
I've been using nRouter as the LLM gateway for our production workloads, and the guardrails are what stood out. Five checks fire on every request from day one: prompt-injection detection, PII redaction, secret scanning, abuse blocking, and response scanning.
What I like:Pre-call blocks cost $0 — inspection runs before any credit reservation, so blocked attacks never hit the bill
PII redaction is conversation-aware; replacement tokens persist across turns
Policy scopes (Org > Team > Key) mean the security floor can't be bypassed by a forgotten endpoint
Under 50ms of pre-call overhead Review collected by and hosted on G2.com.
Honest limits worth knowing: street addresses and personal names are deliberately out of scope for the PII scanner, and post-call blocks still incur provider cost since the upstream call already ran. Review collected by and hosted on G2.com.