Feature matrix · 1.0

What the dashboard ships, vs the rest of the room

One table, mapped to the live Smartflow dashboard. Compared with Portkey (Prisma AIRS), LiteLLM, Helicone, and Kong AI Gateway. Yes means it ships. Partial means it exists, narrower. A dash means it isn't in the product.

Dashboard surfaces Same ruleset on the laptop
Primary advantages

Built for compliance, risk, and finance teams that need to stop a call, not only log it. Same ruleset on the laptop and the gateway. Evidence a third party can verify, in object lock you own. MCP tools and agents on the same path. Cost becomes a cap.

01 · Laptop + gateway

Same ruleset on the machine that types

Shield hooks Cursor, Claude Code, and Copilot. High-severity asks; Critical denies. Policy applies to the shell, not only the API call.

02 · Named human

Step-up identity, not just SSO

ID.me IAL2 / Nafath on risky actions. Agent credentials (AIDA) on egress. Who approved this survives the audit.

03 · Evidence

A chain you can verify without us

HMAC + prev_hash, RFC 3161 time, WORM in your object lock. MIT verifier. Exit 0 is the answer an examiner wants.

04 · Cost path

Cache, local specialist, then frontier

Repeat hits the cache. Proven classes go to the local model. Novel or high-stakes stays on the teacher. FinOps can cap, not only chart.

05 · Policy from a PDF

Atomizer + inline enforce

Paste an acceptable-use doc, get checkable rules, bind them to a group or key. MCP trust registry on the tool call.

How to read: Yes ships today Partial exists, narrower or via a plugin not in product Teal edge marks a capability unique to Smartflow in this set Hover a Partial cell for the note. Rows follow the dashboard nav.
Dashboard · capability Smartflow Portkey / Prisma AIRS LiteLLM Helicone Kong AI GW
Policies
Inline policy by key, group, team, or modelAll Policies Yes Yes Partial Partial
Visual policy builderPolicy Builder Yes Partial
Identity gates on risky actionsIdentity GatesID.me IAL2 / Nafath step-up Yes
Frameworks by directory groupFrameworksHIPAA, GDPR, PCI attach from AD Yes Partial
Inline PII / secret / regulated-pattern detectCompliance Pipeline Yes Yes Partial Partial
Reversible PII tokenizationCompliance Pipeline Yes Partial
HMAC chain + RFC 3161 + WORM in your object lockAudit & Evidence Yes
Independent MIT chain verifierAudit & EvidenceThey build it. Exit 0. They don't have to trust us. Yes
Policy doc → checkable rulesAtomizer Yes
EU AI Act article-level evidence binderFrameworks / Audit Yes
Closed-loop GRC (finding in, closure back)Audit · ServiceNow / Archer / OneTrust Yes Partial Partial
In-process red-team harnessRed-teamScores your traffic. Suggests rules. Nothing leaves the box. Yes Partial
Routing · local models · playground
Drop-in OpenAI + native AnthropicRouting Yes Yes Yes Partial Partial
Fallback chainsRouting Yes Yes Yes Partial
Policy / identity-driven routeRouting Yes Partial Partial Partial
Lowest-cost / effort routerRoutingEasy turns cheap. Hard turns stay on the teacher. Yes Partial Partial
Local runtimes as first-class targetsLocal modelsvLLM, Ollama, LM Studio, llama.cpp, NIM Yes Partial Yes Partial
Cache → local specialist → frontier as teacherLocal models · Routing Yes
Virtual keys + model allow-listsRouting · Auth Yes Yes Partial
Provider catalogue sizeRouting Partial Yes · 250+ Yes · 100+ Partial Partial
Playground against live routesPlayground Yes Yes Partial Yes
Prompt library / versioning studioPrompts Partial Yes Partial Partial
Traces · hallucination · cache
Per-request trace with cost + risk tierTraces Yes Yes Partial Yes Partial
HHEM hallucination scoring on live trafficHallucination Yes
Semantic cache without a sidecar vector DBCaching Yes Partial Partial Partial
In-flight compression + faithfulness checkCaching Yes
Provider prompt-cache injectionCaching Yes Yes Partial Partial
MCP discovery + tool-call cacheCaching · MCP Yes
Trajectory cache for multi-step agent tasksCaching · Agents Yes
FinOps · sustainability
Spend by provider, model, user, groupFinOps Yes Yes Yes Yes Partial
Budget breach → cap or rerouteFinOpsEnforced on the call, not an email after the money's gone. Yes Partial Partial Partial
Billed vs metered bypass reconciliationFinOps Yes
Spend anomaly → draft policyFinOps Yes
Cache / token savings next to the billFinOps Yes Partial Partial Partial
Energy / CO₂ / water from the same tracesSustainabilityIncluding silent same-provider downgrade. Yes
Data & sovereignty
VPC / airgap deployData & Sovereignty Yes Yes Yes Partial Yes
Region + FIPS + minimisation posture viewData & Sovereignty Yes Partial Partial
WORM evidence in the customer's object lockData & Sovereignty Yes
First-party Box / SharePoint connectorsData & Sovereignty Yes
MCP · agents
MCP trust registry (unsigned servers don't run)MCP Yes Partial Partial
AD-gated tools by groupMCP Yes
Shield on destructive tool / shell callsMCP · Shield Yes
Per-server cost attributionMCP · FinOps Yes
A2A gateway + Agent CardsAgents Yes
AIDA agent credentials + signed egressAgents · Identity Yes
Action-risk tiers (T1–T3) + human approvalAgents Yes
Identity · Auth & SSO · Shield
Virtual keys (provider secrets stay in the gateway)Identity · Auth & SSO Yes Yes Partial Partial
Entra / Okta SSO with group → budget / policyAuth & SSO Yes Partial Partial Partial Yes
Verified-identity step-up on high-riskIdentity Gates Yes
Device / coding-agent identity at interceptIdentity · Shield Yes
Laptop agent hooks (ask vs deny)Shield 1.6.2Cursor beforeShellExecution. Approval asks. Block denies. Yes
Insurance-producer licensing (NIPR / PDB)Identity · pre-bind Yes
Independent chain verifier: audit-verifier (MIT). Feature guide.