$5 free credits when you sign up
Enterprise

The LLM gateway your security and procurement teams sign off on

Dedicated tenancy, VPC and private networking, BYO provider contracts, SSO/SAML, audit logs, residency pinning, a named CSM, and procurement-ready legal artifacts — deployed with confidence at scale.

enterprise · deployment · contract

What Enterprise includes

Platform fee0%
Deploymentmanaged / dedicated / VPC
Data residencyUS · EU · on request
SSO / SCIMenforced
Named CSMincluded
LegalDPA · MSA · BAA
SOC 2 controlsGDPRHIPAA BAAISO 27001-aligned
Platform fee, Enterprise
0%

No markup on inference

Uptime SLA
99.9%

Same SLA every tier

Residency regions
9

US + EU GA, more on request

Typical go-live
< 2 weeks

SSO, security review, DPA

Capabilities

Every enterprise control — on every tier

SSO, audit logs, guardrails, and RBAC are not an upsell. They ship to every customer from day one. Enterprise adds deployment, contract, residency, and support depth on top.

Routing, fallback & retry policies

Production resilience across 20+ models — usage/latency/cost routing, fallback chains, and per-org retry, timeout, and cooldown tuning.

  • Routing strategies: usage, latency, cost, shuffle, least-busy
  • Fallback chains retry on backup models on error or timeout
  • Tag-based capability routing — vision, code, long-context
  • Every routing decision captured in observability

SSO & SAML authentication

Single Sign-On for your whole org. SAML 2.0 and OIDC against Okta, Azure AD, Google Workspace, OneLogin, or any compatible IdP — with SCIM provisioning.

  • SAML 2.0 and OpenID Connect
  • Automatic user provisioning via SCIM
  • Enforce MFA policies from your IdP
  • JIT provisioning with role mapping

Audit logging

Append-only audit trail of every key, guardrail, budget, and team change — actor, timestamp, source IP, and payload diff — exportable for compliance reviews.

  • Full CRUD audit trail for all entities
  • Filter by actor, entity, time, IP, action class
  • CSV and JSON export for SIEM ingestion
  • Immutable — append-only retention

Guardrails on every request

PII redaction, prompt-injection detection, secret scanning, abuse blocking, and response scanning run on every request — included on every plan, scoped org > team > key.

  • PII redaction powered by Microsoft Presidio
  • Prompt-injection detection on adversarial corpora
  • API-key + secret scanner on prompts and completions
  • Per-request override semantics for advanced flows

RBAC & team management

Org → team → member hierarchy with Owner, Admin, Member, and Viewer roles enforced by Postgres Row-Level Security — not by application checks alone.

  • Four roles, RLS-enforced at the database layer
  • Per-team virtual keys, guardrails, and budgets
  • Per-key RPM/TPM caps and spend tracking
  • Single-team-per-user invariant, audited

White-label & custom branding

Brand the dashboard for your teams and downstream customers — your logo, your colors, your domain via CNAME, Nemo branding removed.

  • Custom logo and color scheme
  • Custom domain (CNAME) support
  • Branded API-key portal for end users
  • Remove Nemo Router branding
Deployment

Deploy NemoRouter the way your architecture demands

Most teams run on the managed multi-tenant gateway. Regulated and security-sensitive organizations can run dedicated, in their own VPC, or — on the roadmap — fully air-gapped. We are precise about what is GA today and what is a scoped engagement.

Generally available

Managed multi-tenant

The standard NemoRouter offering. Your org runs on shared, RLS-isolated infrastructure on Google Cloud Run + Supabase. Zero-config — sign up, buy credits, call the API.

  • Live in minutes, no infrastructure to run
  • Row-Level Security isolates every tenant at the database
  • US default region; EU residency on Enterprise
  • Best price-performance for most teams
Enterprise

Dedicated tenancy

A single-tenant NemoRouter deployment in an isolated project — your own database, your own routing engine, your own region pin. No noisy-neighbor surface at all.

