DPA) and SLA are published and linkable directly. The MSA and a HIPAA BAA are provided on request through the sales team. nRouter operates SOC 2-aligned and ISO 27001-aligned controls; as of August 2026 a formal SOC 2 Type II audit is in progress with a Q3 2026 target. Any customer can request a controls walkthrough or a completed vendor security questionnaire from security@nrouter.ai.
A 99.9% uptime SLA applies on every tier; Enterprise adds priority incident response, a named Customer Success Manager, a private support channel, and quarterly business reviews. We monitor every provider endpoint and fail over automatically when an issue is detected.
Enterprise · scoped in days
We walk your team through deployment options, the controls, and the DPA. Typically scoped within days, live within two weeks. Auditors welcome on the call.
SOC 2 Type II audit in progress (status as of August 2026) · GDPR-compliant · HIPAA BAA available · ISO 27001-aligned controls