Envoy AI Gateway vs Kong AI Gateway
The question that decides it: Do you need a vendor who can sign a contract and an SLA, or a project you own outright with nothing gated behind a quote?
Our verdict
If you need documented SOC 2 Type 2 and GDPR posture, a 99.9% uptime SLA and content inspection in the request path, Kong AI Gateway, and expect to negotiate a price that is not published anywhere. If you already run Envoy Gateway on Kubernetes and want LLM and MCP routing as ordinary infrastructure with no vendor in the request path and nothing to buy, Envoy AI Gateway.
Why
Both of these are AI layers bolted onto a general-purpose gateway rather than standalone products, so the first question is who owns the layer underneath. Kong AI Gateway is a set of Kong Gateway plugins — AI Proxy and AI Proxy Advanced, minimum Kong Gateway 3.6, with AI MCP Proxy from 3.12 — on a Lua and OpenResty data plane whose repository carries 44,100 stars. Envoy AI Gateway is an extension server and ext_proc filter on top of Envoy Gateway, which its own goals document calls "an additive layer", with 1,987 stars on the AI Gateway repository itself. The star gap is a gap between a decade-old API gateway and a project that reached 1.0 in June 2026, not between two comparable communities.
The commercial shapes are opposites and the pricing is where it bites. Kong is open core with a Konnect SaaS control plane, customer-hosted or Kong-hosted data planes, and a flat per-gateway platform fee whose amount is not published; Enterprise is a custom annual quote, the free entry point is a 30-day Konnect trial, and the Plus tier caps the AI Gateway at five unique LLM models, which pushes any real multi-model deployment into an Enterprise conversation. Third-party reviews also report that the free Kong build lacks semantic caching, analytics and compliance features, so the Kong you can install for nothing is not the Kong being described. Envoy AI Gateway has no pricing page and no account: there is no sign-up or billing step anywhere in the install path, and the managed product built on the same data plane is Tetrate Agent Router Service, sold separately and appearing in the project's own documentation only as one more upstream provider you can route to.
That difference propagates straight into the compliance columns, and it is the reason this pair resolves cleanly. Kong publishes SOC 2 Type 2 and a GDPR DPA on its trust center, a 99.9% uptime SLA, a subprocessor list, and 30-day retention for Konnect analytics with seven days for audit logs. Envoy AI Gateway publishes none of that, and its record explains why rather than apologising: SOC 2 is not published because the project is software you run yourself, no DPA or controller-processor language exists because the project never receives your data, and no BAA is possible because there is no vendor service to sign one with. If your procurement process needs a counterparty, that is a disqualification and no amount of engineering quality fixes it. If your procurement process is your own cluster, it is the entire point.
On features, the asymmetry runs the other way, and it is stark. Envoy AI Gateway has no content guardrails at all — no PII, moderation, injection or custom-evaluator surface appears anywhere in its documentation — and no gateway-side cache; its prompt caching is passthrough of Anthropic-style cache_control breakpoints, minimum 1,024 cacheable tokens and at most four breakpoints, so any discount is the provider's. Kong ships the AI PII Sanitizer across roughly 20 categories against an anonymiser service you run yourself, regex prompt guarding, integrations with Azure Content Safety, AWS Bedrock Guardrails, Google Model Armor and Lakera, semantic caching, prompt templates and asynchronous batch endpoints, and it writes structured block-reason fields into an AI audit log built for exactly that. What Envoy gives back is 19 provider configurations against Kong's 17, an unusually wide endpoint surface for an infrastructure project, OpenTelemetry GenAI metrics you scrape yourself, and a v1beta1 control-plane API with an explicit promise not to break it. If you want the Apache-2.0 licence and a cache and guardrails, Higress is the entry to read instead.
