Feature Guide · 1.10

What Smartflow does, and who else is in the room

The top features that matter in each category, why a buyer cares, and an honest check-box map against the largest name in that space. Split into the three surfaces Smartflow governs: LLM, MCP, and Agent.

How to read: Yes shipped Partial exists, narrower No not in product LLM MCP Agent

Jump to

Categories

Data sovereignty

Who else: Portkey (VPC / airgap), AWS Bedrock (region lock), TrueFoundry.

Regulated buyers can't let prompts, completions, or evidence leave a boundary they control. Sovereignty here means the inference path and the audit trail stay in the customer's tenant, region, and object store — not just "we're SOC 2."

01
Customer-VPC / airgap deploy

Runs inside your cloud or fully disconnected. FedRAMP / IL5 / GAIA-X SKUs, not a shared multi-tenant SaaS.

LLMMCPAgent
02
Region + FIPS + data-minimisation posture

Sovereignty tab shows where data sits and what's stripped before it moves. Posture you can hand an examiner.

LLM
03
WORM archive in your object lock

Evidence lands in your S3 / Azure / GCS / SnapLock with object-lock retention. Residency of the audit trail, not just live logs in our DB.

LLMMCPAgent
04
First-party Box / SharePoint connectors

Pull enterprise content without routing file bodies through a third SaaS middleman.

LLMMCP
05
Local model path (vLLM / Ollama / DeepSeek)

Route sensitive traffic to weights on your own hardware so inference never has to leave the box.

LLM
CapabilitySmartflowPortkeyAWS BedrockTrueFoundry
VPC / airgap deploy
Region + FIPS + minimisation posture view
WORM evidence in customer object lock
First-party content connectors (no 3rd SaaS)
Local / self-hosted model path

Identity

Who else: Portkey (virtual keys), Okta / Entra (SSO only), Cloudflare Access.

Provider API keys are the crown jewels, and "who called the model" has to survive an audit. Smartflow puts identity on the wire for humans, agents, and the device — not just an SSO login at the edge.

01
Virtual keys

Provider secrets never leave the gateway. Rotate or revoke without touching app code.

LLMMCP
02
Entra / Okta SSO with group sync

AD group maps to team, budget, and policy. Access changes flow from the directory, not a spreadsheet.

LLMMCPAgent
03
Layer-1 step-up (ID.me IAL2 / Nafath)

Force verified-identity re-auth on high-risk actions and seal it into the audit chain.

Agent
04
AIDA credentials for agents

Establishes who the agent is, not just the human who launched it — carried on egress.

Agent
05
Shield device / coding-agent identity

Ties a request to the laptop and the coding agent at the intercept point.

MCPAgent
CapabilitySmartflowPortkeyOkta / EntraCloudflare Access
Virtual keys (secrets stay in gateway)
SSO with group → budget / policy sync
Verified-identity step-up on risky actions
Agent identity credentials (AIDA)
Device / coding-agent identity at intercept

Audit

Who else: Portkey (audit DB), Langfuse, Datadog.

Most tools log requests to a database. An examiner asks a harder question: can you prove the record wasn't edited after the fact, and when exactly did it happen? Smartflow's trail is tamper-evident and independently verifiable, then fans out to the systems auditors already trust.

01
Per-request VAS traces

Every call carries user, model, cost, and risk tier. One record, not a metric and a log to reconcile.

LLMMCPAgent
02
HMAC tamper-evident chain

Records are hash-chained, and an open-source verifier lets a third party check the chain independently.

LLMMCPAgent
03
RFC 3161 timestamps + WORM

Trusted-time proof plus write-once storage. Examiner-grade, not "we keep logs indefinitely."

LLM
04
Control IDs and policy IDs on the request

1.10 stamps the control and policy that fired onto the record, so a finding maps straight to a rule.

LLMMCPAgent
05
One chain, many sinks

The same record exports to Splunk, OTel, and ServiceNow without re-deriving it per tool.

LLM
CapabilitySmartflowPortkeyLangfuseDatadog
Per-request trace with cost + risk tier
Tamper-evident chain + independent verifier
RFC 3161 trusted timestamps + WORM
Control / policy IDs on the record
Same record to Splunk / OTel / ServiceNow

Compliance

Who else: Portkey / Prisma AIRS, Enkrypt, Prompt Security.