  • Isolated Postgres + isolated routing engine
  • Dedicated capacity reservations for predictable throughput
  • Region pinned to your residency requirement
  • Independent maintenance window negotiated with your team
Enterprise — scoped per engagement

VPC / BYO-cloud

NemoRouter deployed inside your cloud account (GCP, AWS, or Azure) so prompts and keys never leave your network perimeter. Scoped as an Enterprise engagement.

  • Runs in your VPC / VNet under your IAM
  • Provider egress stays inside your network boundary
  • You own the data plane; we operate the control plane
  • Talk to sales — we scope the architecture with your cloud team
Roadmap — contact us

On-premise / air-gapped

Fully air-gapped, self-hosted NemoRouter for regulated environments. This is on the roadmap, not generally available — we will be candid about timelines on a call.

  • For environments where no traffic may reach a vendor cloud
  • Not GA today — we scope feasibility case by case
  • Bring your requirements; we will not over-promise a date

Dedicated, VPC, and on-premise deployments are scoped engagement-by-engagement. Talk to sales and we will design the topology with your cloud team — no over-promised timelines.

Dedicated tenancy

A single-tenant gateway, end to end

When shared infrastructure is not an option, the Dedicated tenancy SKU gives you an isolated NemoRouter deployment — your own database, your own routing engine, your own region — with no noisy-neighbor surface.

Enterprise SKU

Isolation at every layer, not just the row

Managed multi-tenant already isolates every org with Postgres Row-Level Security. Dedicated tenancy goes further: a separate project, a separate database, a separate routing engine, and dedicated capacity reservations so throughput is predictable under your peak load.

  • Isolated Postgres and isolated in-process routing engine
  • Dedicated provider-capacity reservations — predictable RPM/TPM
  • Region pinned to your residency requirement at provision time
  • Independent maintenance window negotiated with your team
  • All managed-tier features included — nothing is gated away
dedicated · tenancy · isolation

Single-tenant footprint

Databaseisolated project
Routing enginededicated instance
Region pinyour choice
Noisy-neighbor surfacenone
Capacityreserved RPM/TPM
single-tenantregion-pinnedreserved capacity
BYO provider contracts

Already have committed provider spend? Route it through Nemo.

The standard managed product is intentionally no-BYOK — you never touch a provider key. For Enterprise customers with existing committed-spend contracts, NemoRouter can route through that capacity while preserving your pricing and your provider relationship.

Enterprise-only capability

Bring your own provider contract

  • Standard NemoRouter is a fully managed gateway — you never touch a provider key, and that is the default for every self-serve plan.
  • Enterprise teams with existing committed-spend contracts (an Azure OpenAI PTU pool, a Vertex GSU reservation, a Bedrock provisioned-throughput commitment) can have NemoRouter route through that capacity.
  • Your committed pricing and your provider relationship stay yours; NemoRouter adds routing, guardrails, observability, and credit governance on top.
  • Provider credentials are scoped to your dedicated deployment and stored in an isolated secret store — never co-mingled with the managed multi-tenant key pool.
Not sure if this applies? If you hold an Azure OpenAI PTU pool, a Vertex GSU reservation, or a Bedrock provisioned-throughput commitment, talk to us about routing it through NemoRouter.
Private networking

Keep traffic off the public internet

TLS 1.2+ is the baseline on every plan. Enterprise adds IP allowlisting and private connectivity — PrivateLink, Private Service Connect, or Azure Private Endpoint — scoped to your network with our team.

TLS 1.2+ everywhere, HSTS preloaded

Every public endpoint enforces TLS 1.2+ with HSTS preload on the apex domain. This is the baseline on every plan — no configuration required.

IP allowlisting

Restrict dashboard and API access to your corporate egress ranges. Available on Enterprise — configured during onboarding with your network team.

PrivateLink / Private Endpoint

Reach NemoRouter over a private connection — AWS PrivateLink, GCP Private Service Connect, or Azure Private Endpoint — so traffic never traverses the public internet. Available on Enterprise / dedicated tenancy; contact sales to scope.

