Top 5 LLM Gateways with Built-in PII Filtering in 2026
Compare the top LLM gateway options with built-in PII filtering in 2026 on detection engines, redaction modes, response scanning, and deployment.
TL;DR
- An LLM gateway with built-in PII filtering scans prompts and responses for personal data and can detect, block, or redact each match before the text reaches a model provider or a log store.
- Bifrost combines a regex PII template, 222 built-in secret rules, Microsoft Presidio, and Azure AI Language PII, with three redaction modes that cover live traffic, Bifrost logs, and trace exports.
- LiteLLM and Kong AI Gateway redact PII through a separately deployed NLP service, while OpenRouter and Cloudflare AI Gateway run detection inside their hosted platforms.
- Cloudflare AI Gateway flags or blocks sensitive data with DLP profiles but documents no redaction action, and OpenRouter scans requests only, not model responses.
- Azure API Management was evaluated and left off this list because its AI gateway policies cover content safety, not PII redaction.
PII filtering in an LLM gateway is the control that keeps names, account numbers, health identifiers, and credentials in prompts from reaching third-party model providers and long-lived log stores. Bifrost, the open-source LLM gateway built in Go by Maxim AI, is the best choice for enterprises running mission-critical AI workloads that require best-in-class performance, scalability, and reliability, and it ships PII detection and redaction as native enterprise guardrails. This guide compares five LLM gateway options with built-in PII filtering on detection engines, redaction behavior, response scanning, and deployment model, so compliance and platform teams can choose the one that matches their data-handling obligations.
What Is PII Redaction in an LLM Gateway?
PII redaction in an LLM gateway is a policy step that scans request and response text for personal data and replaces each detected value with a placeholder before the text is forwarded or stored. Because every application calls models through the gateway, one redaction policy covers every team, model, and provider without changes to application code.
NIST SP 800-122 defines PII as information that can be used to distinguish or trace an individual's identity, alone or combined with other linked information. In LLM traffic, that information arrives as free text in prompts, retrieved context, and tool results. The OWASP Top 10 for LLM Applications lists sensitive information disclosure as LLM02:2025 and recommends data sanitization before user data enters a model.
A gateway applies one of three actions when a detector finds a match:
- Detect only: record the finding without changing the payload.
- Block: reject the request or response with a policy error.
- Redact: rewrite the matched span (for example,
alex@example.combecomes[EMAIL]) and forward the sanitized text.

Figure 1: A gateway gets two inspection points per request, and the log copy can be redacted even when the live payload is not.
As Figure 1 shows, a policy that redacts the provider call but stores raw text in logs still leaves PII at rest. The mechanics of PII filtering and compliance at the AI gateway layer cover this in more depth, and the Bifrost guardrails overview shows how detection policies attach to gateway traffic.
Key Criteria for Evaluating LLM Gateway PII Filtering
The criteria that separate PII filtering implementations are detection coverage, the actions available on a match, whether responses and tool calls are scanned, whether logs and exported traces are redacted, and where the redaction point sits relative to your network.
| Criterion | What to check | Why it matters for compliance |
|---|---|---|
| Detection engines | Regex, NLP entity recognition, secret scanning | Each engine misses what the others catch |
| Actions on match | Detect, block, redact, and replacement style | Blocking breaks workflows; redaction keeps them running |
| Response and tool-call scanning | Output scan, tool arguments, MCP results | Models and tools can return PII the prompt never contained |
| Log and trace redaction | Stored logs, exported traces, reveal controls | Logs are the longest-lived copy of a prompt |
| Reversibility | Placeholder mapping and who can reveal it | Investigations sometimes need the original value |
| Deployment boundary | Self-hosted, in-VPC, or hosted service | Decides who processes raw personal data |
| Policy scoping | Per team, key, model, or tool | Different data classes need different rules |
These criteria sit on top of the baseline gateway requirements covered in the broader production-ready LLM gateway comparison, which evaluates routing, failover, and governance.
Microsoft Azure API Management was evaluated against the same criteria. Its llm-content-safety policy sends prompts and completions to Azure AI Content Safety to block harm categories, blocklist terms, and prompt attacks, but no built-in PII redaction policy is published, so it is not ranked here.
PII Detection: Pattern-Based vs NLP-Based Engines
PII detection engines fall into three types: regex patterns for fixed-format identifiers, NLP entity recognition for names and addresses, and secret scanners for credentials. Each type misses what the others catch, so a production PII policy usually combines all three rather than choosing one.
| Engine type | Detects well | Misses or struggles with | Runtime cost |
|---|---|---|---|
| Regex patterns | SSNs, card numbers, emails, phone numbers, IP addresses | Names, locations, unformatted or international values | In-process, low |
| NLP entity recognition | Person names, locations, addresses, contextual entities | Uncommon name formats, short inputs without context | Network call to an analyzer; grows with payload size |
| Secret scanners | API keys, access tokens, private keys, JWTs | Personal data | In-process, low |

Figure 2: Most compliance policies need all three engines, because no single detector covers credentials, structured IDs, and names well.
