Neither a self-hosted nor a cloud-hosted AI gateway is automatically more secure. Self-hosting gives your organization more direct control over gateway infrastructure and its data stores, but makes you responsible for operating and securing them. A managed gateway can simplify operations and centralize routing, but adds the service provider to the request and credential trust boundary. Compare the actual data path, key custody, authorization scope, logging, isolation, and your team’s ability to operate the system—not just the hosting label.
First, separate gateway hosting from model hosting
An AI gateway routes requests between an application and one or more model providers. Choosing where the gateway runs does not by itself determine where inference happens. A self-hosted gateway can still forward prompts and other request data to a remote model provider; that provider remains part of the data path. Assess the gateway’s location and the model’s location separately.
For example, LiteLLM documents deployments in infrastructure selected and operated by the organization, while Cloudflare describes a managed API route to models hosted by Cloudflare or third parties such as OpenAI, Anthropic, and Google. Those examples illustrate two deployment patterns; they do not establish the properties of every product in either category. LiteLLM production deployment documentation · Cloudflare AI Gateway REST API documentation
What does self-hosting put under your control?
With a self-hosted gateway, your organization chooses and operates the environment in which the gateway runs. LiteLLM documents Kubernetes deployment with Helm on EKS, GKE, or AKS, and official Terraform modules for AWS and Google Cloud; its guide identifies AKS with Helm as the supported Azure path. Its architecture can be a monolithic service or separate gateway, backend, and UI components. LiteLLM production deployment documentation
Recommended Free Tools
#1 Best Overall
That control comes with operating responsibilities. LiteLLM’s production reference architecture includes PostgreSQL for keys, teams, users, spend logs, and configuration; Redis for rate limiting, router state, and cross-instance caching; and managed secrets for master and provider keys. Its guide says PostgreSQL is required for proxy authentication and tracking features, and Redis is required when running more than one instance. The organization must plan deployment, configuration, patching, availability, secret handling, and monitoring for the components it uses. LiteLLM production deployment documentation
Self-hosting can let you choose the gateway environment and manage its boundary directly. It does not remove upstream model providers from that boundary when requests are sent to them, nor does it prove that prompt data stays within a private network.
Rank #2
What changes with a cloud-hosted gateway?
A managed gateway reduces the need to deploy and operate gateway servers yourself. Cloudflare describes AI Gateway as a common route to models hosted by Cloudflare or third parties, with features including logging, caching, and rate limiting. Its API offers an envelope endpoint and OpenAI-compatible chat-completions and Responses API endpoints; Responses support depends on the model. Authentication and billing are managed through a Cloudflare account. Cloudflare AI Gateway REST API documentation
The trade-off is that gateway traffic passes through the managed service. Before using it, check the current data-handling, logging, retention, and plan terms for your configuration. A managed gateway can centralize routing and controls, but your organization still needs to manage account permissions, application integration, tokens, and policy settings.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Compare the security and control trade-offs
| Decision area | Self-hosted pattern: LiteLLM documentation | Cloud-hosted pattern: Cloudflare documentation | Question to resolve |
|---|---|---|---|
| Gateway infrastructure | Deploy and scale gateway services and supporting database or cache infrastructure in selected cloud accounts or Kubernetes. Source | Use the vendor’s API endpoint and account-managed service. Source | Who owns hardening, patching, availability, and incident response for the gateway layer? |
| Prompt and response path | The gateway can run in organization-selected infrastructure, but remote model calls can still send prompts to an upstream provider. Source | The gateway documents logging and caching features; confirm current retention and data-processing terms for the selected configuration. Source | Which systems can see request content, and which systems retain it? |
| Provider-key custody | The operator must protect configured master and provider keys; LiteLLM’s AWS example places secrets in a secrets manager. Source | Cloudflare’s BYOK feature lets administrators store provider keys in its dashboard rather than send a provider key with every request. Documented controls include rotation, revocation, multiple keys, and aliases. Source | Who stores each credential, who can use it, and how quickly can it be revoked? |
| Authentication and scope | The operator chooses and configures the gateway’s authentication and deployment boundary. LiteLLM documents virtual keys and per-key, team, and user budgets. Deployment · Getting Started | Authenticated Gateway requires a Cloudflare API token when enabled. Cloudflare says AI Gateway Read, Run, and Edit permissions are account-scoped, not restrictable to one gateway; it recommends separate accounts or a Worker-side binding for isolation. Source | Are credentials narrowly scoped to the needed tenant, gateway, model, and action? |
| Policy and inspection | LiteLLM’s overview documents centralized logging, guardrails, and caching; exact controls depend on the chosen setup and configuration. Source | Cloudflare’s wrapper tutorial documents optional prompt and response guardrails, Access policies, DLP profiles, isolated browser sessions, prompt and response visibility, usage views, and log export. Source | Which controls apply before data leaves the user boundary, in the gateway, and at the model provider? |
| Operational burden | The organization operates the gateway and its supporting services, including the documented multi-replica and database/cache considerations. Source | The vendor operates the gateway service, while customers manage account permissions, tokens, application integration, and policy configuration. Service · Permissions | Does your team have the staffing and operational controls to run the gateway securely? |
These are documented product behaviors, not an independent security audit or a universal scorecard. The table does not establish that either product is compliant, private, or more secure in every deployment.
How to choose for your organization
- Map the data path. Trace prompts, responses, metadata, and logs from the application through the gateway to the model provider. Identify which systems can process or retain each item.
- Map every credential. Record who stores and uses gateway tokens and provider keys, what each credential can access, and how revocation works. For Cloudflare Authenticated Gateway, account-scoped permissions may make separate accounts or a Worker-side binding relevant to isolation.
- Set the required boundaries and policies. Identify where authorization, tenant isolation, guardrails, DLP, and logging must apply. Check the exact product configuration rather than assuming a feature is enabled or applies to every request.
- Assess operational capacity. If self-hosting, decide who will deploy, patch, monitor, scale, and respond to incidents across the gateway and its dependencies. If using a managed gateway, assign ownership for account permissions, tokens, integrations, and policy configuration.
- Verify current terms and configuration. Review the selected service’s data handling and retention terms, and verify the model provider’s role in processing. A gateway choice cannot answer those questions on its own.
What the choice comes down to
Self-hosting is a fit when direct control of the gateway environment matters and the organization can securely operate its services and dependencies. A cloud-hosted gateway is a fit when reducing gateway operations is valuable and the organization accepts the managed service as part of its request path, after checking its scope, data handling, and isolation. The defensible choice comes from the full data and credential flow and the team’s ability to manage it—not the words “self-hosted” or “cloud.”
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

