TrueFoundry AI Gateway vs Apache APISIX AI Gateway
The question that decides it: Do you want a free foundation project you operate entirely yourself, or a paid platform with a vendor and an audit report behind it?
Our verdict
Free, permissive and already part of your API stack, with basic LLM proxying being enough: Apache APISIX AI Gateway. You need a SOC 2 report, a GDPR agreement, air-gapped support and 27 providers working out of the box, and you have budget: TrueFoundry AI Gateway.
Why
Both of these end up running inside your own infrastructure, so the deployment field does not separate them. What separates them is whether there is a vendor on the other end of the phone, and what that costs.
Apache APISIX AI Gateway is free in the strongest sense: the entire project is Apache-2.0 with a zero token markup, no credit fee and no seat fee, and its AI proxy plugins are part of that. Because it is a foundation project rather than a vendor, it publishes no SOC 2 report, no HIPAA position, no GDPR agreement and no air-gapped position — those are not gaps in our research, they are things a project of that shape does not issue. Its documented reach is 10 to 20 upstream providers, and it publishes no total model count. Zero data retention is recorded as not applicable, because prompts never reach a vendor at all.
TrueFoundry is the inverse trade. It is proprietary and sold on request tiers, and in exchange it publishes a SOC 2 report and a GDPR data processing agreement, supports air-gapped installation, and states 1,000 models across 27 upstream providers. If your reason for self-hosting is a compliance requirement rather than a cost one, that combination is the point: you get the isolation of running it yourself and an audit report to show a reviewer, which APISIX cannot give you.
The honest framing is that these are answers to different questions. Adopting APISIX purely for LLM routing is usually the wrong call — its value comes from already running it for ordinary API traffic and wanting AI requests governed by the same data plane. Adopting TrueFoundry is a platform decision with a budget attached. If neither of those describes you, the pair to look at is a self-hostable LLM-native gateway such as LiteLLM or Bifrost, which sit between these two on both cost and feature depth.
Which one, concretely
Choose TrueFoundry AI Gateway if
- You need a published SOC 2 report and a GDPR data processing agreement
- You need vendor-supported air-gapped installation
- You want 1,000 models across 27 providers working without integration work
- You want a vendor accountable for fixes and support
Choose Apache APISIX AI Gateway if
- You already run APISIX for ordinary API traffic and want one data plane
- You want a genuinely free Apache-2.0 stack with no vendor account
- Basic multi-provider proxying and token rate limits are enough
- You want prompts never to reach any vendor at all
What catches people out
- APISIX publishes no SOC 2 report, HIPAA position, GDPR agreement or air-gapped position — a foundation project does not issue these.
- APISIX documents only 10 to 20 upstream providers and publishes no total model count.
- Adopting APISIX from scratch purely for LLM routing is usually the wrong call; its value is in an existing deployment.
- TrueFoundry is proprietary with no source available, so self-hosting it still leaves you dependent on the vendor.
- TrueFoundry publishes no HIPAA business associate agreement and no zero-data-retention position.
- TrueFoundry sells request tiers rather than a percentage, so the cost is a negotiation rather than a published rate.
Side by side
Interpret these fields: How much does an LLM gateway lock you in? · LLM gateway compliance: SOC 2, HIPAA and evidence · How LLM gateway failover actually works
5 of 17 fields differ, marked with a dot. Every figure links to the vendor page it came from. Blank values read Not published rather than No — silence from a vendor is not a negative answer.
| Field | TrueFoundry AI Gateway | Apache APISIX AI Gateway |
|---|---|---|
| Ease of leaving Derived score, higher is easier | 100/100 Easy to leave | 100/100 Easy to leave |
| What kind of product Category | Cloud platform | Open source |
| Who runs it Deployment model | Managed or self-host | Self-host only |
| Licence Licence | Proprietary | Apache-2.0 |
| Models available Models available | ~1,000 | Not published |
| Model providers reachable Upstream providers | 27 | 10–20 |
| Markup on model prices Token markup | Not published | None |
| Fee to add funds Credit purchase fee | Not published | None |
| Monthly cost per person Seat fee | Not published | None |
| Runs fully disconnected Air-gapped deployment | Yes | Not published |
| SOC 2 audited SOC 2 audited | Yes | Not published |
| GDPR commitments GDPR commitments | Yes | Not published |
| What gets logged Logged content | Your choice | Metadata only |
| You can turn logging off Body-logging opt-out | Yes | Yes |
| How long they keep it Default content retention (days) | 90 days | Not published |
| Can use your own provider accounts BYOK supported | Yes | Yes |
| GitHub stars GitHub stars | Not published | 17,155 |
| Free tier Free tier | Developer plan $0/month: 50,000 requests/month, 3 users, 50,000 MCP tool calls, up to 10 saved prompts. | Entire project is free under Apache-2.0, including the ai-proxy and ai-proxy-multi AI gateway plugins. |
for TrueFoundry AI Gateway and for Apache APISIX AI Gateway. Want more fields, or a third option in the mix? Open these two in the full comparison tool.
Common questions
Is Apache APISIX enough to use as an AI gateway?
For basic multi-provider proxying and token rate limiting on an APISIX deployment you already run, yes. Its documented reach is 10 to 20 upstream providers and it publishes no total model count, so it is not a substitute for an LLM-native gateway if breadth or AI-specific features are what you need.
Why pay for TrueFoundry when APISIX is free?
For the paperwork and the reach. TrueFoundry publishes a SOC 2 report and a GDPR data processing agreement, supports air-gapped installation with a vendor behind it, and states 1,000 models across 27 providers. APISIX issues none of those documents, because it is a foundation project rather than a vendor.
Do prompts leave my network with either one?
Not to the gateway vendor. APISIX records zero data retention as not applicable precisely because it runs inside your own infrastructure and prompts never reach a vendor. TrueFoundry can also run in your own cloud or air-gapped. In both cases prompts still reach whichever model providers you route to.