Financial services

Every dollar of inference
maps to a desk.

An append-only audit trail your examiners can read, PII redaction on every request, and per-desk budgets settled from the provider's own response — exact, not estimated.

No BYOK · negative balances blocked at the database · flat 4% platform fee

  • Append-onlyAudit trailEvery key, budget, guardrail change
  • 3Budget scopesOrg · desk/team · per-key
  • InlineGuardrail checksPII redaction runs in-process
  • 4%Platform feeOpenRouter's published rate is 5.5% (verified September 2026)
Cost governance

Exact cost. Atomic accounting. No overruns.

In a regulated firm, unattributed spend is a finding waiting to happen. Every request reserves credits, forwards, and settles against the provider-reported cost. A failed request releases the reservation. A desk that hits a hard cap gets a clean 402; the database refuses to write a negative balance.

  • Per-desk teams with independent hard and soft budgets
  • Costs settled from the provider response — exact, not inferred
  • Soft-cap alerts at 70 / 90 / 100% via Slack or webhook
  • Per-key spend breakdown for chargeback and cost allocation
  • Append-only audit trail with actor, IP, and diff: CSV/JSON export for your SIEM

Desk — markets research

Soft cap at 90%

Slack alert fired · desk lead sees it before finance does

Desk — client support

Within budget

PII redaction in front of every customer-facing request

Ledger

Negative balance: impossible

Reserve + settle · 402 on a tripped hard cap · no partial debit

Financial Enterprise Architecture

Regulated Request Pipeline: From Trading Desk to Upstream Model

Every financial query flows through an in-memory Rust gate chain designed to execute sub-millisecond policy evaluation, atomic credit holds, and PII masking before touching any external model API.

Enterprise request lifecycle: client → gateway → guardrail filter → smart router → model provider

  1. Trading / Analyst Client

    POST /v1/chat/completions

    Market research, credit analysis, algorithmic summarization.

  2. Gateway Preflight & Auth

    :4000 · In-memory RLS

    Virtual key auth, desk budget verification, token bucket rate limit.

  3. Guardrail Filter

    FINRA / PII Redaction

    Account numbers, SSNs, credit cards redacted in-process.

  4. Smart Router & Optimizer

    Tier Routing · Latency

    40–70% cost reduction by steering light tasks to fast models.

  5. Model Providers

    OpenAI · Anthropic · Bedrock

    99.99% multi-provider failover; exact list price settlement.

40–70%

Cost Reduction

Via smart tier routing

99.99%

Uptime SLA

Cross-cloud failover

< 1 ms

Gateway Overhead

In-memory p50 routing

SEC 17a-4

Audit Trail

Append-only WORM logs

Stage 01 — Ingress & Desk Isolation

Virtual Key Authentication & Row Level Security

Requests arrive at the Rust gateway with an sk-nrouter-desk-... virtual key. In-memory tenant lookup validates desk budgets, team memberships, and per-minute token buckets before any processing begins.

Database Row Level Security (RLS) guarantees absolute cross-tenant and cross-desk data isolation.

Stage 02 — Inline Compliance Preflight

Financial PII Redaction & Prompt Injection Defense

In-process zero-overhead pattern and AST analyzers scan input payloads for sensitive financial identifiers: IBAN, ABA routing, credit card numbers, SSNs, and executive contact details. Malicious instruction overrides and prompt injection vectors are refused with HTTP 400 before egress.

Stage 03 — Cost & Latency Optimization

Smart Tier Routing (40–70% Cost Reduction)

Routine financial extraction and tabular summarization queries are dynamically steered to high-speed tier-1 models, while complex valuation modeling routes to frontier reasoning models. Latency-optimized routing selects the healthiest endpoint with lowest recent p95 latency.

Stage 04 — High-Availability Execution

Cross-Cloud Multi-Provider Failover (99.99% SLA)

If an upstream provider returns 429, 503, or exceeds timeout budgets during market open, nRouter transparently retries across alternative cloud deployments (AWS Bedrock, Azure OpenAI, Google Cloud Vertex) in under 50ms without dropping client connections.

Stage 05 — Immutable Accounting & Audit

FINRA / SEC Rule 17a-4 Compliant Audit Logging

Inference completes and spend is settled atomically at the exact provider list price with zero token markup. Every prompt event, actor, IP address, latency measurement, and cryptographic hash is committed to an append-only, tamper-evident WORM audit log exportable to Splunk, Datadog, or S3.

Production Implementation

Drop-In SDK Integration with Desk Scope & Compliance Headers

Replace OpenAI or Anthropic API endpoints in minutes. Pass desk identifiers, audit parameters, and automated fallback chains using standard HTTP headers.

