One table, mapped to the live Smartflow dashboard. Compared with Portkey (Prisma AIRS), LiteLLM, Helicone, and Kong AI Gateway. Yes means it ships. Partial means it exists, narrower. A dash means it isn't in the product.
Built for compliance, risk, and finance teams that need to stop a call, not only log it. Same ruleset on the laptop and the gateway. Evidence a third party can verify, in object lock you own. MCP tools and agents on the same path. Cost becomes a cap.
Shield hooks Cursor, Claude Code, and Copilot. High-severity asks; Critical denies. Policy applies to the shell, not only the API call.
ID.me IAL2 / Nafath on risky actions. Agent credentials (AIDA) on egress. Who approved this survives the audit.
HMAC + prev_hash, RFC 3161 time, WORM in your object lock. MIT verifier. Exit 0 is the answer an examiner wants.
Repeat hits the cache. Proven classes go to the local model. Novel or high-stakes stays on the teacher. FinOps can cap, not only chart.
Paste an acceptable-use doc, get checkable rules, bind them to a group or key. MCP trust registry on the tool call.
| Dashboard · capability | Smartflow | Portkey / Prisma AIRS | LiteLLM | Helicone | Kong AI GW |
|---|---|---|---|---|---|
| Policies | |||||
| Inline policy by key, group, team, or modelAll Policies | Yes | Yes | Partial | — | Partial |
| Visual policy builderPolicy Builder | Yes | Partial | — | — | — |
| Identity gates on risky actionsIdentity GatesID.me IAL2 / Nafath step-up | Yes | — | — | — | — |
| Frameworks by directory groupFrameworksHIPAA, GDPR, PCI attach from AD | Yes | Partial | — | — | — |
| Inline PII / secret / regulated-pattern detectCompliance Pipeline | Yes | Yes | Partial | — | Partial |
| Reversible PII tokenizationCompliance Pipeline | Yes | Partial | — | — | — |
| HMAC chain + RFC 3161 + WORM in your object lockAudit & Evidence | Yes | — | — | — | — |
| Independent MIT chain verifierAudit & EvidenceThey build it. Exit 0. They don't have to trust us. | Yes | — | — | — | — |
| Policy doc → checkable rulesAtomizer | Yes | — | — | — | — |
| EU AI Act article-level evidence binderFrameworks / Audit | Yes | — | — | — | — |
| Closed-loop GRC (finding in, closure back)Audit · ServiceNow / Archer / OneTrust | Yes | Partial | — | — | Partial |
| In-process red-team harnessRed-teamScores your traffic. Suggests rules. Nothing leaves the box. | Yes | Partial | — | — | — |
| Routing · local models · playground | |||||
| Drop-in OpenAI + native AnthropicRouting | Yes | Yes | Yes | Partial | Partial |
| Fallback chainsRouting | Yes | Yes | Yes | — | Partial |
| Policy / identity-driven routeRouting | Yes | Partial | Partial | — | Partial |
| Lowest-cost / effort routerRoutingEasy turns cheap. Hard turns stay on the teacher. | Yes | Partial | Partial | — | — |
| Local runtimes as first-class targetsLocal modelsvLLM, Ollama, LM Studio, llama.cpp, NIM | Yes | Partial | Yes | — | Partial |
| Cache → local specialist → frontier as teacherLocal models · Routing | Yes | — | — | — | — |
| Virtual keys + model allow-listsRouting · Auth | Yes | Yes | Partial | — | — |
| Provider catalogue sizeRouting | Partial | Yes · 250+ | Yes · 100+ | Partial | Partial |
| Playground against live routesPlayground | Yes | Yes | Partial | Yes | — |
| Prompt library / versioning studioPrompts | Partial | Yes | Partial | Partial | — |
| Traces · hallucination · cache | |||||
| Per-request trace with cost + risk tierTraces | Yes | Yes | Partial | Yes | Partial |
| HHEM hallucination scoring on live trafficHallucination | Yes | — | — | — | — |
| Semantic cache without a sidecar vector DBCaching | Yes | Partial | — | Partial | Partial |
| In-flight compression + faithfulness checkCaching | Yes | — | — | — | — |
| Provider prompt-cache injectionCaching | Yes | Yes | Partial | Partial | — |
| MCP discovery + tool-call cacheCaching · MCP | Yes | — | — | — | — |
| Trajectory cache for multi-step agent tasksCaching · Agents | Yes | — | — | — | — |
| FinOps · sustainability | |||||
| Spend by provider, model, user, groupFinOps | Yes | Yes | Yes | Yes | Partial |
| Budget breach → cap or rerouteFinOpsEnforced on the call, not an email after the money's gone. | Yes | Partial | Partial | — | Partial |
| Billed vs metered bypass reconciliationFinOps | Yes | — | — | — | — |
| Spend anomaly → draft policyFinOps | Yes | — | — | — | — |
| Cache / token savings next to the billFinOps | Yes | Partial | Partial | Partial | — |
| Energy / CO₂ / water from the same tracesSustainabilityIncluding silent same-provider downgrade. | Yes | — | — | — | — |
| Data & sovereignty | |||||
| VPC / airgap deployData & Sovereignty | Yes | Yes | Yes | Partial | Yes |
| Region + FIPS + minimisation posture viewData & Sovereignty | Yes | Partial | — | — | Partial |
| WORM evidence in the customer's object lockData & Sovereignty | Yes | — | — | — | — |
| First-party Box / SharePoint connectorsData & Sovereignty | Yes | — | — | — | — |
| MCP · agents | |||||
| MCP trust registry (unsigned servers don't run)MCP | Yes | Partial | — | — | Partial |
| AD-gated tools by groupMCP | Yes | — | — | — | — |
| Shield on destructive tool / shell callsMCP · Shield | Yes | — | — | — | — |
| Per-server cost attributionMCP · FinOps | Yes | — | — | — | — |
| A2A gateway + Agent CardsAgents | Yes | — | — | — | — |
| AIDA agent credentials + signed egressAgents · Identity | Yes | — | — | — | — |
| Action-risk tiers (T1–T3) + human approvalAgents | Yes | — | — | — | — |
| Identity · Auth & SSO · Shield | |||||
| Virtual keys (provider secrets stay in the gateway)Identity · Auth & SSO | Yes | Yes | Partial | — | Partial |
| Entra / Okta SSO with group → budget / policyAuth & SSO | Yes | Partial | Partial | Partial | Yes |
| Verified-identity step-up on high-riskIdentity Gates | Yes | — | — | — | — |
| Device / coding-agent identity at interceptIdentity · Shield | Yes | — | — | — | — |
| Laptop agent hooks (ask vs deny)Shield 1.6.2Cursor beforeShellExecution. Approval asks. Block denies. | Yes | — | — | — | — |
| Insurance-producer licensing (NIPR / PDB)Identity · pre-bind | Yes | — | — | — | — |