One gate to
every AI model.
See every request, cap every budget and cut the bill by up to 74%. Zero code changes.
Your teams adopted AI overnight.
Your controls should keep up.
Torii is an enterprise AI gateway that sits between your people and every model they use.
It runs on your infrastructure. Your keys and your data never leave it.
One door to the models your teams already use:
- Llama
$15,917 became $4,163.
Same team, same models, same output.
— 7-person team, two months on Torii
Direct access ≠ control
Claude Code, Cursor and the SDKs talk straight to the provider. That leaves three gaps:
- 01The invoice has no names on it.
- 02Every key can call every model.
- 03Nothing an auditor would accept.
Fast for the team. Blind for everyone else.
A gateway between your teams and every model
Every request passes through Torii. It is priced, checked against budgets and access rules, and written to a tamper-evident log before it moves on.
Your apps change one line: the base URL.
Visible. Capped. Cheaper.
Pick Two Three
Measured at a live customer. Not a projection.
−74%less on the invoice
7 people · ~2 months · 30,297 requests · ~3.65B tokens
- 01Repeat work isn't billed twiceA repeat request never reaches the provider. It's still logged.
- 02Context stops snowballingLong agent loops stop paying for the same tokens every turn.
- 03Tools stay out of the promptCapabilities are carried by Torii, not re-sent to the model.
- 04Premium models where they matterAllow-lists keep the priciest models for the people who need them.
- 05Runaway loops hit a ceilingHard caps per user, team or key stop a loop before it burns the budget.
- And moreMany smaller optimisations run on every request, too.
Ready to take control? Meet the Torii panel.
Every rule you set is live on the very next request.
Join the waitlistBudgets
Per user, team or key. Soft or hard caps.
Access
Who gets which model, set once.
Audit
Hash-chained. Provable. EU AI Act ready.
Failover
Across regions and providers, automatically.
Deploy & connect
Single host
One installer. Preflight, keys and TLS included.
1command
$ curl -fsSL https://get.torii.io/install.sh | shKubernetes
One Helm release. The gateway scales on its own.
1Helm release
$ helm install torii oci://registry.torii.io/toriiOpenAI SDKs
Speaks /v1/chat/completions. Point the SDK, keep the code.
1line changed
$ base_url="https://torii.acme.com/v1"Claude Code
Speaks /v1/messages. Sees Torii as the Anthropic API.
0code changes
$ export ANTHROPIC_BASE_URL=https://torii.acme.com
Your infrastructure. Your rules.
Torii runs where your data already lives. No provider keys in the box, and no traffic through ours.
Talk to usIdentity
OIDC · SAML · SCIM
Your directory decides who gets in, and who is out the day they leave.
Audit
Tamper-evident
A hash-chained log you can verify from the panel in one click.
Providers
Your own hardware
Live now, alongside Bedrock and Vertex AI. Azure OpenAI is next.
Questions, answered.
Short answers to what teams ask first. For anything else, write to hi@toriigate.ai.
What is Torii?
Torii is a self-hosted enterprise AI gateway. It sits between your teams and every AI model they use, and prices, budgets, access-checks and audits each request before it moves on.
How long does it take to connect?
Only the base URL changes. Claude Code uses ANTHROPIC_BASE_URL and a token; OpenAI SDKs use base_url and api_key. No code, library or request schema changes.
Which providers and models are supported?
AWS Bedrock, Google Cloud Vertex AI and models on your own hardware are live, and Azure OpenAI is next. That covers Claude, GPT, Gemini, Llama, Mistral, Cohere and Amazon Nova, plus speech, image and embedding models, all under the same rules.
Where do our prompts and provider keys go?
Nowhere. Torii runs on your infrastructure, so prompts and credentials stay inside your perimeter. Provider keys are stored encrypted in the panel, never in a plain-text file.
How do we know the cost numbers are right?
Token counts come from the provider's reported usage, and every request is verified on top. Input, output, cache and reasoning are priced separately, and a model with an unknown price is flagged, never written as $0.
Does the 74% saving apply to every team?
No. It was measured on a 7-person team over about two months (30,297 requests). Agent-heavy workloads with a lot of repetition save more; short one-off requests save less.
Does the audit trail satisfy regulators?
Torii keeps a tamper-evident, append-only ledger per account, in line with EU AI Act Article 12, that you can verify from the panel or the API. Emails, cards, IBANs and API keys are redacted before anything is stored.
Does it work with our SSO?
Yes. People sign in through your identity provider over OIDC or SAML 2.0, and SCIM 2.0 provisions and removes accounts automatically, including revoking keys the day someone leaves.
Can we run Torii on Kubernetes?
Yes. One Helm release brings up the gateway, panel, data layer and ingress, with secrets generated inside the cluster. A single-command installer covers plain hosts.
AI your organisation can see. budget. audit. trust.
Torii is opening to a first group of teams. Leave your email and we'll write once, when your access is ready.
— The Torii team