Data residency

Pin where your data is processed

United States is the default footprint. EU residency is generally available on Enterprise. UK, Canada, Australia, Singapore, and India are available on request for residency-sensitive workloads — customer data is replicated within a single region and never moved without an explicit migration request.

United States (us-central1)GA
US East (Virginia)GA
European Union (europe-west4)On request
EU North (Stockholm)On request
United Kingdom (London)On request
Canada (Montréal)On request
Australia (Sydney)On request
SingaporeOn request
India (Mumbai)On request

Need a region not listed? Ask sales — most major cloud regions can be supported on a dedicated deployment.

Compliance

Honest status on every framework

We state precisely where each framework stands — achieved, in progress, or available on request. We never imply a certification NemoRouter does not hold.

Audit in progress · Q3 2026

SOC 2 Type II

NemoRouter operates SOC 2-aligned security, availability, and confidentiality controls today — encryption, access control, change management, audit logging, tenant isolation. A formal SOC 2 Type II observation period is underway; the audited report is targeted for Q3 2026. Our infrastructure substrate (Google Cloud Run, Supabase) is already SOC 2 Type II certified.

Controls walkthrough
Aligned — certification planned

ISO/IEC 27001

Information security management practices aligned to ISO/IEC 27001 Annex A controls — asset management, access control, cryptography, operations security, supplier relationships. A formal ISO 27001 certification is on the roadmap; the infrastructure substrate (Cloud Run, Supabase) is independently ISO 27001 certified.

Controls walkthrough
Compliant — DPA available

GDPR

Compliant with the EU General Data Protection Regulation. Data Processing Addendum available for signature, EU Standard Contractual Clauses with subprocessors, data-subject access and erasure tooling built into the dashboard, and EU data residency available on Enterprise.

Read the DPA
BAA available on Enterprise

HIPAA

NemoRouter supports HIPAA-eligible workloads. A Business Associate Agreement (BAA) is available for healthcare customers processing protected health information — request one through the Enterprise team. PII redaction guardrails run on every request at no extra cost.

Request a BAA
Stripe PCI L1 — no card data on our servers

PCI DSS

NemoRouter never touches raw cardholder data. All payments are processed by Stripe, a PCI DSS Level 1 certified service provider; card numbers are tokenized client-side and never reach our servers or database. Your PCI scope for using NemoRouter is therefore minimal.

How payments work
US + EU GA · more on Enterprise

Data residency

Pin where customer data is processed and stored. US is the default footprint; EU residency is generally available on Enterprise, with UK, Canada, Australia, Singapore, and India available on request for residency-sensitive workloads.

Residency map

Full controls detail in the Security overview and the trust center.

Procurement

The paperwork your legal team will ask for

No back-and-forth chasing documents. The DPA and SLA are published and linkable. The MSA and a HIPAA BAA are issued on request through the Enterprise team.

Professional services

An implementation team, not just a login

Enterprise engagements come with people. An onboarding engineer configures the deployment, a migration plan maps your existing setup, and a security review clears the path to go-live.

Guided onboarding

A dedicated onboarding engineer configures SSO, provider routing, guardrail policy, and budgets with your team. Most enterprise deployments are production-ready inside two weeks.

Migration assistance

Moving off OpenRouter, a direct provider, or a self-hosted gateway? We map your existing model groups, fallback logic, and spend controls onto NemoRouter so the cutover is a base-URL change.

Security & architecture review

We walk your security team through the controls, answer the vendor questionnaire, and review the deployment architecture before go-live — auditor on the call welcome.

Customer success

A named CSM who knows your deployment

Enterprise is not a ticket queue. You get a named Customer Success Manager — a single accountable contact who knows your routing config, your spend pattern, and your roadmap.

Included on Enterprise

One accountable contact, quarterly reviews, priority response

Your CSM runs onboarding, joins quarterly business reviews, surfaces cost-optimization opportunities before they show up on an invoice, and is the escalation path when something needs a human in minutes — not a queue position.

