Portkey vs LiteLLM
Managed SaaS with compliance certs versus open-source self-hosted control: which routing tool fits your team.
Portkey and LiteLLM represent two different philosophies for AI model routing. Portkey is a managed SaaS platform with built-in compliance. LiteLLM is an open-source proxy you run on your own servers.
The choice comes down to a simple question: do you want to own the infrastructure or let a vendor handle it? Each answer brings different trade-offs in cost, control, compliance, and operational burden.
This guide compares both tools on features, data residency, compliance certs, pricing, and security. We are vendor-neutral. Layer3 Labs does not resell either tool.
Portkey vs. LiteLLM: Side-by-Side
| Dimension | Portkey | LiteLLM |
|---|---|---|
| Hosting model | Managed SaaS. Gateway component is open-source but full platform is hosted. | Self-hosted open-source (Apache 2.0). Enterprise tier available for managed hosting. |
| Compliance certs | SOC 2, GDPR. | None for the OSS version. Enterprise tier: verify on vendor site. |
| Data residency | Region options available. Verify specifics on vendor site. | Full control when self-hosted. Data stays in your infrastructure. |
| Guardrails | Built-in. Block or flag certain model outputs before they reach users. | Not built-in. Implement your own or use third-party guardrail tools. |
| Observability | Advanced analytics, cost tracking, latency monitoring, and request logging. | Built-in spend tracking. Integrations with Langfuse, Prometheus, and others. |
| Pricing | Usage-based platform fee. No per-token markup on model costs. | Free self-hosted. You pay provider token costs only. Enterprise tier has a fee. |
| Model catalog | 250+ models across providers. You configure which are available. | 100+ providers. You explicitly configure which models are available. |
| Security track record | SOC 2 audited. No published security incidents. | Supply chain incident in 2024. Patched. Post-mortem published. |
Quick verdict
If your team needs vendor-issued compliance certs, Portkey wins. SOC 2 and GDPR coverage are built in. LiteLLM's open-source version cannot provide that.
If your team needs full infrastructure control and wants zero vendor dependency, LiteLLM wins. Self-hosting means data never touches a third party's servers.
Many teams that start with LiteLLM eventually move to Portkey when their compliance requirements grow. The reverse is less common.
Deciding between Portkey and LiteLLM for your AI routing stack? We can map both to your compliance requirements and ops capacity in a short consultation.
Book a ConsultationCompliance: certs vs control
Portkey publishes SOC 2 and GDPR compliance. That means an independent auditor has verified their security controls. For teams that need to show a compliance cert to their own auditors, this is valuable.
LiteLLM does not publish compliance certs for its open-source version. Instead, it gives you full control over where data flows. You can meet any compliance requirement, but you must build and document the controls yourself.
The key question is what your auditor expects. If they want a vendor cert, Portkey delivers. If they want proof of infrastructure control, self-hosted LiteLLM delivers. Both are valid paths to compliance.
- Portkey: SOC 2, GDPR published. Vendor-issued certs.
- LiteLLM OSS: no vendor certs. You build and document your own controls.
- LiteLLM Enterprise: verify compliance features on vendor site.
- Ask your auditor which path they accept before choosing.
Features: guardrails and observability
Portkey's standout feature is built-in guardrails. You can set rules that block, flag, or modify model outputs before they reach your users. This is useful for preventing sensitive data leakage, enforcing content policies, or catching model hallucinations.
LiteLLM focuses on routing and spend tracking. It does not include built-in guardrails. If you need output filtering, you add it yourself with tools like Guardrails AI, NeMo Guardrails, or custom middleware.
On observability, both are capable. Portkey's dashboard is more polished out of the box. LiteLLM integrates with Langfuse, Prometheus, and other open-source observability tools, which gives more flexibility for teams that already run those stacks.
Pricing: SaaS fee vs infrastructure cost
Portkey charges a usage-based platform fee on top of your model provider costs. There is no per-token markup on the model cost itself. You pay for features like logging volume, guardrails, and team seats.
