LLM Gateway vs Requesty

The question that decides it: Do you want a fee you can escape by self-hosting, or a hosted router with EU residency that you must trust with full request logs?

Our verdict

Self-hosting is on the table, or you want the option later: LLM Gateway, where the 5% applies only to hosted credits and the AGPL build carries no fee at all. You want a hosted-only router with EU data residency and a flat fee on inference: Requesty, provided the missing SOC 2 report and the full request-body logging are both acceptable to whoever signs off.

Why

The 5% figure is the trap in this pair, because it is the same number describing two different mechanisms. LLM Gateway takes 5% as a platform fee when you buy hosted credit and applies no token markup. Requesty applies a 5% markup on inference itself and no credit fee. The practical difference is what the percentage is a percentage of: a top-up charge is levied once on money you load, while a markup is levied on every call forever. At steady volume they converge; at bursty or exploratory volume the top-up fee is the cheaper shape.

The larger difference is not price at all. Requesty is the only product in this catalog that records soc2 as an explicit no rather than as unpublished — that is a stated absence, not a gap in our research. It also logs full request and response bodies, and whether that logging can be turned off is not documented. Those two facts travel together badly: a vendor holding complete prompt and completion content, with no audit report and no documented opt-out, is a combination most security reviews will stop on. It does publish a GDPR data processing agreement, EU data residency and a zero-data-retention position with 30-day stated retention, so the picture is not uniformly bad — but it is inconsistent in a way you will have to explain internally.

LLM Gateway answers those questions better and introduces a different one. It publishes a SOC 2 report, logs metadata only, allows logging to be turned off, and states it does not train on customer data. Its licence is AGPL-3.0, which is the strongest copyleft in this catalog: fine if you run it as a standalone service, a genuine legal question if you intend to modify it and embed it in something you distribute. Its zero-data-retention position is conditional rather than default, which is worth pinning down before it matters.

On reach, LLM Gateway states 200 models drawn from 40 upstream providers. Requesty's own pages give between 160 and 600 models, and that spread is the finding rather than noise — where a vendor's pages disagree with each other, the honest rendering is both numbers. Both support bringing your own upstream provider keys, which is the real escape hatch on either side: with BYOK the model providers bill you directly and you are only paying for the routing layer.

Which one, concretely

Choose LLM Gateway if

  • You want the option to self-host and drop the platform fee entirely
  • You need a published SOC 2 report
  • You want metadata-only logging with a documented off switch
  • You want the fee levied on top-ups rather than on every call

Choose Requesty if

  • You want a hosted-only service with no infrastructure to run
  • You need EU data residency and a GDPR data processing agreement
  • You prefer a flat markup on inference to a charge on credit purchases
  • You want a free plan that covers all free models at 200 requests a day

What catches people out

Side by side

9 of 18 fields differ, marked with a dot. Every figure links to the vendor page it came from. Blank values read Not published rather than No — silence from a vendor is not a negative answer.

Field LLM Gateway Requesty
Ease of leaving Derived score, higher is easier 72/88 Some work to leave 64/100 Some work to leave
What kind of product Category Open source Managed marketplace
Who runs it Deployment model Managed or self-host Managed only
Licence Licence AGPL-3.0 Not published
Models available Models available ~200 706
Model providers reachable Upstream providers ~40 Not published
Markup on model prices Token markup None 5%
Fee to add funds Credit purchase fee 5% Not published
Monthly cost per person Seat fee None None
SOC 2 audited SOC 2 audited Yes No
GDPR commitments GDPR commitments Not published Yes
Can keep data in the EU EU data residency Not published Yes
Does not retain your data Zero data retention Depends how you deploy it Yes
What gets logged Logged content Metadata only Full prompts and responses
You can turn logging off Body-logging opt-out Yes Not documented
How long they keep it Default content retention (days) 30 days 30 days
Can use your own provider accounts BYOK supported Yes Yes
Could they train on your prompts Training on customer data No No
Free tier Free tier $0 forever: no seats or minimums, BYOK free, 3 free models limited to 20 req/min, 30-day data retention; hosted credits carry a 5% platform fee. Free plan: all free models, 200 requests/day, routing, caching, fallbacks, EU residency, no credit card.

for LLM Gateway and for Requesty. Want more fields, or a third option in the mix? Open these two in the full comparison tool.

Common questions

Is LLM Gateway or Requesty cheaper?

It depends on the shape of your spend, not the rate, because both are about 5%. LLM Gateway charges it once when you buy hosted credit and adds no token markup. Requesty charges it on inference itself, on every call. Self-hosting LLM Gateway removes the fee altogether, which is the cheapest option either side offers.

Does Requesty have a SOC 2 report?

No. Requesty is the only product in this catalog recorded as an explicit no on SOC 2 rather than as unpublished, meaning the absence is stated rather than merely undocumented. It does publish a GDPR data processing agreement and EU data residency, so ask directly whether an audit is underway before ruling it out.

Does the AGPL licence on LLM Gateway matter for commercial use?

Running the unmodified image as an internal service is straightforward. The question arises if you modify it and then convey the software or offer it to third parties over a network, where AGPL-3.0 obligations attach. Most teams treat it as fine for internal deployment and a legal review item for anything they redistribute.