Compliance can't be a nightly scan — it has to happen on the request, before the data moves. Smartflow inspects content inline, ties it to the framework that governs that team, and turns policy documents into checkable rules.

01
Inline compliance detector

PII, secrets, and regulated patterns caught on the request path — not flagged after the fact.

LLMMCP
02
Framework assignment by group

HIPAA, GDPR, PCI and more attach by directory group, so the right rules apply to the right team automatically.

LLM
03
Reversible PII tokenization

Opt-in tokenization keeps workflows usable so teams don't route around the gateway to get their data back.

LLM
04
Policy atomizer

Paste an acceptable-use doc and get discrete, checkable rules out — not a PDF nobody enforces.

LLMMCP
05
EU AI Act Conformity Console

Article-by-article evidence binder for a Notified Body — concrete conformity, not "audit-ready" blog copy.

LLMAgent
CapabilitySmartflowPrisma AIRSEnkryptPrompt Security
Inline PII / secret / regulated-pattern detect
Framework assignment by directory group
Reversible PII tokenization
Policy doc → checkable rules (atomizer)
EU AI Act article-level conformity binder

Governance

Who else: Prisma AIRS (network / CISO channel), LiteLLM (thin policy), Portkey.

Governance is only real if it's enforced on the request and it closes the loop back to the system of record. Smartflow attaches policy inline, gives risk a stop button, and pushes findings into the GRC tools the second and third lines already run.

01
Policy attachments, enforced inline

Bind policy to a virtual key, AD group, team, or model. Enforced on the call, not documented in a wiki.

LLMMCPAgent
02
Shield approval queue + emergency stop

Hold risky actions for human sign-off, or flip to read-only / halt when something's wrong.

MCPAgent
03
In-process red-team harness

Scores your own traffic and suggests rules. Nothing leaves the box to a third-party test service.

LLMAgent
04
Closed-loop GRC

Finding flows into ServiceNow / Archer / OneTrust and the closure flows back — not a one-way alert.

LLM
05
MCP trust registry

Unsigned or unapproved MCP servers don't get a tool call. Supply-chain control for agent tools.

MCPAgent
CapabilitySmartflowPrisma AIRSLiteLLMPortkey
Inline policy by key / group / team / model
Approval queue + emergency stop
In-process red-team harness
Closed-loop GRC (finding in, closure back)
MCP trust registry gating tool calls

FinOps

Who else: Helicone, CloudZero / Flexera, LiteLLM spend dashboards.

Cost tools show you the bill after it's spent. Because Smartflow is on the request path, the same trace that enforces policy also meters spend — so a budget breach can become a route change or a cap, not just another dashboard.

01
Spend off the same VAS trace

Cost by provider, model, user, and group from the record the gateway already enforces. No second pipeline.

LLMMCPAgent
02
Budgets with burn-rate forecast

Forecast the overrun and stage a policy in response — not an email that lands after the money's gone.

LLM
03
Reconciliation: billed vs metered

Surfaces ungoverned spend — traffic that bypassed the gateway — by comparing provider bills to what we metered.

LLM
04
Anomaly → draft policy

A spend spike turns into a proposed rule you can review and enforce, closing the loop on runaway cost.

LLM
05
Savings next to the bill

Cache and token savings shown against actual spend — enforcement plus visibility, not invoice-only.

LLM
The line for sales: Ramp, Flexera, and Helicone see spend. Smartflow can cap and reroute it, because it's the thing making the call.
CapabilitySmartflowHeliconeCloudZero / FlexeraLiteLLM
Spend by provider / model / user / group
Budget breach → enforced policy / reroute
Billed-vs-metered bypass reconciliation
Anomaly → draft policy from the spike
Cache / token savings next to the bill

Routing

Who else: LiteLLM, Portkey, Kong AI Gateway.

Routing is table stakes, so the question is what it's tied to. Smartflow's routing is drop-in for the SDKs teams already use, and every route decision can be driven by the same policy and identity the rest of the platform enforces.

01
Drop-in OpenAI + native Anthropic

Point the base URL at the gateway. No app rewrite for either endpoint style.

LLM
02
Fallback chains

Retryable vs non-retryable failures handled distinctly, so a provider blip doesn't take the app down.

LLM
03
Policy-driven route

Send group X to a cheaper model, or a regulated team to a compliant one — as a rule, not a code branch.

