EU-sovereign LLM gateway · data stays in Europe

Never get a surprise LLM bill. Guaranteed.

Fortress is one gateway your app's LLM calls pass through — metering every token against a hard spend ceiling, redacting secrets, and logging every request. One control point, many walls, all in the EU.

Bring your own key Point your SDK, change nothing else Cannot be overcharged — even on a leaked key
Runs on EU-owned inference — not a US cloud's European region
Scaleway Generative APIs Mistral OVH AI Endpoints + your own OpenAI / Anthropic key
Everyone with an API key is one leaked key away from a five-figure bill.

A committed key, a runaway agent loop, a streaming response that never stops. Provider dashboards tell you what you already spent. Existing gateways track budgets — they don't physically stop the spend, and most send your prompts through a US cloud.

One gateway, many walls

Every protection is a policy at the same control point

Not six products — six walls on one gateway. Cost Guard ships first; the rest are additive. Some sit on the hot path; Audit is an async evidence log; Instant Kill lives on the control plane.

Cost Guard Core

A hard spend ceiling enforced in-request (BYOK) — per org, project, key, or route. Reserve-before-spend, mid-stream cut, concurrency-safe. The guarantee is the cap, not a Fortress prepaid wallet (providers stay postpaid).

Leak Guard MVP

Detects and redacts secrets and PII on the way in — API keys, source, personal data — before a prompt ever reaches the model.

Output Guard Next

Scans completions for sensitive data leaking back out — context regurgitation or PII the model shouldn't have returned.

Injection Guard Next

Prompt-injection and jailbreak detection, including RAG-borne indirect attacks. Best-of-breed detection integrated — not reinvented.

Audit MVP · Anomaly Next

Audit (MVP): immutable log of who / what / when / cost / which walls fired — the evidence pack for a DPO. Anomaly (next): flags compromised keys and weird burn patterns on top of that log — it does not replace Cost Guard or Instant Kill.

Instant Kill Switch Core

One action revokes keys (and later stops tagged infra) — per project or the whole account. Control-plane panic button: next request is 403 even if the gateway is under load.

Why the cap is a guarantee

A budget flag warns you. Fortress stops the spend.

Most gateways check a budget after the fact — asynchronously, per key, overshooting on streaming and concurrency. Fortress reserves before it spends and cuts off mid-stream. Four properties turn a feature into a promise:

reserve-before-spend
Every call reserves its maximum cost up front. Nothing runs that the balance can't cover.
mid-stream cutoff
A streaming response is severed the moment it would cross the cap — not after it finishes.
concurrency-safe
A hundred parallel calls can't race past the limit. The balance is the single source of truth.
leaked-key-proof
A stolen key still can't spend beyond the cap. The ceiling holds even when the key is compromised.
One gateway, two ways in

Safe enough for anyone. Sovereign enough for a regulator.

The same gateway serves the developer who never wants a surprise bill and the CISO who must prove where every prompt went.

For everyone with an API key

Never overspend again

Solo devs · startups · any team shipping with LLMs

Bring your own OpenAI, Anthropic, or Mistral key. Fortress caps it, guards it, and logs it — the ceiling your provider never gave you. Free-tier friendly.

For the regulated buyer

Sovereign, AI Act–ready control point

EU CISO / DPO · public sector · regulated industries

Inference on EU-owned infra (Scaleway, OVH, Mistral) — not a US hyperscaler's Frankfurt region. Fortress is the control point: kill switch, policies, and an exportable evidence pack that helps your DPO support EU AI Act and governance duties — not a magic “AI Act certified” sticker.

How it works

Point your SDK at Fortress. Change one line.

app.py
# before — straight to the provider, uncapped
client = OpenAI(
    base_url="https://api.openai.com/v1",
)

# after — same SDK, through the Fortress gateway
client = OpenAI(
    base_url="https://eu.fortress.dev/v1",
    api_key="frt_live_…",  # your BYOK key, capped
)
# every call is now metered, guarded and logged.
# the cap holds — in-request, mid-stream.
1

Connect your key, set a spend ceiling

Bring your provider key (BYOK), set a hard spend cap per org/project/key. Near-zero risk — you keep your own account; the provider still invoices postpaid usage that already ran.

