LLM Gateway vs Bifrost

The question that decides it: Is a permissive licence with no hosted escape hatch worth more to you than a copyleft one that comes with a managed service?

Our verdict

You want a permissive licence you can embed without legal review, or you need an air-gapped install: Bifrost, Apache-2.0 and self-host only. You want to start on someone else's infrastructure and move in-house later without changing products: LLM Gateway, provided AGPL-3.0 is acceptable and you accept 5% on hosted credit.

Why

Both are free to run and neither takes a cut of your tokens when self-hosted: both record a zero token markup and no seat fee. So this is not a pricing comparison, it is a licence and deployment comparison, and those are the two fields most likely to be decided by someone other than you.

Bifrost is Apache-2.0 and self-host only — there is no vendor-hosted build to fall back on. That is a real constraint and also the source of its strongest property: it is one of only four products here that supports air-gapped installation, which matters if the network the gateway sits on has no route to the internet at all. Permissive licensing means you can modify and embed it without the obligations copyleft creates. Its published reach is 20 to 23 upstream providers, narrower than LLM Gateway's, and it does not publish a total model count.

LLM Gateway can be run either way, which is its main structural advantage: the same product covers a hosted trial and an eventual in-house deployment, so the migration is a deployment change rather than a vendor change. The hosted side costs 5% on credit purchases; the self-hosted side costs nothing. It also publishes a SOC 2 report, which Bifrost does not, and states 200 models across 40 upstream providers. The cost is the licence: AGPL-3.0 obligations attach if you modify it and convey it onward, which is a conversation Apache-2.0 never starts.

On data handling the two answer differently rather than better or worse. Bifrost makes logging configurable with a documented off switch and states 365-day retention, but publishes no zero-data-retention position and does not say whether it trains on customer data — both of which are moot when you are the one running it. LLM Gateway logs metadata only, allows logging off, states 30-day retention and states it does not train on customer data, which is the more complete answer but also the answer a hosted service is obliged to give.

Which one, concretely

Choose LLM Gateway if

  • You want one product that covers both a hosted start and a later in-house move
  • You need a published SOC 2 report
  • You want wider published reach — 200 models across 40 upstream providers
  • You want metadata-only logging with a stated 30-day retention

Choose Bifrost if

  • You need a permissive Apache-2.0 licence with no copyleft obligations
  • You need air-gapped installation
  • You want no vendor relationship and no hosted tier at all
  • You are comfortable being the only operator, with no managed fallback

What catches people out

Side by side

9 of 17 fields differ, marked with a dot. Every figure links to the vendor page it came from. Blank values read Not published rather than No — silence from a vendor is not a negative answer.

Field LLM Gateway Bifrost
Ease of leaving Derived score, higher is easier 72/88 Some work to leave 100/100 Easy to leave
What kind of product Category Open source Open source
Who runs it Deployment model Managed or self-host Self-host only
Licence Licence AGPL-3.0 Apache-2.0
Models available Models available ~200 Not published
Model providers reachable Upstream providers ~40 20–23
Markup on model prices Token markup None None
Fee to add funds Credit purchase fee 5% None
Monthly cost per person Seat fee None None
Runs fully disconnected Air-gapped deployment Not published Yes
SOC 2 audited SOC 2 audited Yes Not published
What gets logged Logged content Metadata only Your choice
You can turn logging off Body-logging opt-out Yes Yes
How long they keep it Default content retention (days) 30 days 365 days
Can use your own provider accounts BYOK supported Yes Yes
Could they train on your prompts Training on customer data No Not published — silence, not a no
GitHub stars GitHub stars 1,643 8,359
Free tier Free tier $0 forever: no seats or minimums, BYOK free, 3 free models limited to 20 req/min, 30-day data retention; hosted credits carry a 5% platform fee. OSS tier is "Free Forever": drop-in gateway, OpenTelemetry observability, budgets, rate limits, virtual keys, custom routing, fallbacks, simple and semantic caching, MCP gateway, prompt repository.

for LLM Gateway and for Bifrost. Want more fields, or a third option in the mix? Open these two in the full comparison tool.

Common questions

Is Bifrost or LLM Gateway the better self-hosted gateway?

Bifrost if the licence matters most: Apache-2.0 imposes no copyleft obligations and it supports air-gapped installation. LLM Gateway if breadth matters more, at 200 models across 40 upstream providers with a published SOC 2 report, and if you want the same product available as a hosted service while you migrate.

Does either one charge a fee when self-hosted?

No. Both record a zero token markup and no seat fee, and both are free to run on your own infrastructure. The only fee in this pair is on the hosted side of LLM Gateway, where buying credit carries a 5% platform charge. Self-hosting either one costs you infrastructure and nothing else.

Which one supports air-gapped deployment?

Bifrost. It is one of only four products in this catalog that record air-gapped installation as supported, alongside LiteLLM, Orq.ai Router and TrueFoundry AI Gateway. LLM Gateway does not publish an air-gapped position, which is recorded as unpublished rather than as a no — worth confirming directly if that is a hard requirement.