Ssluss.euBook a demo

LLM egress control · EU

Your teams already use AI. Decide where the data goes — and prove it.

Sluss is a self-hosted, open-source LLM gateway for regulated EU organisations. Classify every prompt, route it by policy, and keep tamper-evident proof for NIS2, DORA and GDPR.

AGPL-3.0 · Single binary · OpenAI & Anthropic compatible

The risk

AI is already in your organisation. The question is whether you can see it.

Shadow AI

Staff paste contracts, patient notes and customer data into public chatbots. You can't see it, so you can't govern it.

The evidence gap

NIS2 and DORA auditors ask what left the building. Without a verifiable log, the honest answer is: we don't know.

The cost of saying no

Blocking AI pushes usage underground and leaves productivity on the table. Competitors won't wait.

The paradox

Most AI security tools create the exposure they promise to prevent.

✕ 01

US cloud DLP ships prompts abroad

To inspect your data, cloud data-loss tools send it to US infrastructure first — the very transfer you were trying to prevent.

✕ 02

LLM-based inspection adds new risk

Using a model to judge prompts adds latency, per-token cost and a fresh prompt-injection surface on your security control.

How it works

Classify → Route by policy → Prove.

Point your clients at Sluss. Every request is classified in under a millisecond, sent only where policy allows, and recorded.

client
app · agent · IDE
sluss
classify · route · log
local model
sensitive data
approved cloud
public / internal

Split routing · a router, not a wall

Teams keep their AI. Sensitive data just takes a different road.

public

Public / general

→ Approved cloud

OpenAI · Anthropic

sensitive

Personal data · secrets

→ Local EU model

Ollama · vLLM on your hardware

no route

No approved destination

→ 403 · fail-closed

Explained to the user · audited

Zero-agent deployment

One base URL. No software on laptops.

Sluss runs as a central proxy in your network. Block direct AI egress at the firewall and it becomes the only sanctioned path out.

Read the security briefing →
# before — straight to a US cloud
OPENAI_BASE_URL="https://api.openai.com/v1"

# with Sluss — inside your perimeter
OPENAI_BASE_URL="https://sluss.internal.example/v1"

The control plane

See every routing decision in one place.

Track where data went, what was blocked fail-closed, and the evidence behind every decision — live.

Sluss dashboard showing data routing, blocked requests, data classes, compliance evidence, and spend
Live routing overview · deterministic classification · audit evidenceOpen dashboard →

01 · Define the control

Policy that fails closed.

Turn data classes, agent capabilities and risk levels into enforceable routes. Start with DORA, GDPR or NIS2 baselines, then test every change before it goes live.

Sluss policy controls showing fail-closed routing rules, dry-run testing, and EU compliance packs

02 · See it enforced

Every decision, visible.

See sensitive requests blocked, approved workloads kept local, and low-risk traffic routed to cloud — with the reason, model and cost recorded for each decision.

Sluss request log showing sensitive data blocked, local routes, cloud routes, risk, model, and cost

Define the rule. Watch it hold. Hand the evidence to your auditor.

Explore the controls →

Four pillars

Built like a security control, not a proxy.

01

Classify

Deterministic rules, under 1 ms, no LLM in the loop. Swedish personal ID numbers validated with the Luhn check — not guessed.

02

Route

Fail-closed by design. If no approved destination fits, Sluss returns a 403 that says what was stopped and why — never a silent cloud fallback.

03

Prove

Every decision lands in a hash-chained audit log that can be verified offline by you or your auditor.

04

Gate

Agent permissions scoped to read, write, external and destructive actions. Tools only do what policy allows.

Why Sluss

Predictable enough for auditors. Simple enough for Monday.

Deterministic

Same input, same decision. Explainable to auditors.

Fail-closed, never silent

Uncertainty blocks — and the user is told why. It never leaks.

Self-hosted

Runs in your data centre or EU cloud. No call-home.