Which one, concretely
Choose Envoy AI Gateway if
- Nothing may pass through a vendor, and there is no account, contract or billing relationship to review
- You already run Envoy Gateway on Kubernetes and want the AI layer to be more of the same
- You want a control-plane API committed to stability — v1beta1 CRDs with documented migrations
- You need MCP served from the same gateway with OAuth 2.0 plus PKCE and CEL-based tool authorization
Choose Kong AI Gateway if
- You need SOC 2 Type 2 and a GDPR DPA from a named counterparty, plus a 99.9% uptime SLA
- You need content inspection in the request path: PII sanitization, moderation and prompt guards
- You need a semantic cache, prompt templates or asynchronous batch endpoints from the gateway
- You already run Kong for API management and want AI traffic under the same plugins and ops tooling
What catches people out
- Envoy AI Gateway is not standalone: Envoy Gateway v1.7.0+ and Kubernetes v1.32+ are hard prerequisites, and token rate limiting or quotas additionally need Redis plus rate-limit configuration chosen at Envoy Gateway install time rather than afterwards.
- Envoy AI Gateway's QuotaPolicy is v1alpha1 only, outside the project's stability guarantee, and its serviceQuota field is accepted but not enforced end to end.
- Kong publishes no dollar figure for the AI Gateway, and the Plus tier caps it at five unique LLM models; third-party reviews report the free build lacks semantic caching, analytics and compliance features.
- Neither latency figure is a project-run measurement of your path. Envoy AI Gateway's roughly 2 ms is Tetrate's summary of a Broadcom VMware Cloud Foundation validation, and Broadcom's own post states no millisecond value; Kong's 12 ms and 8,200 RPS come from a third-party guide summarising Kong's own benchmark against a mock LLM, and that guide cautions that independent tests show much smaller gaps.
Side by side
Interpret these fields: How much does an LLM gateway lock you in? · LLM gateway compliance: SOC 2, HIPAA and evidence · How LLM gateway failover actually works
4 of 15 fields differ, marked with a dot. Every figure links to the vendor page it came from. Blank values read Not published rather than No — silence from a vendor is not a negative answer.
| Field | Envoy AI Gateway | Kong AI Gateway |
|---|---|---|
| Ease of leaving Derived score, higher is easier | 100/100 Easy to leave | 100/100 Easy to leave |
| What kind of product Category | Open source | Managed gateway |
| Who runs it Deployment model | Self-host only | Managed or self-host |
| Licence Licence | Apache-2.0 | Apache-2.0 |
| Model providers reachable Upstream providers | 16–19 | 17 |
| Markup on model prices Token markup | None | Not published |
| GitHub stars GitHub stars | 2,112 | 44,100 |
| Delay it adds Proxy overhead | 2 ms | 12 ms |
| Content guardrails Content guardrails | Not published | Yes |
| Strips personal data PII redaction | Not published | Yes |
| Similar-question caching Semantic cache | Not published | Yes |
| Prompt versioning Prompt management | Not published | Yes |
| Spending limits Budget controls | Yes | Not published |
| SOC 2 audited SOC 2 audited | Not published | Yes |
| GDPR commitments GDPR commitments | Not published | Yes |
| How long they keep it Default content retention (days) | Not published | 30 days |
for Envoy AI Gateway and for Kong AI Gateway. Want more fields, or a third option in the mix? Open these two in the full comparison tool.
Common questions
Can I buy support for Envoy AI Gateway?
Not from the project. It is Apache-2.0 with no vendor-priced tier, no pricing page and no account, and its only artifacts are Helm charts, container images and CLI binaries. The community meets weekly on the Envoy Slack. A managed product on the same data plane is sold separately by Tetrate as Tetrate Agent Router Service, which the project treats as just another upstream provider you can route to.
How much does Kong AI Gateway cost?
Kong does not publish a figure. Konnect Plus is a flat per-gateway monthly platform fee with no amount stated, billed monthly in arrears, and Enterprise is a custom annual quote whose duration sits in the order form. There is a 30-day Konnect trial with enterprise functionality, and Kong Gateway core is Apache-2.0 and free to self-host. Plus also caps the AI Gateway at five unique LLM models.
Does Envoy AI Gateway have guardrails?
No. There is no PII redaction, moderation, injection detection or custom evaluator anywhere in its documentation, and no guardrail feature means no documented fail-open or fail-closed behaviour either. What it has instead is infrastructure-grade control: client auth delegated to Envoy Gateway SecurityPolicy, route-scoped model allowlisting, and CEL-gated MCP tool authorization. Kong is the side of this pair with request-path content inspection.