Portkey alternative? Portkey and the Myra AI Workspace gateway compared
As of 11 October 2026
Portkey and the gateway inside Myra AI Workspace both sit between your applications and the model providers. They route requests, hold the provider keys and enforce limits. Portkey grew up as a developer platform with observability and prompt management, offered as a cloud service, a hybrid deployment and an MIT-licensed open-source gateway. Myra runs its gateway as a managed service on infrastructure it operates itself in the EU, and puts a chat workspace for employees on the same foundation.
One piece of news first. Palo Alto Networks closed its acquisition of Portkey in May 2026, and Portkey's homepage now says “Portkey is now PRISMA AIRS AI Gateway”. Since the documentation and the open-source repository still use the Portkey name, so does this page. All statements about Portkey are taken from Portkey's own pages, its GitHub repository and Palo Alto Networks' announcements.
Where Portkey is strong
Developer experience is the obvious one. You can start the open-source gateway with one npx command, and Portkey's homepage speaks of access to 1,600+ LLMs through one API. Fallbacks, load balancing, conditional routing and retries are part of the open-source code. On top, the hosted plans add logs and traces, prompt templates with versioning, plus caching and alerts. If your engineers want to see every request with its latency and cost from day one, Portkey is built around exactly that.
Compliance paperwork is in good shape as well. The Trust Center shows SOC 2, ISO 27001:2022, GDPR and HIPAA, and Portkey offers custom business associate agreements for healthcare data. The sub-processor list is public, with a location for each entry.
There is also more than one way to deploy. Enterprise customers can stay on the SaaS or choose a hybrid setup in which the gateway and the data plane run in their own VPC while Portkey manages the control plane. The architecture docs say that prompts and responses then stay inside your network, and only anonymised metrics cross the boundary. With the Palo Alto Networks acquisition, Portkey is also becoming the gateway of the Prisma AIRS security platform, which matters if you already buy from that vendor.
Portkey and Myra, criterion by criterion
| Criterion | Portkey (according to Portkey) | Myra AI Workspace |
|---|---|---|
| Deployment | Open-source gateway (MIT), cloud plans, Enterprise hybrid; fully air-gapped setups are no longer offered for new customers | Managed service on Myra infrastructure; on-premises deployment on request |
| Hosting of the cloud service | Trust Center names AWS and Cloudflare as cloud infrastructure, location US | Myra infrastructure with a BSI C5 Type 2 attestation; Myra models run on Myra's own EU infrastructure¹ |
| Data residency | Regional data residency announced in July 2025; hybrid keeps prompts in your VPC | A residency floor per gateway or organisation refuses non-EU routes with HTTP 403 before the provider call; off by default |
| Models | 1,600+ LLMs (homepage) | Many external providers via your own keys, plus Myra-hosted open-weight models¹ |
| Personal data | PII redaction with standard identifiers via Portkey Pro PII and partner guardrails; documented as one-way (non-reversible) | Reversible tokenisation before external models, originals restored in the answer, German checksum recognisers; every plan |
| Budgets and rate limits | Budget limits on providers for Enterprise and select Pro customers | Spending caps per token and gateway as well as per tenant; rate limits per gateway or token |
| Audit log | Enterprise: admin actions with user and workspace as well as IP and country; filterable under Admin Settings | Admin changes and security events are logged, tamper-evident via a hash chain on request; customer admins have no audit-log view |
| SSO and roles | OIDC and SAML 2.0 for Enterprise, SCIM; RBAC from the Production plan | OIDC and SAML, SCIM, system roles plus custom roles |
| Certifications | SOC 2, ISO 27001:2022, GDPR, HIPAA (Trust Center) | Myra: ISO 27001 on the basis of IT-Grundschutz; infrastructure with BSI C5 Type 2 |
| Sub-processors | Public list in the Trust Center | New sub-processors are announced 30 days ahead under the DPA, with a right to object |
| Chat for employees | No chat app of its own; docs cover front ends such as LibreChat and Open WebUI | Chat workspace with projects and agents, plus a privacy indicator |
Prices stay off this page on purpose. Portkey prices by recorded logs and quotes Enterprise individually, while Myra bills per user plus model usage, and the two models do not line up.
Three ways to deploy Portkey, and what each means for your data
On the cloud plans, Portkey runs everything. Its Trust Center describes AWS as the place where most data stored and processed through Portkey resides, with Cloudflare as a second infrastructure provider; both entries carry the location US. According to Portkey's pricing page, the Production plan is not recommended for organisations that need custom security controls or data residency commitments. Those belong to Enterprise.
In the hybrid model, the gateway and its data plane live in your Kubernetes cluster on AWS or Azure or on Google Cloud, and Portkey's control plane manages configuration. You get the managed console without sending prompts out of your network, at the price of operating the data plane yourself. The open-source gateway is the third route: no Portkey account at all, but also none of the hosted logs, budgets or audit features.
Myra's gateway has a single standard shape. Myra Security operates it on its own infrastructure, and the BSI, Germany's Federal Office for Information Security, lists the company as a qualified DDoS mitigation service provider. Its C5 Type 2 attestation covers that infrastructure; the AI Workspace application itself is outside its scope. Inside a tenant you create gateways, each with its own routing rules, guardrails, budgets and provider keys.
