Security · policy on the rack

Where a request may go is gateway policy.

Set it once for the whole team. Agents hold scoped gateway keys. Provider keys attach at the bay and never reach them.

Lockout · trunk group ZDR
ALLOWLIST · TEAM POLICY hosted A ZDR · open your key BYOK · open local GPU never leaves blocked not on list

Zero Data Retention routing

Route only to providers under ZDR agreements. Enforce it team-wide or per request. A request that would leave the allowlist never leaves the bay.

No training on your data

Route only to providers that will not train on customer data. Configurable per request so a research lane and a production lane can differ.

Provider allowlist

Restrict your team to approved providers. Enforced on every request, no code changes. Local-only scopes pin sensitive work to your GPUs.

Keys never leave the gateway

Agents hold scoped gateway keys (sk-rlb-). Provider keys attach at the gateway. Revoke one caller without rotating the rest.

Org controls

Hard stops

Requests stop at the cap: per key, per team, or org-wide. Nothing silently overruns. A paused key says so in the dashboard.

Roles

Owner, admin, member, and viewer, built in. Finer grains are an enterprise conversation — write contact@routerlab.buzz.

Request logs

Search and filter every request, and open one to see how it routed and what it cost. The same numbers over the Usage API.

Open source posture

Run the gateway yourself if the hosted bay is not the right trunk. Same API shape either way.