Installpip install openai
1# Cache: enabled (org default). Pass nrouter_cache: false to skip.
2from openai import OpenAI
3import os
4
5client = OpenAI(
6 api_key=os.environ["NROUTER_API_KEY"],
7 base_url="https://api.nrouter.ai/v1",
8)
9
10response = client.chat.completions.create(
11 model="gpt-5.4-mini",
12 temperature=1,
13 max_completion_tokens=1024,
14 messages=[
15 {"role": "user", "content": "Hello! What models do you support?"},
16 ],
17 extra_body={
18 # "nrouter_cache": False, # Uncomment to skip cache
19 },
20)
21
22print(response.choices[0].message.content)

Header Configuration & Policy Spec

# Production Financial Services Configuration (OpenAI Python SDK)
from openai import OpenAI

client = OpenAI(
    base_url="https://api.nrouter.ai/v1",
    api_key="sk-nrouter-desk-equities-live-0941",
    default_headers={
        "x-nr-budget-scope": "desk-equities-trading",
        "x-nr-guardrails": "pii-mask,secret-detect,prompt-injection",
        "x-nr-audit-compliance": "sec-17a4",
        "x-nr-residency": "us"
    }
)

response = client.chat.completions.create(
    model="nrouter/auto",  # Automatically resolves cost/latency tier
    messages=[
        {"role": "system", "content": "Extract SEC Form 10-K non-GAAP reconciliation metrics."},
        {"role": "user", "content": "Extract EBITDA adjustments from the attached earnings release text."}
    ],
    extra_body={
        "fallback_models": ["anthropic/claude-3-5-sonnet", "openai/gpt-4o"],
        "max_cost_limit": "0.05"
    }
)

Pre-Egress Credit Hold & Settlement

Every inference request reserves estimated tokens in an atomic database transaction before provider egress. If the provider fails or rejects the call, 100% of held funds are immediately released with $0 debit.

FINRA Rule 4511 & SEC 17a-4 Logging

Every model interaction records timestamped sha256 payload hashes, user identifiers, caller IP, and exact token micro-costs into tamper-evident append-only storage.

Hard Desk Budget Enforcement (HTTP 402)

The database rejects negative balances at the schema level. When an equity or fixed-income desk reaches its budget cap, further inference halts immediately with clean HTTP 402 errors.

Also on every plan

Core enterprise capabilities on every plan

PII redaction before a prompt leaves the desk

Account numbers, SSNs, card numbers, emails, and phone numbers redacted inline by the built-in scanner.

Failover for trading-hours workloads

Fallback chains retry on a backup model when a provider degrades. 99.9% uptime SLA on every tier.

Versioned prompt templates

Compliance-approved prompts ship as server-side templates, with every change captured in the audit trail.

Compliance — honest status

What we can prove, and what is in progress.

  • SOC 2 Type II — in progress. SOC 2-aligned controls operate today; the audit is in progress as of August 2026. We do not claim “certified” until it is signed.
  • GDPR — compliant. A Data Processing Addendum is published and signable; subprocessors are covered by EU Standard Contractual Clauses.
  • PCI scope — minimal. nRouter never touches cardholder data; payments run through Stripe, a PCI DSS Level 1 provider.

Running a vendor security review? security@nrouter.ai will send a completed questionnaire and walk your risk team through the controls.

Finance questions, answered

How does nRouter support SEC Rule 17a-4 and FINRA Rule 4511 recordkeeping?

nRouter produces an immutable, append-only audit trail for every LLM interaction. Each entry records the virtual key id, desk identity, UTC timestamp, prompt payload hash, model version, exact token counts, and billed micro-cost.

Audit rows cannot be modified or truncated through application interfaces and can be archived to WORM (Write Once, Read Many) compliant object storage for regulatory examiners.

Is nRouter SOC 2 certified?

Not yet, and we will not say "certified" until the report is signed. nRouter operates SOC 2-aligned controls today: encryption, access control, change management, audit logging, and tenant isolation. As of August 2026, a formal SOC 2 Type II observation period is underway and the audited report is targeted for Q3 2026.

The underlying infrastructure (Microsoft Azure, Supabase) is independently SOC 2 Type II certified. Risk teams that need assurance before the report lands can request a controls walkthrough or a completed vendor security questionnaire from security@nrouter.ai.

How do you guarantee sub-millisecond gateway overhead during market volatility?

The nRouter gateway is written in Rust and executes routing decisions, token-bucket rate limits, and virtual key authentication entirely in memory using zero-allocation data structures. Added p50 latency is under 1 ms, ensuring that algorithmic research and real-time execution pipelines experience no perceptual lag.

How do we stop one trading desk from overspending shared allocations?

Give each desk its own team with an independent hard budget ceiling. A hard cap returns HTTP 402 the moment an execution would breach it.

There is no partial debit and no negative balance. Soft caps fire automated Slack or webhook notifications at 70%, 90%, and 100% capacity so desk heads can adjust limits before operations are impacted.

Can we keep customer data strictly within sovereign US financial jurisdictions?

Yes. United States data residency is standard.

Ingress endpoints, caching layers, and provider egress routes are strictly pinned to US-East and US-West sovereign enterprise zones. Prompts never transit overseas infrastructure or non-compliant cloud regions.

Do we ever have to handle or rotate provider API keys directly?

No. nRouter is a fully managed gateway. Your teams authenticate with nRouter virtual keys (sk-nrouter-…) only.

We manage all enterprise agreements, rate limit quotas, and credential rotations. Enterprise customers holding direct committed-spend provider agreements can configure hybrid routing across dedicated tenant capacity.

Explore industry solutions

Tailored AI gateway controls for every vertical

Financial services

Bring us your control matrix.

We will walk your risk, security, and finance teams through the audit trail, the residency map, and the budget model. Auditors welcome on the call.

SOC 2 Type II audit in progress (status as of August 2026) · GDPR-compliant · data residency on request