LiteLLM's open-source proxy is free. You pay only the underlying model provider token costs. Your infrastructure cost (servers, monitoring, engineer time) replaces Portkey's platform fee.
For small teams, Portkey is often cheaper because the platform fee is less than the cost of running and maintaining LiteLLM infrastructure. For large teams with existing DevOps capacity, LiteLLM is cheaper because the marginal cost of hosting is low.
- Portkey: platform fee + provider token costs
- LiteLLM: infrastructure costs + provider token costs
- Small teams: Portkey often wins on total cost
- Large teams with DevOps: LiteLLM often wins on total cost
Data residency: managed regions vs full control
Portkey offers data residency options within its managed infrastructure. Verify the specific regions and data handling on their site. Your data passes through Portkey's servers before reaching the model provider.
Self-hosted LiteLLM gives you full control. Data flows from your infrastructure directly to the model provider's endpoint. Nothing passes through a third party's servers.
For teams under ITAR or strict data sovereignty rules, self-hosted LiteLLM is the cleaner path. For teams under GDPR or SOC 2 with a managed-vendor approach, Portkey's data residency options may satisfy the requirement.
When each tool fits
Choose Portkey when you need compliance certs, guardrails, and managed observability without running your own infrastructure. It is the right pick for teams that want enterprise features without enterprise ops.
Choose LiteLLM when you need full infrastructure control, zero vendor dependency, or have strict data sovereignty requirements. It is the right pick for teams with DevOps capacity and security expertise.
Both support OpenAI-compatible API formats. If your requirements change, migration between them is manageable. Start with the tool that matches your current team capacity. For a step-by-step evaluation framework, see our AI routing vendor audit guide.
- Need vendor-issued SOC 2: Portkey
- Need full self-hosted control: LiteLLM
- Small team, no DevOps: Portkey
- Large team with infra expertise: LiteLLM
- Need built-in guardrails: Portkey
- Need maximum flexibility in tooling: LiteLLM
The Verdict
Portkey and LiteLLM are the two strongest options in AI model routing today. They represent a clean split: managed compliance versus self-hosted control.
If compliance certs and guardrails drive your decision, Portkey is the stronger pick. SOC 2 and GDPR coverage, built-in output filtering, and managed observability remove a lot of work from your plate.
If infrastructure control and zero vendor dependency drive your decision, LiteLLM is the stronger pick. Full self-hosting, open source, and no per-token markup give you maximum control over your AI routing stack.
Researched from primary vendor documentation and public regulator sources. Pricing and availability are accurate as of Jul 19, 2026 and can change — confirm current terms with each vendor before you buy.
Frequently Asked Questions
- It depends on your priorities. Portkey is better for compliance certs, guardrails, and managed ops. LiteLLM is better for full control, zero markup, and self-hosted data residency.
- Portkey offers a free tier with limited usage. The gateway component is open-source. The full platform with guardrails and analytics is paid. Verify current pricing on their site.
- You can self-host the gateway component. The full platform with guardrails, analytics, and team management is SaaS-only.
- Not built-in. LiteLLM focuses on routing and spend tracking. You add guardrails separately using tools like Guardrails AI, NeMo Guardrails, or custom middleware.
- LiteLLM has no per-token markup or platform fee. You pay only infra and provider costs. Portkey charges a usage-based platform fee. For small teams, Portkey can be cheaper overall because infra management is bundled.
- Yes. Both support OpenAI-compatible API formats. You need to reconfigure your model routing, set up guardrails, and update your app to point to the new endpoint.
- Portkey has SOC 2 and no published incidents. LiteLLM is open-source (auditable) but had a 2024 supply chain incident (patched). The answer depends on whether you trust vendor certs or your own security review.
- Both support 100+ providers. The catalogs are comparable. In both cases, you configure which models are available to your team.
Need help choosing between Portkey and LiteLLM?
Layer3 Labs helps teams pick the right AI routing tool based on compliance, security, and ops capacity. Book a free 30-minute routing audit.
Book Your Free AI Routing Audit