Skip to content
THE AI GATEWAY THAT PROVES COMPLIANCE

Your engineers want frontier models.
Your regulator wants proof.

Sluis is the gateway in between: one API for every AI model that strips personal data from each prompt before it leaves, puts it back in the answer, and seals every passage in an audit ledger.

Get a key

First 50,000 tokens free

Now supporting Grok by xAI. One line of code. +1 ms measured overhead. No seats, no minimums.

one request · sealed round-triplive
YOUR APP · REQUESTAnna de Vries · anna@vandijk.nlSluisgateAnna de Vries · anna@vandijk.nl«NAME_1» «EMAIL_1»«NAME_1» «EMAIL_1»01inspect · dlp02route · residency03seal · ledgerROUTE · ANY MODEL, YOUR POLICYthe model only ever sees the tokenEUmistral/mistral-large · eu-parisin-regionUSopenai/gpt-5.1 · us-eastallowed · policyCNdeepseek/deepseek-v3 · cn403 · not in policy403 · not in policyRESPONSE · RESTORED TO YOUR APP◀ Anna de Vries · anna@vandijk.nl◀ Anna de Vries · anna@vandijk.nlsealed · #4f9c2a ✓sealed · #4f9c2a ✓
01 / API

One API for every model.

Drop-in and OpenAI-compatible: swap your base_url and you are behind the lock.

02 / INSPECT

Personal data stays inside.

Detection and reversible pseudonymization before anything leaves; the key never exits your perimeter.

03 / SEAL

Proof per request.

A sealed, hash-chained ledger records every passage, ready for your auditor.

04 / RESOLVE

Best model, still inside policy.

Call sluis/auto or a use-case alias; Sluis refreshes managed routes daily from Artificial Analysis and resolves the target inside your residency policy.

Why a lock

A lock does what no dam can: it holds back the sea and lets the ship through. It never opens both gates at once, and every passage goes in the keeper's ledger. Sluis does the same for AI traffic: your data sails through, what must stay inside stays inside, and every passage is provable.

Sluis is Dutch for canal lock.

One prompt, three views.

The same request: as your user types it, as the model receives it, and as your app gets it back.

What your user types
“Draft a payment plan for Anna de Vries, anna.devries@mail.nl, citizen ID 123456782.”
What the model sees
“Draft a payment plan for «PERSON_1», «EMAIL_1», «ID_1».”
What your app gets back
The full answer, with Anna back in place, restored mid-stream, no visible delay.
your apprequestSluis gatejohn@acme.com«EMAIL_1»«EMAIL_1»masks PIImodel«EMAIL_1»«EMAIL_1»token onlySluis gate«EMAIL_1»john@acme.comjohn@acme.comrestoresresponseyour appyour app · requestSluis masksjohn@acme.com«EMAIL_1»«EMAIL_1»PII stays insidemodel«EMAIL_1»«EMAIL_1»token onlySluis restores«EMAIL_1»john@acme.comjohn@acme.cominside the streamyour app · restored

Every request passes three gates.

No request skips a gate. None leaves without a record.

your app01inspect · dlp02route · residency03seal · ledgermistral · eu-parisscaleway · eu-amsopenai · us-eastallowed · policydeepseek · cn403 · not in policyyour app · request01inspect · dlp02route · residency03seal · ledgermistral · eu-parisscaleway · eu-amsopenai · us-eastallowed · policydeepseek · cn403 · not in policy

Inspect

The gate closes behind you.

60+ detectors scan every prompt before it leaves; what they find is reversibly pseudonymized.

Route

The water level equalizes.

You decide per key: which models, which region, whose ownership; a failed provider fails over automatically.

Seal

The passage goes in the ledger.

Every request gets a hash-chained entry: verifiable offline, exportable, erasable per person (GDPR Art. 17, or any right-to-delete duty).

A data center address is only half the answer.

