Financial services
Every dollar of inference
maps to a desk.
An append-only audit trail your examiners can read, PII redaction on every request, and per-desk budgets settled from the provider's own response — exact, not estimated.
No BYOK · negative balances blocked at the database · flat 4% platform fee
- Append-onlyAudit trailEvery key, budget, guardrail change
- 3Budget scopesOrg · desk/team · per-key
- InlineGuardrail checksPII redaction runs in-process
- 4%Platform feeOpenRouter's published rate is 5.5% (verified September 2026)
Exact cost. Atomic accounting. No overruns.
In a regulated firm, unattributed spend is a finding waiting to happen. Every request reserves credits, forwards, and settles against the provider-reported cost. A failed request releases the reservation. A desk that hits a hard cap gets a clean 402; the database refuses to write a negative balance.
- Per-desk teams with independent hard and soft budgets
- Costs settled from the provider response — exact, not inferred
- Soft-cap alerts at 70 / 90 / 100% via Slack or webhook
- Per-key spend breakdown for chargeback and cost allocation
- Append-only audit trail with actor, IP, and diff: CSV/JSON export for your SIEM
Desk — markets research
Soft cap at 90%
Slack alert fired · desk lead sees it before finance does
Desk — client support
Within budget
PII redaction in front of every customer-facing request
Ledger
Negative balance: impossible
Reserve + settle · 402 on a tripped hard cap · no partial debit
Regulated Request Pipeline: From Trading Desk to Upstream Model
Every financial query flows through an in-memory Rust gate chain designed to execute sub-millisecond policy evaluation, atomic credit holds, and PII masking before touching any external model API.
Enterprise request lifecycle: client → gateway → guardrail filter → smart router → model provider
Trading / Analyst Client
POST /v1/chat/completions
Market research, credit analysis, algorithmic summarization.
Gateway Preflight & Auth
:4000 · In-memory RLS
Virtual key auth, desk budget verification, token bucket rate limit.
Guardrail Filter
FINRA / PII Redaction
Account numbers, SSNs, credit cards redacted in-process.
Smart Router & Optimizer
Tier Routing · Latency
40–70% cost reduction by steering light tasks to fast models.
Model Providers
OpenAI · Anthropic · Bedrock
99.99% multi-provider failover; exact list price settlement.
40–70%
Cost Reduction
Via smart tier routing
99.99%
Uptime SLA
Cross-cloud failover
< 1 ms
Gateway Overhead
In-memory p50 routing
SEC 17a-4
Audit Trail
Append-only WORM logs
Virtual Key Authentication & Row Level Security
Requests arrive at the Rust gateway with an sk-nrouter-desk-... virtual key. In-memory tenant lookup validates desk budgets, team memberships, and per-minute token buckets before any processing begins.
Database Row Level Security (RLS) guarantees absolute cross-tenant and cross-desk data isolation.
Financial PII Redaction & Prompt Injection Defense
In-process zero-overhead pattern and AST analyzers scan input payloads for sensitive financial identifiers: IBAN, ABA routing, credit card numbers, SSNs, and executive contact details. Malicious instruction overrides and prompt injection vectors are refused with HTTP 400 before egress.
Smart Tier Routing (40–70% Cost Reduction)
Routine financial extraction and tabular summarization queries are dynamically steered to high-speed tier-1 models, while complex valuation modeling routes to frontier reasoning models. Latency-optimized routing selects the healthiest endpoint with lowest recent p95 latency.
Cross-Cloud Multi-Provider Failover (99.99% SLA)
If an upstream provider returns 429, 503, or exceeds timeout budgets during market open, nRouter transparently retries across alternative cloud deployments (AWS Bedrock, Azure OpenAI, Google Cloud Vertex) in under 50ms without dropping client connections.
FINRA / SEC Rule 17a-4 Compliant Audit Logging
Inference completes and spend is settled atomically at the exact provider list price with zero token markup. Every prompt event, actor, IP address, latency measurement, and cryptographic hash is committed to an append-only, tamper-evident WORM audit log exportable to Splunk, Datadog, or S3.
Drop-In SDK Integration with Desk Scope & Compliance Headers
Replace OpenAI or Anthropic API endpoints in minutes. Pass desk identifiers, audit parameters, and automated fallback chains using standard HTTP headers.