  • Named CSM — a person, not a rotating inbox
  • Private support channel (Slack or Teams)
  • Quarterly business reviews on usage, spend, and roadmap
  • Priority incident response with guaranteed acknowledgement
  • Proactive cost and routing optimization recommendations
enterprise · customer success

Your success plan

Named CSMassigned
Support channelprivate Slack / Teams
Business reviewsquarterly
Incident responsepriority
Cost reviewsproactive
named contactQBRspriority SLA
Pricing

Self-serve for most teams. Talk to Sales for the rest.

Tiers 1–3 are transparently priced and self-serve — start in minutes on the pricing page. Enterprise is custom-quoted for large deals: dedicated capacity, custom contracts, residency pins, and a named CSM.

Self-serve (Tier 1–3)Enterprise
Platform fee
2–4%2–4%
0%0%
Deployment
Managed multi-tenantManaged multi-tenant
Managed, dedicated, or VPCManaged, dedicated, or VPC
Data residency
USUS
US, EU + on requestUS, EU + on request
Support
Email + communityEmail + community
Named CSM + private channelNamed CSM + private channel
Contracts
Standard ToS + DPAStandard ToS + DPA
MSA, BAA, custom termsMSA, BAA, custom terms
Onboarding
Self-serveSelf-serve
Guided — engineer-ledGuided — engineer-led
IncludedNot availableNot applicablenSourced footnote below

Large deal — committed volume above roughly $10K/month, a residency pin, or a custom contract? That is an Enterprise conversation.

FAQ

Enterprise questions, answered

For tier details, see the pricing page.

What's the minimum enterprise commitment?

Self-serve features — SSO, audit logs, guardrails, RBAC, custom branding — are included on every tier at no extra cost. Enterprise is for teams that need dedicated capacity, dedicated or VPC deployment, a named CSM, custom contracts, or a residency pin. It is custom-priced based on volume; talk to sales to scope it.

What deployment options do you offer?

Managed multi-tenant is generally available and the default. Dedicated single-tenant deployments and VPC / BYO-cloud deployments are Enterprise engagements scoped with your cloud team. Fully air-gapped on-premise is on the roadmap, not GA — we will be candid about timelines on a call rather than over-promising.

Can we use our own provider contracts (BYOK)?

The standard managed product is intentionally no-BYOK — you never handle a provider key. For Enterprise customers with existing committed-spend contracts (Azure OpenAI PTU, Vertex GSU, Bedrock provisioned throughput), NemoRouter can route through that capacity on a dedicated deployment, with your provider pricing preserved. This is an Enterprise-only capability — talk to us about your existing commitments.

Where can our data be processed?

United States is the default footprint. EU residency is generally available on Enterprise. UK, Canada, Australia, Singapore, and India are available on request for residency-sensitive workloads. Customer data is replicated within a single region and never moved without an explicit migration request.

Which compliance documents can procurement get?

The Data Processing Addendum (DPA) and SLA are published and linkable directly. The MSA and a HIPAA BAA are provided on request through the Enterprise team. NemoRouter operates SOC 2-aligned and ISO 27001-aligned controls; a formal SOC 2 Type II audit is in progress with a Q3 2026 target. Enterprise customers can request a controls walkthrough or a completed vendor security questionnaire from security@nemorouter.ai.

What's your SLA and support model?

A 99.9% uptime SLA applies on every tier; Enterprise adds priority incident response, a named Customer Success Manager, a private support channel, and quarterly business reviews. We monitor every provider endpoint and fail over automatically when an issue is detected.

Enterprise · scoped in days

Bring us your security review, your residency map, and your timeline

We walk your team through deployment options, the controls, and the DPA — typically scoped within days, live within two weeks. Auditors welcome on the call.

SOC 2 Type II audit in progress (target Q3 2026) · GDPR-compliant · HIPAA BAA available · ISO 27001-aligned controls