Provable AI governance · one base URL
The AI layer you can prove to a regulator.
Your teams are already calling LLMs. RemKey is the record of what went where: every call screened for PII and prompt injection, signed into a tamper-evident audit chain, and exportable as a bundle your auditor verifies offline. The same layer routes each request to the cheapest capable model and proves the downgrade held quality, so governance arrives with a lower bill, not a bigger one. One base URL, live in 60 seconds, no card.
Coming from Portkey? It went enterprise inside Palo Alto / Prisma AIRS. RemKey imports your config and grandfathers a free window, so you move in minutes and keep your self-serve workflow. See the Portkey alternative.
Everything a gateway should do, plus the security layer none of them ship
Every request is hash-chained and Ed25519-signed. Your auditor verifies the export offline, with nothing to trust but the math. This is the layer that clears sign-off.
PII detection (email, SSN, phone, card, API key) plus Llama Guard injection screening, fail-closed. Redact or block before the prompt ever leaves.
Agent tool-calls run against a fail-closed allowlist. Blocked calls still land on the audit chain. Nothing else governs agent tools this way.
An LLM classifier sends each request to the right model tier at 96% accuracy, versus 33% for keyword rules. Cheap prompts stop paying premium prices.
On a sample of downroutes we also run the premium model and score whether the cheap answer held up. You get a quality-hold number, so the savings come with proof instead of a shrug.
Anthropic, OpenAI, or OpenRouter keys, encrypted at rest and revocable instantly. First-party preferred, OpenRouter as commodity overflow.
Accepts both Authorization: Bearer and x-api-key. Swap one base URL and your Anthropic or OpenAI code doesn't change.
Transient provider failures retry with backoff, then fail over to your next lane, your own second key or the pooled lane, never a fake response. The record shows exactly which lane served.
An audit trail a reviewer can actually verify
Every request becomes a block, hash-chained to the one before it and signed with Ed25519. Your security team verifies the export offline, with nothing to trust but the math. When the question is "can you prove what your AI did last quarter," this is the difference between a log you're asked to trust and a chain anyone can check.
In financial services? See how the signed chain, the offline verifier, and multi-year retention map to the questions your compliance team is already being asked: RemKey for financial services.
Savings you can prove, not a shrug
A router can tell you it downrouted. It can't tell you the answer held quality. We sample downroutes, run the premium model in the background, and score the two against each other. The number that comes out the other end is the one you can put in front of a security review.
MCP tool-calls, governed the same way
Most agent frameworks trust MCP tool-calls once a connection is made. RemKey puts a fail-closed allowlist in front of every call: unknown tool or unknown scope is blocked by default, and both allowed and blocked calls are signed onto the same audit chain as everything else.
Why now
AI agents are moving from prototype to production, the fastest-inflecting slice of AI spend in 2026. Every team making that move hits two walls at once. Token bills run away from over-using frontier models on work a cheaper model handles fine. And a security review stalls the launch, because nobody can prove what the agents actually did. Today those are two separate tools, or two things nobody built.
RemKey collapses them into one layer. The routing cuts spend, then proves the cheaper model held quality before it counts a dollar saved. The governance guards, signs, and audits every call, so the gateway that lowers the bill is the one that clears the review. A commodity router can't add the proof. An enterprise suite can't be turned on in a minute. That gap is the opening.
routing accuracy, against 33% for keyword rules. See the methodology
guarded for PII and injection, signed into a tamper-evident chain
from base-URL swap to a governed, audited endpoint
Drop-in in one line
Nobody wants to be a token accountant or a model sommelier. Swap the base URL, keep your
Anthropic (or OpenAI) code unchanged, and both jobs disappear: every request is classified to the
cheapest capable model, guarded, and audited, with model: "auto" doing the choosing.
The founder's confession on why.
# Anthropic SDK / Claude Code: swap the base URL, nothing else
export ANTHROPIC_BASE_URL=https://remkey.ai
export ANTHROPIC_API_KEY=rmk_your_key
Free to route. Pay for proof or governance, never for volume.
Routing and guardrails are free up to a ceiling no real evaluation will touch. You pay only if you want the verified-savings number for yourself (Verified), a security review is watching (Team), or an auditor is (Compliance). Compare to Portkey.
- Full classifier + guardrails
- MCP governance
- 7-day signed audit
- BYOK providers
- Everything in Free
- Confirmation the cheap model didn't get it wrong
- 30 days of savings & routing history
- Everything in Verified
- 90-day signed audit
- Seats + per-environment policy
- SOC 2 controls documented, audit engagement next
- Everything in Team
- 1 to 7 year signed-chain retention
- Offline verifier workflow for your auditors
- SSO/SCIM, HIPAA BAA, dedicated deployment
- Dedicated support
Free covers 1M governed requests/mo, then $8/100k, so the cap only ever touches silent high-volume traffic, never a team finding its feet. Token margin only ever applies on the optional pooled lane. We market the dollars you save. We never bill on them. Compliance is a flat annual platform fee, never a per-token bill, because a variable number is not something you can take to procurement.
Start free in 60 seconds
No card. You get a live key and a working dashboard immediately.