Smartflow is an on-premises AI governance control plane. Portkey is an AI gateway and observability platform, acquired by Palo Alto Networks in May 2026 and now positioned as the Prisma AIRS AI Gateway. Both govern enterprise AI traffic. They differ on where the control plane lives and on what the governance record is designed to prove.
What changed in 2026
Palo Alto Networks announced its intent to acquire Portkey in April 2026 and completed the acquisition on 29 May 2026. Portkey's own site now leads with "Portkey is now PRISMA AIRS AI Gateway." Anyone evaluating Portkey in late 2026 is evaluating a Palo Alto Networks product, with the roadmap, commercial model and platform dependencies that implies. That is not a criticism — for an organization already standardized on Palo Alto it may be the deciding advantage — but it belongs at the top of the page rather than in a footnote.
Feature Comparison
| Capability | Smartflow | Portkey (Prisma AIRS AI Gateway) |
|---|---|---|
| Deployment | On-premises, air-gapped, Kubernetes-native. | Cloud SaaS on the Developer and Production tiers. Enterprise adds private cloud and VPC hosting. The open-source gateway is MIT-licensed and self-hostable. |
| Control plane location | Customer environment. Configured with local embeddings and a local model, policy, cache and audit make no call to us or anyone else. | Documented hybrid model: data plane in the customer VPC, control plane in Portkey's VPC. Configuration syncs on a heartbeat and the gateway operates on cached config between syncs. |
| Log residency | Customer-controlled throughout. | Configurable. Logs to the customer's blob store, or encrypted to the Portkey log store, set by LOG_STORE. |
| Semantic caching | MetaCache resolves a lookup in four phases, first hit wins: intent signature, intent near-miss, exact key, then a VectorLite BERT semantic match. Hit rates are workload-dependent. | Simple exact-match and semantic caching with a default cosine threshold of 0.95. Semantic matching is limited to requests under 8,191 tokens and four messages or fewer. |
| Agent identity | AIDA cryptographic agent credentials, scoped and revocable, with the audit record naming the person who authorized the agent. | Governed through workspaces, keys, RBAC and an Agent Registry. A distinct cryptographic agent credential is not a documented feature. |
| MCP governance | MCP JSON-RPC gateway with tool caching. | MCP Gateway and MCP Registry with OAuth 2.1, client-credentials and header auth, and per-tool enable and disable. |
| Guardrails | Visual policy editor. PII, topic restriction, jailbreak detection, output moderation. | Twenty-plus deterministic guardrails with deny, async, sequential, feedback and fallback actions. PII redaction is an enterprise addition over the open-source gateway. |
| Audit log retention | Customer-controlled. No vendor-imposed ceiling. | Documented as indefinite on the enterprise plan. Request-log retention is tiered: three days on Developer, thirty on Production, configurable on Enterprise. |
| Regulatory evidence | Examination packages and model inventory mapped to FINRA 3110, HIPAA, SOX and the EU AI Act. | Vendor certifications published (SOC 2, ISO 27001, HIPAA, GDPR) with custom BAAs at the enterprise tier. |
One correction carried from an earlier version of this page: Portkey's audit log retention on the enterprise plan is documented as indefinite, and the thirty-day figure this page once cited applies to request logs on the Production tier. Portkey's own documentation and pricing page also disagree on whether semantic caching is Production or Enterprise; both readings are cited below.
The control plane question
The substantive architectural difference is not cloud versus on-premises — Portkey's enterprise deployment does put the data plane in the customer VPC, and prompt content and responses stay inside the customer network by design. It is where the control plane sits.
In Portkey's documented hybrid architecture the dashboard, routing configuration and provider integrations live in Portkey's VPC, with configuration deltas fetched on roughly a one-minute heartbeat. Portkey is explicit that this removes runtime dependency: the gateway keeps serving on cached configuration between syncs. That is sound engineering and it answers the availability question.
It does not answer the governance question, which is narrower. If the authoritative record of which policy was in force at 14:07 on a given Tuesday lives in a vendor's environment, then reconstructing an enforcement decision for an examiner is a request to a third party rather than a query against your own system. For most organizations that is an acceptable trade. For a bank assembling a supervision file, or a defense program where the configuration itself is controlled information, it is the trade they cannot make. Smartflow keeps the decision point and its record inside the perimeter for that reason.