Regex is fast and transparent, but it is not semantic classification. A regex PII template typically covers email, phone, SSN, card, and IP formats and does not attempt names, so names and addresses need an NLP analyzer such as Microsoft Presidio or Azure AI Language PII. Credentials belong to a dedicated scanner. A walkthrough of gateway-level PII redaction before provider transmission shows how these engines are layered in one policy.
LLM Gateways with PII Filtering Compared at a Glance
The five gateways below all detect PII in LLM traffic without custom code, but they differ on whether they can redact rather than only block, whether they scan model responses, and whether redaction happens inside your network. Each cell reflects what the vendor documents.
| Gateway | Detection engines | Actions on match | Scans responses | Log redaction | Deployment |
|---|---|---|---|---|---|
| Bifrost | Regex PII template, 222 secret rules, Microsoft Presidio, Azure AI Language PII | Detect, block, redact (replace, mask, hash) | Yes, plus MCP tool arguments and results | Yes: runtime, logs-only, or reversible | Self-hosted, in-VPC, on-prem |
| LiteLLM | Microsoft Presidio (Analyzer and Anonymizer containers) | Mask or block per entity type | Yes (output or both scope) | Yes (logging_only mode) |
Self-hosted proxy |
| Kong AI Gateway | Kong AI PII Anonymizer Service (Docker image) | Placeholder or synthetic replacement | Yes (v3.12+) | Not published | Kong Gateway or Konnect; AI Gateway Enterprise only |
| OpenRouter | Regex presets, Presidio-based NLP presets (beta), custom regex | Redact or block | No, requests only | Not published | Hosted service |
| Cloudflare AI Gateway | Cloudflare DLP profiles (predefined and custom) | Flag or block | Yes (request, response, or both) | Not published; findings are logged | Hosted on Cloudflare |
For the wider set of questions to ask during a gateway evaluation, the LLM gateway buyer's guide lists requirements beyond PII handling.
1. Bifrost
The Bifrost AI gateway unifies 25+ providers and 10,000+ models behind one OpenAI-compatible API, with PII detection and redaction delivered as enterprise guardrails. Bifrost guardrails can detect, block, or redact personal data in prompts, model responses, and MCP tool calls, and redaction extends to Bifrost logs and trace exports.
Best for: Bifrost is built for enterprises running mission-critical AI workloads that require best-in-class performance, scalability, and reliability. It serves as a centralized AI gateway to route, govern, and secure all AI traffic across models and environments with ultra low latency. Bifrost unifies LLM gateway, MCP gateway, and Agents gateway capabilities into a single platform. Designed for regulated industries and strict enterprise requirements, it supports air-gapped deployments, VPC isolation, and on-prem infrastructure. It provides full control over data, access, and execution, along with robust security, policy enforcement, and governance capabilities.
Bifrost adds 11 microseconds of overhead per request at 5,000 RPS in sustained benchmarks, and the same guardrail policies apply to every provider in the supported providers matrix. Bifrost guardrails are built from two objects: rules, written in CEL, decide when content is checked, and profiles decide how it is checked.

Figure 3: Rules decide when a check runs and profiles decide how it detects, so one PII policy can be reused across teams, models, and MCP tools.
Detection engines for PII and secrets
Bifrost ships three managed profiles (Custom Regex, Secrets Detection, and Prompt Guardrails) and integrates external providers, including two Microsoft PII engines. The four that handle PII and credentials are:
- Custom Regex: in-process RE2 patterns, with a PII Detection template for email, US phone, US SSN, credit-card-like numbers, and IPv4 addresses.
- Secrets Detection: 222 built-in rules for API keys, access tokens, private keys, and other credentials, with
ignored_secret_keywordsto suppress known false positives. - **Microsoft Presidio:** calls your own Presidio Analyzer endpoint, with entity filters and a
score_threshold(default 0.5). - **Azure AI Language PII:** PII category filters, an optional
phidomain for protected health information, Entra ID authentication, and alogging_opt_outsetting.
Presidio and Azure AI Language PII default to detect_only, so a policy that must rewrite data sets action: "redact" explicitly.
