Logo RouteroAI
Security

SSO + audit.

Enterprise SSO at the front door. RBAC, short-lived keys, and a complete audit log behind it. Every prompt and every policy change is reproducible months after the fact.

OIDC SSOVirtual keys + rotationComplete audit logSIEM-ready
SOC 2
Type II audit in progress (WIP)
Retention
By plan: 7d Free · 90d Growth · custom + export on Enterprise
OIDC
Microsoft Entra, Google Workspace, any OIDC IdP
SCIM 2.0
Coming soon: account & group sync, automatic deprovisioning

Your security team has questions.
None of the answers are in OpenAI's console.

Who can call which model? Who actually called it? Which prompts touched PII? Are deprovisioned employees still hitting the API with a leaked key?

Routero AI is the layer where those answers live — SSO at the door, RBAC for permissions, and a centralized audit log of every request that crossed the boundary.

SSO in. Permissions through.

SSO

OIDC single sign-on

Microsoft Entra, Google Workspace, and any OIDC-compatible IdP — Okta, Auth0, Keycloak, custom. JIT user provisioning on first login.

SCIM

Automatic provisioning

SCIM 2.0 coming soon: accounts and groups sync from your IdP; deprovisioning automatically revokes API keys.

RBAC

Role-based permissions

Built-in roles (Admin, Developer, Auditor) plus custom roles and fine-grained object permissions. Scope to organizations, teams, and keys.

Keys

Short-lived keys

Issue virtual keys with TTL, model and route scope. Auto-rotate without redeploys. Revoke from the console in one click.

Vault

Provider key vault

Upstream provider keys are encrypted and rotated centrally. Your apps only hold Routero virtual keys — real credentials never land in your code.

Audit-only

Read-only roles

Give your compliance team and SIEM ingest pipelines audit-only access. No risk of accidental policy edits.

Every request, every decision,
every minute — recorded.

Centralized, queryable, complete. Replay any incident with full context — caller identity, chosen model and provider, retry reasons, content classifications.

audit.events · last 5 minutes ↓ siem-export
14:32:04 request.routed sarah.chen@acme.co · customer-support → anthropic/sonnet-4
14:32:01 policy.evaluated sarah.chen@acme.co · pii_detected=false · region=us
14:30:18 key.rotated admin:mike.r@acme.co · prod-customer-support · auto-rotate
14:28:55 user.provisioned admin:sso · jen.taylor@acme.co · group:engineering
14:27:12 policy.changed admin:mike.r@acme.co · finance-team.yaml · v17 → v18
14:25:03 request.blocked contractor.tmp@acme.co · content_filter=pii · model=gpt-5.4
14:24:50 user.deprovisioned admin:sso · jane.old@acme.co · 3 keys revoked

Stream the same events to Datadog or Azure Sentinel, or via OpenTelemetry into ELK, Loki, and your existing log platform or SIEM stack.

The paperwork your security
team is already asking for.

SOC 2

Type II (WIP)

Audit in progress (WIP). Report will be available under NDA once complete.

HIPAA

BAA available

Routero AI signs a BAA on Enterprise. PHI never persisted beyond audit metadata.

ISO

27001 (WIP)

Information security management. Certification in progress (WIP).

GDPR

DPA + SCCs

Standard contractual clauses for EU data. Regional deployments keep requests and logs within their region.

Bring your IdP, leave with the audit log.

A 30-minute walkthrough with a solutions engineer — bring your provider list and we'll map it live.