Redaction or reversible masking
Portkey's PII redaction replaces names, email addresses, phone numbers and similar data with standard identifiers before the request reaches the model. You switch it on with a toggle in supported guardrails, from Portkey's own PII check to partners like Pangea or AWS Bedrock Guardrails, and you can add regex patterns. Portkey documents the redaction as one-way, so the original values do not come back in the response. For many API workloads that is exactly right: the model never needs the real value.
Chat is different. When an employee asks for a letter to Mr Weber, the answer should contain Mr Weber. Myra masks personal data with placeholders before an external model sees it and puts the original values back into the reply. Recognisers with checksum validation handle German identifiers such as the tax ID or an IBAN. In legal terms this remains pseudonymisation. Requests that Myra-hosted models answer are not masked, because the data stays with Myra.
Employees see the routing before they send. A coloured indicator beside the model picker turns green (“Local model” or “Local + masking”) for Myra models and yellow (“Privacy on”) for an external model behind masking, and it shows red (“Privacy off”) when text would leave unchanged. An admin can enforce masking tenant-wide. A project with the access tier “Local only” allows Myra models alone and blocks web search too.
Who can read the audit log
Portkey's Enterprise audit log is the more convenient one for a compliance team. Org owners and admins open it under Admin Settings and filter by method, resource type or request ID, and each entry carries the user, workspace, client IP and country.
At Myra, admin changes and security events such as failed sign-ins or a disabled PII masker are written to an audit log, with tamper evidence via a hash chain available on request. Customer admins cannot open that log themselves today; Myra pulls extracts via API. Request logs with cost and latency are visible in the admin UI, and security events can be streamed into your SIEM.
Which situation fits which product
| Your situation | Better fit |
|---|---|
| Developers want request-level observability and prompt management in one tool | Portkey |
| Prompts must stay in your own VPC while someone else runs the console | Portkey (Enterprise hybrid) |
| You already standardise on Palo Alto Networks security products | Portkey (Prisma AIRS AI Gateway) |
| You need a HIPAA business associate agreement | Portkey |
| Your compliance team wants to filter the admin audit log itself | Portkey (Enterprise) |
| Masked data should come back unmasked in chat answers | Myra |
| Some workloads may only run on models hosted by the gateway operator in the EU | Myra (“Local only” per project) |
| The gateway should also give employees a governed chat workspace | Myra |
| Procurement requires a BSI C5 attestation for the infrastructure operator | Myra |
Myra does not use customer data to train AI models; for external models, the provider's terms apply. For the general picture, see what an AI gateway does. The self-hosted open-source option is covered in our LiteLLM comparison, and the Myra documentation explains routing and guardrails as well as the residency floor step by step.
Frequently asked questions
Is Portkey now part of Palo Alto Networks?
Yes. Palo Alto Networks announced on 29 May 2026 that it had closed the acquisition of Portkey. Portkey's homepage now reads “Portkey is now PRISMA AIRS AI Gateway”, and Palo Alto Networks announced general availability of that product on 16 July 2026.
Is the Portkey gateway open source?
The AI Gateway repository on GitHub is MIT-licensed and runs locally with a single npx command. Logs, traces, the audit log and most governance features belong to Portkey's hosted plans. According to the README, the core enterprise gateway is moving into open source with a 2.0 release that is currently in pre-release.
Where does Portkey's cloud service process data?
Portkey's Trust Center lists AWS and Cloudflare as cloud infrastructure providers, both with the location US. A July 2025 changelog entry announced regional data residency, and the Enterprise plan adds hybrid deployment, where the gateway and the data plane run in your own environment.
Does Myra mask personal data in the reply as well?
Myra replaces personal data with placeholders before an external model sees the request, then restores the original values in the answer. The user reads the real names again. Detection fully supports German and English, and the feature is included in every plan.
Sources
- Portkey: homepage (“Portkey is now PRISMA AIRS AI Gateway”), retrieved 11 October 2026
- Palo Alto Networks: completes acquisition of Portkey (press release), retrieved 11 October 2026
- Palo Alto Networks blog: general availability of Prisma AIRS AI Gateway, retrieved 11 October 2026
- Portkey AI Gateway on GitHub: README and LICENSE (MIT), retrieved 11 October 2026
- Portkey: pricing and plans, retrieved 11 October 2026
- Portkey documentation: feature comparison and deployment options, retrieved 11 October 2026
- Portkey documentation: hybrid deployment architecture, retrieved 11 October 2026
- Portkey documentation: Security @ Portkey, retrieved 11 October 2026
- Portkey Trust Center (certifications, sub-processors), retrieved 11 October 2026
- Portkey changelog, July 2025 (regional data residency), retrieved 11 October 2026
- Portkey documentation: PII redaction, retrieved 11 October 2026
- Portkey documentation: audit logs, retrieved 11 October 2026
- Portkey documentation: SSO, retrieved 11 October 2026
- Portkey documentation: budget limits, retrieved 11 October 2026
- Portkey documentation: LibreChat integration, retrieved 11 October 2026
- Myra AI Workspace documentation, retrieved 11 October 2026