Redaction modes and strategies
Redaction modes decide where Bifrost applies the rewrite, and strategies decide the replacement value: replace ([EMAIL]), mask ([EMAIL:****************]), or hash (a deterministic short hash).
| Mode | Live request and response | Bifrost logs | Trace-export connectors |
|---|---|---|---|
runtime |
Redacted | Redacted | Redacted content only |
logs_only |
Left raw | Reversible placeholders | Placeholders |
runtime_reversible |
Reversible placeholders | Reversible placeholders | Placeholders |
Reversible modes store numbered placeholders such as [EMAIL-1] with a mapping kept on the log row. Only users holding the Logs:Reveal permission in role-based access control can see original values, the mapping is encrypted when an encryption key is configured, and it is never sent to export connectors.
LLM, MCP, and streaming coverage
Every rule targets either llm or mcp traffic. MCP rules redact tool arguments before execution and text results after it, and on LLM rules the four PII and secret profiles also scan tool-call arguments by default. On streaming output, runtime redaction checks buffered text segments before releasing them, while a block-capable rule holds the stream until the final decision. Redaction is text-based, and when two rewrite paths conflict on one phase, Bifrost fails closed.
Compliance controls around the policy
CEL rules can reference virtual_key, team, customer, and user, so PII policies can differ by tenant or business unit, with virtual keys acting as the identity each rule evaluates. Audit logs record administrative activity (who changed which configuration, and when) as HMAC-signed events exportable as JSON, JSON Lines, or Syslog. Data access control scopes which logs each role can read.
For data residency, in-VPC deployments keep the redaction point inside your own cloud account, and the Bifrost Enterprise tier adds clustering and identity provider integration. The guardrails resource hub collects the configuration patterns for these policies.
2. LiteLLM
LiteLLM is an open-source library and self-hosted proxy that implements PII masking through a Microsoft Presidio guardrail. Teams deploy the Presidio Analyzer and Anonymizer containers themselves, then configure LiteLLM to mask or block entity types before the model call, after it, or only in logs.
Documented PII capabilities:
- Guardrail modes
pre_call,post_call,logging_only, andpre_mcp_callfor MCP requests. - Per-entity
MASKorBLOCKactions, with optional confidence thresholds globally or per entity. - A
presidio_filter_scopesetting of input, output, or both. - An
output_parse_piiflag that restores masked tokens in the response without scanning it. - Ad hoc recognizers and per-request language selection.
LiteLLM's guardrail documentation lists secret detection and redaction as Enterprise-only, and the two Presidio containers become an operational dependency on the request path.
Best for: Python-centric teams already running the LiteLLM proxy that can operate Presidio containers alongside it.
Teams weighing a move can review the Bifrost LiteLLM alternative overview or a ranked list of LiteLLM alternatives in 2026.
3. Kong AI Gateway
Kong AI Gateway provides PII filtering through the AI PII Sanitizer plugin, which sends request or response bodies to a separate AI PII Anonymizer Service and forwards the sanitized result. The plugin is available only as part of Kong's AI Gateway Enterprise offering and requires the AI Proxy or AI Proxy Advanced plugin to be configured first.
Documented PII capabilities:
- An anonymizer service shipped as language-tagged Docker images, each bundling an NLP model and needing at least 600 MB of memory.
- Two anonymization modes:
placeholder(numbered placeholders) andsynthetic(a replacement word of the same type). - Categories including names and locations, phone, email, credit card, SSN, medical, passport, bank, national ID, and credentials.
- Per-request custom regex patterns and an optional restoration feature that reinstates original request data in responses.
- Response sanitization from Kong Gateway 3.12 onward.
Best for: organizations already standardized on Kong Gateway that hold an AI Gateway Enterprise license and can run the anonymizer service.
The plugin documentation does not describe redaction of stored gateway logs. Comparisons of Kong AI Gateway alternatives cover teams that want PII controls without a plugin chain.
4. OpenRouter
OpenRouter provides a Sensitive Info Guardrail that detects personal data in API requests and either redacts it with labeled placeholders or blocks the request with a 403 error. Detection runs on the input side only, covering message content, tool call arguments, and prompt strings, and it does not scan model responses.
Documented PII capabilities:
- Regex presets for email, phone, SSN, credit card, IP address, and provider-prefixed secrets.
- NLP presets for person names and addresses, built on Presidio and currently in beta.
- Custom regex patterns that redact to
[REDACTED]or block, validated against catastrophic backtracking. - Guardrails assigned per organization member or API key, where block takes precedence over redact.
OpenRouter documents that if a person-name or address check times out, the request proceeds rather than being blocked, and raw prompts reach OpenRouter before redaction because detection runs inside the hosted service.
Best for: teams that already buy model access through OpenRouter and need input-side redaction without operating their own gateway.
Teams that need the redaction point inside their own network can compare open-source LLM gateways for self-hosted deployments.
