01 · Define the control
Policy that fails closed.
Turn data classes, agent capabilities and risk levels into enforceable routes. Start with DORA, GDPR or NIS2 baselines, then test every change before it goes live.

LLM egress control · EU
Sluss is a self-hosted, open-source LLM gateway for regulated EU organisations. Classify every prompt, route it by policy, and keep tamper-evident proof for NIS2, DORA and GDPR.
AGPL-3.0 · Single binary · OpenAI & Anthropic compatible
The risk
Staff paste contracts, patient notes and customer data into public chatbots. You can't see it, so you can't govern it.
NIS2 and DORA auditors ask what left the building. Without a verifiable log, the honest answer is: we don't know.
Blocking AI pushes usage underground and leaves productivity on the table. Competitors won't wait.
The paradox
To inspect your data, cloud data-loss tools send it to US infrastructure first — the very transfer you were trying to prevent.
Using a model to judge prompts adds latency, per-token cost and a fresh prompt-injection surface on your security control.
How it works
Point your clients at Sluss. Every request is classified in under a millisecond, sent only where policy allows, and recorded.
Split routing · a router, not a wall
public
Public / general
→ Approved cloud
OpenAI · Anthropic
sensitive
Personal data · secrets
→ Local EU model
Ollama · vLLM on your hardware
no route
No approved destination
→ 403 · fail-closed
Explained to the user · audited
Zero-agent deployment
Sluss runs as a central proxy in your network. Block direct AI egress at the firewall and it becomes the only sanctioned path out.
Read the security briefing →# before — straight to a US cloud OPENAI_BASE_URL="https://api.openai.com/v1" # with Sluss — inside your perimeter OPENAI_BASE_URL="https://sluss.internal.example/v1"
The control plane
Track where data went, what was blocked fail-closed, and the evidence behind every decision — live.

01 · Define the control
Turn data classes, agent capabilities and risk levels into enforceable routes. Start with DORA, GDPR or NIS2 baselines, then test every change before it goes live.

02 · See it enforced
See sensitive requests blocked, approved workloads kept local, and low-risk traffic routed to cloud — with the reason, model and cost recorded for each decision.

Define the rule. Watch it hold. Hand the evidence to your auditor.
Explore the controls →Four pillars
Deterministic rules, under 1 ms, no LLM in the loop. Swedish personal ID numbers validated with the Luhn check — not guessed.
Fail-closed by design. If no approved destination fits, Sluss returns a 403 that says what was stopped and why — never a silent cloud fallback.
Every decision lands in a hash-chained audit log that can be verified offline by you or your auditor.
Agent permissions scoped to read, write, external and destructive actions. Tools only do what policy allows.
Why Sluss
Same input, same decision. Explainable to auditors.
Uncertainty blocks — and the user is told why. It never leaks.
Runs in your data centre or EU cloud. No call-home.
Tamper-evident logs map directly to control frameworks.
Observe real traffic before enforcing a single rule.
Unblock AI projects already waiting on security sign-off.
Compliance packs
DIR (EU) 2022/2555
Incident-ready logging, supply-chain egress control and access gates for essential and important entities.
REG (EU) 2022/2554
ICT third-party risk controls and audit evidence for banks, insurers and investment firms.
REG (EU) 2016/679
Personal data stays on EU or local models. Transfers to third countries are blocked by default.
AI-powered regulatory scan
Describe your organisation and how your teams use AI. Get an indicative first overview of relevant EU regulation in seconds. Not legal advice.
Your overview will appear here.
Compatibility
APIs
OpenAI + Anthropic compatible
Agents
MCP supported
Ship
Single binary
Deploy
60 seconds
Comparison
| Capability | Sluss | LiteLLM | Portkey | US cloud DLP |
|---|---|---|---|---|
| Egress control by data class | ● | ◐ | ◐ | ● |
| Deterministic classification | ● | — | — | ◐ |
| Self-hosted | ● | ● | ◐ | — |
| Tamper-evident audit | ● | — | — | ◐ |
| EU data sovereignty | ● | ◐ | — | — |
● yes ◐ partial — no · Based on publicly documented default capabilities.
For customers
For partners
Remove the compliance objection that stalls projects in regulated accounts.
Local models need GPUs. Sluss creates the reason to buy them.
Recurring policy tuning and evidence reviews for NIS2 and DORA.
A single binary. Your first demo runs before the coffee does.
FAQ
Yes. The core is licensed under AGPL-3.0 and the source is on GitHub. You can audit every line that touches your data.
No. Classification is deterministic and runs in under a millisecond, so it is predictable, cheap and immune to prompt injection.
Sluss fails closed and returns a 403 with a stable block code and a plain reason, so the client can explain the block instead of showing a raw error. It never silently reroutes sensitive data to a cloud you didn't approve.
Yes. Monitor mode logs every decision without enforcing it, so you can see real traffic before switching to enforce.
Anything that speaks the OpenAI or Anthropic API, plus MCP-based agents. Usually it's a one-line base URL change.
No. Rules match patterns and validate checksums — they don't read or follow instructions. There is no model in the loop to jailbreak.
Rarely. Sensitive prompts are rerouted to a local model and still get an answer. Only requests with no approved destination are blocked — and you start in monitor mode.
An explanation, not a mystery error. The response names the task class, the data class and the block code — classes only, never the prompt content. When a prompt is rerouted instead, the response says why and that it stayed in-house.
No. Sluss is a central proxy. Clients change one base URL, and you block direct access to public AI APIs at the firewall.
Each entry is hash-chained to the previous one. The chain can be verified offline with the included tool — no access to Sluss required.
Get started