An address says where a server stands, not who owns it. Legal reach follows ownership: a provider's parent company can be compelled under laws like the CLOUD Act.

  • Region and owner

    Where a model runs and who owns it are two different risks; Sluis labels both axes on every model in the catalog.

  • EU by default

    The default is the strictest setting: EU-owned providers on EU-region clouds only, until you deliberately allow more.

  • Per workload

    One key allows a frontier model for general drafting; another stays locked to the strictest route for anything personal.

residency.policy · class: PHIenforced
EU · France
mistral/mistral-large-latest
primary
EU · France
scaleway/llama-3.3-70b
fallback
EU · region
vertex/gemini-3.5-pro
allowed
United States
xai/grok-4.3
blocked · policy

Selling AI into Europe?

If your models or agents serve EU customers, Sluis is your compliance bridge: put the lock in front of your product and every call gains enforced EU residency, reversible pseudonymization, and a verifiable audit trail. No rebuild, one base_url.

  • EU residency, enforced on every request

  • Personal data pseudonymized before it reaches a model

  • An audit ledger your customers' auditors can verify themselves

Two readers. One gateway.

Whether you ship the code or sign off the risk, Sluis is built for you.

01

For engineering

Swap one base_url and you are behind the lock: OpenAI-compatible, streaming stays streaming, +1 ms measured.

Read the docs
02

For compliance

DPA, sub-processor list, DPIA input, and answers to your security questionnaire.

MCP / TOOL GATEWAY

Your agents leak through tools, not just prompts.

MCP tool calls pass the same three gates as any request: an agent reading your CRM is as watertight as your chatbot.

Deny-by-default grantsResidency-routed toolsSealed in the same ledger
See the MCP gateway →
tool.crm.readLIVE
01grant.customer.readALLOW
02anna@bedrijf.nl → «EMAIL_1»MASK
03route.eu-ownedEU
04sha256:8f21…b40aSEALED
Enterprise · optional

Need it on your own hardware? Run Sluis Edge.

The whole data plane as a single binary on your own iron: same gates, same ledger, your perimeter.

On your hardwareData never transits SluisOne console
See Sluis Edge →
SLUIS WORKBENCH

Turn a computer into a governed AI workforce.

Switch from Chat to Passage. Sluis turns the goal into a Passage Contract, routes it to an owner-activated Station, keeps work inside a Chamber, pauses sensitive actions at a Gate, and gives every successful verified outcome a Seal.

PASSAGE / 0241passage-contract.v3
CONTROLLED
  1. 01

    Passage Contract

    Agree the goal, limits, acceptance checks and budget before work starts.

  2. 02

    Station

    An owner explicitly activates a macOS, Windows or Linux computer for execution.

  3. 03

    Chamber

    Folders, applications, tools and collaborators stay inside one bounded workspace.

  4. 04

    Gate

    Shell, browser, computer and other high-impact actions pause for policy or human review.

    REVIEW
  5. 05

    Seal

    Every outcome carries the exact contract, actions, approvals, changes and checks.

    VERIFIED
SIMPLE TARIFF

The fee is for the lock, not the tokens.

Your provider's list price, plus a flat 10%. Your first 50,000 tokens are free.

See pricing
Compliance shouldn't mean giving up the best models. That's a false dilemma. You're just missing a lock.
Bas Alderding, founder
Chat · Passages · Stations

From a question to a verified outcome.

Use Chat for an answer or Passage for durable work. A Station executes inside a Chamber, risky actions stop at Gates, reusable Skills standardise the workflow, and every successful verified Passage ends with a Seal.

Open Sluis Chat →
Sluis Chat · PassageEU
YOU

Prepare the renewal, keep changes reversible, and stop before sending.

CONTRACT SETGATE APPROVEDSEAL VERIFIED
SLUIS / PASSAGE

Renewal prepared. No message was sent. Three checks passed and rollback evidence is attached.

seal · 8f21…b40a

Put the lock in between.

Get a key