2

Repoint the base URL

Change one line in your OpenAI/Anthropic-compatible SDK. No rewrite, no new client library.

3

Every call passes the walls

Leak Guard redacts, Cost Guard reserves under your spend cap, the call forwards to an EU model; Audit logs async. Output Guard and Anomaly ship later.

4

The cap can't be crossed

When the next token would exceed the balance, Fortress refuses in-request and can revoke the key — no overshoot, no surprise.

It doesn't stop at LLM

One balance caps your whole cloud bill.

The LLM gateway is the way in. The same Cost Guard ceiling later covers whole EU cloud burn (routes + resources) — because a bill you can't see is a bill you can't cap. That's the line no LLM wrapper can cross: a proxy only meters what flows through it.

In the request path

Routes — per token

LLM & API calls

Every call reserves its cost before a token is spent, and is cut mid-stream if it would cross the cap. A true hard cap — and where the wrappers stop.

On your infrastructure

Resources — per hour

GPUs · databases · storage · egress

Compute billed by the clock never touches a proxy, so Cost Guard stops tagged infra at the buffer (phase 2). GPUs, DBs, storage — under the same ceiling as token routes.

Where Fortress sits

Budgets exist everywhere. Guarantees don't.

Gateways track spend and route cheaply. None sell a hard cap you can't cross on EU-owned infrastructure.

Gateway Hard, in-request cap EU-owned inference AI Act evidence pack
Fortress Guaranteed Yes Yes
OpenRouter Soft credits No No
Portkey Budget flag Enterprise tier No
Requesty / Opper Tracking only AWS Frankfurt No
LiteLLM (OSS) Async flag Self-host No

Competitive facts verified July 2026. Full brief: docs/gtm/fortress-competitive-brief.html

Pricing

Free to start. Pro when you grow. Sovereign when you prove.

The hard-cap guarantee is free on one project. Pro is the easy first step. Team is the org plan. Sovereign is the EU control point and evidence pack for regulated buyers.

Free
For every developer
€0
Bring your own key. No card.
Start free
  • BYOK — OpenAI, Anthropic, Mistral, Scaleway
  • Cost Guard — hard in-request cap
  • Leak Guard — secrets & PII redaction
  • Instant kill switch
  • 1 project · 3 keys · 7-day audit log
  • Community support
Pro
When one project isn't enough
€59/org/mo
Everything in Free, plus:
Get early access
  • 3 projects · up to 10 keys
  • 30-day audit log
  • Email support
  • Same hard Cost Guard guarantee
  • Leak Guard & kill switch included
  • Save with annual billing
Most popular
Team
For growing teams
€199/org/mo
Everything in Pro, plus:
Get early access
  • Whole-budget cap — per-hour GPUs, DBs, storage
  • Unlimited projects & keys
  • Seats & roles (RBAC)
  • 90-day audit log + export
  • Anomaly detection
  • Email support
Sovereign
For regulated teams
From €1,990/org/mo
Everything in Team, plus:
Talk to us
  • Guaranteed EU-owned inference
  • AI Act evidence pack for your DPO
  • SSO / SAML · SCIM
  • DPA · data residency · unlimited retention
  • Dedicated support · SLA
  • Optional private deployment

Prices per organisation. Annual billing ≈ 2 months free. BYOK: you pay your provider for tokens — Fortress never marks them up. Sovereign starts at €1,990/mo; custom above that. The EU AI Act evidence pack supports your governance duties — Fortress does not replace your legal role as deployer or provider.

Put a wall between your app and a runaway bill.

Fortress is in early access. Bring your own key, set a cap you can trust, and keep your data in Europe.

We'll email you the moment your spot opens. No spam, ever.