AI governance
Model allow- and deny-lists, provider and region restrictions, data boundaries, PII handling, budgets and quotas per workspace, tenant and key, approval through a human queue, and a hash-chained audit trail - applied before any model is scored, visible in a governance report with a posture score. Hosted or self-hosted, Apache-2.0.
Free plan, no card. Open source under Apache-2.0; self-hosting is free forever.
From the benchmark
100%
of requests traced, attributed and auditable
Every metered request carries its key, member, tenant, target, tokens, cost and outcome; the governance report lists every control in force with the findings behind it. Controls you configure for regulated workloads - not a certification claim.
The whole benchmark, with the cases the router lostThe problem
Most AI governance is a page that says which models may be used, where data may go and who may spend what. Nothing reads it at request time. The platform team is asked to enforce it and has no place in the path of a request to do so - until the router is that place.
How the router answers it
Data boundary, region, tenant, cost and latency ceilings, allowed and denied targets, PII handling and payload logging apply to every key before any candidate is scored. A target that fails is not a candidate, and the trace says which rule removed it.
Daily and monthly budgets per workspace, tenant and key are ceilings, not alerts: once reached, the request is refused with a reason the caller can read. Per-key scopes, rate limits and expiry bound what one credential can do.
A hash-chained audit trail of decisions and outcomes, a governance report with every control in force and a posture score, and - when judgement is needed - a human queue as a routing target with approval in the loop.
A real request
Not a prompt and not a weight: a request that would break it is refused or re-routed before a model is called, and the audit trail records the rule.
data_boundary: private # never a public endpoint
region: eu # EU targets only
contains_pii: true # treat every request as if it may carry PII
deny_targets: [llm-frontier] # never this one, whatever the score
max_cost_per_1k: 0.01
daily_budget_usd: 250
log_payloads: false # prompts and answers are not keptRead next
Install
curl -fsSLO https://opensmartroute.ai/download/helm && helm install router opensmartroute-*.tgzOr no install at all: the hosted API answers a plain curl with the decision, and the browser extension shows the price and the router's pick under the composer of the AI chat sites you already use.
OpenSmartRoute is open source and the free plan keeps the full trace of every decision. Create a workspace, mint a key and send the request above.
Free plan, no card. Fifteen thousand decisions a month with the full trace.