5. Cloudflare AI Gateway
Cloudflare AI Gateway applies Data Loss Prevention (DLP) to AI traffic using the same detection profiles as Cloudflare One. Policies can scan requests, responses, or both, and the documented actions on a match are flag (record the finding) or block (return an error); no redaction action is documented.
Documented PII capabilities:
- Predefined profiles for financial information, personally identifiable information, government identifiers, and healthcare information, plus custom profiles.
- DLP findings recorded in AI Gateway logs and in the
cf-aig-dlpresponse header. - Full buffering of streamed responses when response scanning is enabled, which increases time to first token.
- Cache hits served without re-running DLP, so policy changes do not re-evaluate cached responses.
DLP policies apply at the gateway level, so per-tenant policy differences require separate gateways, and a matched prompt is rejected rather than sanitized and forwarded.
Best for: teams already on Cloudflare that need to flag or block sensitive data and can accept rejection instead of rewriting.
A review of Cloudflare AI Gateway alternatives covers options for teams that need redaction instead.
Where Redaction Happens Matters for PII Compliance
PII compliance depends on where redaction happens, not only on whether it happens. A self-hosted LLM gateway redacts inside your network, so with runtime redaction the model provider receives only redacted values and no third-party gateway operator handles the raw prompt. A hosted gateway receives the raw prompt first, which makes its operator another processor of personal data under your compliance program.

Figure 4: With a hosted gateway, the redaction point sits outside your network, so the gateway operator becomes another processor of raw personal data.
Article 25 of the GDPR requires data protection by design and by default, and placing redaction at the first hop your organization controls is one practical way to apply that principle to LLM traffic. Regulated teams should also confirm how each gateway behaves under these conditions:
- Detector failure: whether a timed-out detector forwards the original text or stops the request.
- Log persistence: whether logs and exported traces hold raw values or placeholders.
- Reveal access: which roles can see original values.
- Response leakage: whether model outputs and tool results are scanned, not only prompts.
The patterns for PII redaction in regulated industries apply directly here, and healthcare teams can map these controls to the requirements on the Bifrost healthcare and life sciences page.
The Bifrost gateway addresses the boundary question by running inside your infrastructure, with enterprise deployment options for VPC, on-prem, and air-gapped environments. The request-path view of PII redaction before data reaches providers shows the same boundary in configuration terms.
The Bifrost AI security overview and a breakdown of LLM gateway security for prompt injection, PII, and audit compliance cover the adjacent controls.
Frequently Asked Questions
How do you mask PII data before sending it to an LLM?
Route every model call through an LLM gateway and attach an input guardrail that replaces each detected value with a placeholder such as [EMAIL] before the provider call. In the open-source Bifrost gateway, this is a Custom Regex, Presidio, or Azure AI Language PII profile set to action: "redact" on an input rule.
What PII needs to be redacted?
Redact any value that can identify a person alone or combined with other data: names, email addresses, phone numbers, government IDs such as SSNs and passport numbers, account and card numbers, health identifiers, IP addresses, and precise locations. Credentials are not personal data but leak through the same prompts, so scan them in the same pass.
What is PII in an LLM?
PII in an LLM context is personal data that appears in prompts, retrieved context, tool results, or model outputs. It can be exposed to model providers, stored in gateway logs, or repeated back in responses, and gateway-level filtering inspects all of these points in one place.
What is Microsoft Presidio?
Microsoft Presidio is an open-source framework for detecting and anonymizing PII in text. Its Analyzer service combines NLP named-entity recognition with pattern recognizers and returns each finding with an entity type, position, and confidence score. LLM gateways such as Bifrost and LiteLLM call a self-hosted Presidio Analyzer to detect names, locations, and other entities that regex patterns cannot reliably match.
What is the difference between PII masking and PII redaction?
PII redaction substitutes a label such as [EMAIL], while PII masking hides the value but preserves part of its shape, such as length. Bifrost supports replace, mask, and hash strategies, plus reversible redaction modes for log investigations.
Does an LLM gateway redact PII in model responses?
Some do and some do not. Bifrost, LiteLLM, and Kong AI Gateway (from version 3.12) can scan model responses, and Cloudflare AI Gateway can flag or block responses. OpenRouter documents its Sensitive Info Guardrail as input-only. Response scanning matters because models can repeat personal data from retrieved context or tool results that the prompt filter never saw.
Try Bifrost for PII Redaction
An LLM gateway with built-in PII filtering lets compliance teams enforce one redaction policy across every model, provider, and MCP tool. Bifrost combines regex, secret, Presidio, and Azure AI Language PII detection with redaction that covers live traffic, logs, and trace exports, all inside your own infrastructure. Browse the Bifrost resources for configuration guides, or book a demo with the Bifrost team to review your PII and compliance requirements.