pip install openai| 1 | # Cache: enabled (org default). Pass nrouter_cache: false to skip. |
| 2 | from openai import OpenAI |
| 3 | import os |
| 4 | |
| 5 | client = OpenAI( |
| 6 | api_key=os.environ["NROUTER_API_KEY"], |
| 7 | base_url="https://api.nrouter.ai/v1", |
| 8 | ) |
| 9 | |
| 10 | response = client.chat.completions.create( |
| 11 | model="gpt-5.4-mini", |
| 12 | temperature=1, |
| 13 | max_completion_tokens=1024, |
| 14 | messages=[ |
| 15 | {"role": "user", "content": "Hello! What models do you support?"}, |
| 16 | ], |
| 17 | extra_body={ |
| 18 | # "nrouter_cache": False, # Uncomment to skip cache |
| 19 | }, |
| 20 | ) |
| 21 | |
| 22 | print(response.choices[0].message.content) |
Header Configuration & Policy Spec
# Production Financial Services Configuration (OpenAI Python SDK)
from openai import OpenAI
client = OpenAI(
base_url="https://api.nrouter.ai/v1",
api_key="sk-nrouter-desk-equities-live-0941",
default_headers={
"x-nr-budget-scope": "desk-equities-trading",
"x-nr-guardrails": "pii-mask,secret-detect,prompt-injection",
"x-nr-audit-compliance": "sec-17a4",
"x-nr-residency": "us"
}
)
response = client.chat.completions.create(
model="nrouter/auto", # Automatically resolves cost/latency tier
messages=[
{"role": "system", "content": "Extract SEC Form 10-K non-GAAP reconciliation metrics."},
{"role": "user", "content": "Extract EBITDA adjustments from the attached earnings release text."}
],
extra_body={
"fallback_models": ["anthropic/claude-3-5-sonnet", "openai/gpt-4o"],
"max_cost_limit": "0.05"
}
)Pre-Egress Credit Hold & Settlement
Every inference request reserves estimated tokens in an atomic database transaction before provider egress. If the provider fails or rejects the call, 100% of held funds are immediately released with $0 debit.
FINRA Rule 4511 & SEC 17a-4 Logging
Every model interaction records timestamped sha256 payload hashes, user identifiers, caller IP, and exact token micro-costs into tamper-evident append-only storage.
Hard Desk Budget Enforcement (HTTP 402)
The database rejects negative balances at the schema level. When an equity or fixed-income desk reaches its budget cap, further inference halts immediately with clean HTTP 402 errors.
Core enterprise capabilities on every plan
PII redaction before a prompt leaves the desk
Account numbers, SSNs, card numbers, emails, and phone numbers redacted inline by the built-in scanner.
Failover for trading-hours workloads
Fallback chains retry on a backup model when a provider degrades. 99.9% uptime SLA on every tier.
Versioned prompt templates
Compliance-approved prompts ship as server-side templates, with every change captured in the audit trail.
What we can prove, and what is in progress.
- SOC 2 Type II — in progress. SOC 2-aligned controls operate today; the audit is in progress as of August 2026. We do not claim “certified” until it is signed.
- GDPR — compliant. A Data Processing Addendum is published and signable; subprocessors are covered by EU Standard Contractual Clauses.
- PCI scope — minimal. nRouter never touches cardholder data; payments run through Stripe, a PCI DSS Level 1 provider.
Running a vendor security review? security@nrouter.ai will send a completed questionnaire and walk your risk team through the controls.
Finance questions, answered
How does nRouter support SEC Rule 17a-4 and FINRA Rule 4511 recordkeeping?
nRouter produces an immutable, append-only audit trail for every LLM interaction. Each entry records the virtual key id, desk identity, UTC timestamp, prompt payload hash, model version, exact token counts, and billed micro-cost.
Audit rows cannot be modified or truncated through application interfaces and can be archived to WORM (Write Once, Read Many) compliant object storage for regulatory examiners.
Is nRouter SOC 2 certified?
Not yet, and we will not say "certified" until the report is signed. nRouter operates SOC 2-aligned controls today: encryption, access control, change management, audit logging, and tenant isolation. As of August 2026, a formal SOC 2 Type II observation period is underway and the audited report is targeted for Q3 2026.
The underlying infrastructure (Microsoft Azure, Supabase) is independently SOC 2 Type II certified. Risk teams that need assurance before the report lands can request a controls walkthrough or a completed vendor security questionnaire from security@nrouter.ai.
How do you guarantee sub-millisecond gateway overhead during market volatility?
The nRouter gateway is written in Rust and executes routing decisions, token-bucket rate limits, and virtual key authentication entirely in memory using zero-allocation data structures. Added p50 latency is under 1 ms, ensuring that algorithmic research and real-time execution pipelines experience no perceptual lag.
How do we stop one trading desk from overspending shared allocations?
Give each desk its own team with an independent hard budget ceiling. A hard cap returns HTTP 402 the moment an execution would breach it.
There is no partial debit and no negative balance. Soft caps fire automated Slack or webhook notifications at 70%, 90%, and 100% capacity so desk heads can adjust limits before operations are impacted.
Can we keep customer data strictly within sovereign US financial jurisdictions?
Yes. United States data residency is standard.
Ingress endpoints, caching layers, and provider egress routes are strictly pinned to US-East and US-West sovereign enterprise zones. Prompts never transit overseas infrastructure or non-compliant cloud regions.
Do we ever have to handle or rotate provider API keys directly?
No. nRouter is a fully managed gateway. Your teams authenticate with nRouter virtual keys (sk-nrouter-…) only.
We manage all enterprise agreements, rate limit quotas, and credential rotations. Enterprise customers holding direct committed-spend provider agreements can configure hybrid routing across dedicated tenant capacity.
Explore industry solutions
Tailored AI gateway controls for every vertical
Financial services
Bring us your control matrix.
We will walk your risk, security, and finance teams through the audit trail, the residency map, and the budget model. Auditors welcome on the call.
SOC 2 Type II audit in progress (status as of August 2026) · GDPR-compliant · data residency on request