Evidence

Tamper-evident logs map directly to control frameworks.

Monitor mode first

Observe real traffic before enforcing a single rule.

ROI

Unblock AI projects already waiting on security sign-off.

Compliance packs

Start from a baseline, not a blank page.

DIR (EU) 2022/2555

NIS2 baseline

Incident-ready logging, supply-chain egress control and access gates for essential and important entities.

REG (EU) 2022/2554

DORA baseline

ICT third-party risk controls and audit evidence for banks, insurers and investment firms.

REG (EU) 2016/679

GDPR sovereign

Personal data stays on EU or local models. Transfers to third countries are blocked by default.

monitor mode→enforceObserve real traffic first. Switch when you're ready.

AI-powered regulatory scan

Which EU rules apply to your AI use?

Describe your organisation and how your teams use AI. Get an indicative first overview of relevant EU regulation in seconds. Not legal advice.

Your overview will appear here.

Compatibility

Drops into what you already run.

APIs

OpenAI + Anthropic compatible

Agents

MCP supported

Ship

Single binary

Deploy

60 seconds

Comparison

Gateways route. Sluss governs.

CapabilitySlussLiteLLMPortkeyUS cloud DLP
Egress control by data class●◐◐●
Deterministic classification●——◐
Self-hosted●●◐—
Tamper-evident audit●——◐
EU data sovereignty●◐——

● yes ◐ partial — no · Based on publicly documented default capabilities.

For customers

For CISOs, DPOs and IT leaders who need to say yes.

  • →Say yes to AI with controls your CISO and DPO can sign
  • →Keep sensitive prompts on local models, automatically
  • →Hand auditors verifiable evidence instead of screenshots
  • →Start in monitor mode — no disruption to teams
Book a demo

For partners

A reason to walk into every regulated account.

Unblocked AI deals

Remove the compliance objection that stalls projects in regulated accounts.

Hardware pull-through

Local models need GPUs. Sluss creates the reason to buy them.

Compliance retainers

Recurring policy tuning and evidence reviews for NIS2 and DORA.

60-second deployment

A single binary. Your first demo runs before the coffee does.

FAQ

Questions we hear from security teams.

Is Sluss really open source?+

Yes. The core is licensed under AGPL-3.0 and the source is on GitHub. You can audit every line that touches your data.

Does Sluss use an LLM to classify prompts?+

No. Classification is deterministic and runs in under a millisecond, so it is predictable, cheap and immune to prompt injection.

What happens if a destination is unavailable?+

Sluss fails closed and returns a 403 with a stable block code and a plain reason, so the client can explain the block instead of showing a raw error. It never silently reroutes sensitive data to a cloud you didn't approve.

Can we try it without blocking anything?+

Yes. Monitor mode logs every decision without enforcing it, so you can see real traffic before switching to enforce.

Which clients work with Sluss?+

Anything that speaks the OpenAI or Anthropic API, plus MCP-based agents. Usually it's a one-line base URL change.

Can a clever prompt trick the classifier?+

No. Rules match patterns and validate checksums — they don't read or follow instructions. There is no model in the loop to jailbreak.

Will strict rules block our teams?+

Rarely. Sensitive prompts are rerouted to a local model and still get an answer. Only requests with no approved destination are blocked — and you start in monitor mode.

What does a user see when a prompt is blocked?+

An explanation, not a mystery error. The response names the task class, the data class and the block code — classes only, never the prompt content. When a prompt is rerouted instead, the response says why and that it stayed in-house.

Do we install anything on employee devices?+

No. Sluss is a central proxy. Clients change one base URL, and you block direct access to public AI APIs at the firewall.

How do auditors verify the log?+

Each entry is hash-chained to the previous one. The chain can be verified offline with the included tool — no access to Sluss required.

Get started

Take back control of where your data goes.

Direct customer

I'm a customer

Reseller / partner

I'm a partner