Caching, and the threshold as a policy setting
Both products ship semantic caching, and the mechanism is the same in outline: embed the prompt, compare against cached vectors, serve the stored response above a similarity threshold. Portkey documents a default cosine threshold of 0.95 and constrains semantic matching to requests under 8,191 tokens with four messages or fewer.
The constraint worth understanding is not the number. It is that the threshold is a governance setting rather than a tuning detail. Set it loose and the system answers a question nobody asked; set it tight and it degrades to exact match. In a regulated environment the threshold, and any change to it, belongs in the same versioned policy record as everything else — which is how Smartflow treats it.
Agent and MCP governance
Portkey shipped an MCP Gateway in January 2026 and an Agent Gateway in beta in April 2026, with a registry, OAuth 2.1 upstream auth, per-tool enable and disable, and guardrails applied to tool calls. It is a serious implementation and the comparison here is not one of presence versus absence.
The difference is the principal. Portkey governs agents through the workspace, key and RBAC model that governs everything else. AIDA makes the agent itself the principal, with a credential that can be scoped and revoked without touching the human who launched it. Where that matters is the audit record: an agent acting on a borrowed key is indistinguishable in the log from the person who owns it, and an information barrier cannot be enforced against a principal the system cannot name.
Where Portkey excels
Portkey has strong developer experience, mature observability, good prompt management, a genuinely capable free tier and an MIT-licensed open-source gateway that routes to a very large provider catalogue. Its guardrail enforcement model is one of the more thoughtful in the category — the distinction between deny, async, sequential and fallback actions, with distinct HTTP status codes for each outcome, is the kind of design detail that only shows up after production use.
The Palo Alto acquisition adds weight rather than removing it. For an enterprise already running Prisma, consolidating the AI gateway into the same platform is a real advantage in procurement, support and integration, and it is the scenario in which Portkey is the straightforward answer.
When to choose Smartflow
- The control plane must sit inside the perimeter: financial services, healthcare, defense, or any environment where the governance configuration is itself controlled
- Examination evidence: automated packages for FINRA 3110, FFIEC and model inventory, generated from runtime records
- Agent identity: a credential held by the agent rather than inherited from a human
- Vendor independence: where consolidating onto a single security platform is a constraint rather than a benefit
Migrating from Portkey
Portkey's virtual keys and Smartflow's provider credentials serve the same purpose, so the provider layer transfers cleanly. The two areas that need design work are guardrail semantics — Portkey's deny, async and fallback actions map onto Smartflow policy outcomes but not mechanically — and log history, which does not migrate. If retention beyond the Production tier's thirty days matters for a period you have already run, export before you cut over.
Common questions
Is Portkey still an independent company? No. Palo Alto Networks completed the acquisition on 29 May 2026. Portkey's capabilities are being integrated into Prisma AIRS.
Can Portkey be self-hosted? Yes. The gateway is MIT-licensed and self-hostable, and the enterprise offering documents private cloud and VPC hosting with the data plane in the customer environment. The control plane remains in Portkey's VPC in the documented hybrid architecture.
Does Portkey support semantic caching? Yes, with a default cosine similarity threshold of 0.95. Which tier it requires is unclear: the documentation says select enterprise plans, the pricing page lists it under Production.
How long does Portkey retain logs? Audit logs are documented as retained indefinitely on the enterprise plan. Request logs are three days on Developer, thirty on Production, and configurable on Enterprise.
Related reading
Enterprise AI gateway guide · Trust Fabric architecture · AI sovereignty · Agent governance · All comparisons · AI guardrails · Model allowlist and denylist · Agentic AI · Tamper-evident audit log
Verified against each vendor’s published documentation in September 2026. Vendor capabilities change. If something here is out of date, tell us and we will correct it.
Portkey sources: portkey.ai, portkey.ai/pricing, portkey.ai/for/enterprise, portkey.ai/docs (cache-simple-and-semantic, guardrails, mcp-gateway/mcp-registry, enterprise-offering, enterprise-offering/audit-logs, self-hosting/hybrid-deployments/architecture), portkey.ai/blog (introducing-the-mcp-gateway, agent-gateway), github.com/Portkey-AI/gateway, paloaltonetworks.com press releases dated 30 April 2026 and 29 May 2026.
Put this in the path of your own agents.
Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.
Request a Demo Read the docs