LLM
04
Local / Azure / Vertex / DeepSeek

Self-hosted and cloud targets are first-class, so sovereignty routing is a config choice.

LLM
05
Virtual-key model allow-lists

Scope which models a key can reach, so access control and routing are the same control.

LLM
06
Lowest-cost / effort router

Easy turns go cheap, hard turns stay on the model you asked for. Same scorer in Smartflow and Halo. Install notes.

LLM
CapabilitySmartflowLiteLLMPortkeyKong AI GW
Drop-in OpenAI + native Anthropic
Fallback chains (retryable vs not)
Policy / identity-driven routing
Local / self-hosted as first-class target
Virtual-key model allow-lists
Lowest-cost / effort router (prompt-scored cheap lane)

Performance (cache)

Who else: LiteLLM (exact + Qdrant semantic), Portkey (semantic cache), Helicone.

Caching cuts cost and latency, but most semantic caches need a vector DB bolted on. Smartflow does semantic caching in-process and extends it past the LLM into MCP tool calls and multi-step agent runs.

01
Exact + intent + VectorLite semantic cache

Semantic hits without a sidecar vector DB to run and secure. One less dependency in the boundary.

LLM
02
In-flight compression + HHEM check

Compress context on the way through, with an optional faithfulness check so you don't cache a hallucination.

LLM
03
Provider prompt-cache injection

Uses the provider's own prompt-cache when it's cheaper, so you don't pay twice for the same prefix.

LLM
04
MCP discovery + tool-call cache

Caches tool discovery and repeat calls, and reports the measured percentage of calls avoided.

MCP
05
Trajectory cache

Reuses results across repeated multi-step agent tasks so the same plan doesn't re-run from scratch.

Agent
CapabilitySmartflowLiteLLMPortkeyHelicone
Semantic cache without sidecar vector DB
In-flight compression + faithfulness check
Provider prompt-cache injection
MCP discovery + tool-call cache
Trajectory cache for agent tasks

By surface

LLM LLM

Who else: LiteLLM, Portkey, Cloudflare AI Gateway.

On the model surface Smartflow is a drop-in gateway that also enforces policy on the completion. You get the routing and cache incumbents offer, plus inline governance on the same request.

Protocol-native capabilitySmartflowLiteLLMPortkeyCloudflare AI GW
Drop-in /v1 + Anthropic /messages
Streaming
Virtual keys
Semantic cache (no sidecar)
Inline policy on completions

MCP MCP

Who else: LiteLLM MCP, generic MCP hosts (Claude Desktop / Cursor), Cloudflare.

MCP hosts connect tools; they don't govern them. Smartflow sits in front of the tool call — gating which servers are trusted, which groups reach which tools, and holding destructive calls for approval.

Protocol-native capabilitySmartflowLiteLLM MCPMCP hostsCloudflare
Trust registry (signed / approved servers)
AD-gated tools by group
Discovery cache
Trajectory cache
Shield on destructive tool calls
Per-server cost attribution

Agent Agent

Who else: Google A2A (protocol), LangGraph / CrewAI (orchestration), Portkey.

Orchestration frameworks build agents; they don't sit on the wire when the agent acts. Smartflow is the enforcement point for agent-to-agent traffic — identity, risk tiers, approval, and a signed identity on egress.

Protocol-native capabilitySmartflowGoogle A2ALangGraph / CrewAIPortkey
A2A gateway + Agent Cards
AIDA agent credentials
Action-risk tiers (T1–T3)
Human approval on high-risk actions
Signed identity on egress (Web Bot Auth)

Where others still win

Don't get blindsided on a call. Say this before the prospect does.

They usually win on: provider catalogue size (LiteLLM, Portkey), a polished prompt / eval studio (Portkey), the self-serve OSS flywheel (LiteLLM), and the CISO network channel (Palo Alto Prisma). If the buyer just wants "another gateway" or the widest model list, that's their turf.

One thing they do not have: an independent chain verifier a regulator can build and run. audit-verifier — MIT, crate tarball on that page, sample chain included. Exit 0 means the HMACs and prev_hash links check out.
We win when the buyer is compliance, risk, a regulator, or finance that can actually enforce. Tamper-evident audit, WORM in their own object store, inline policy across LLM / MCP / Agent, closed-loop GRC, and FinOps that caps and reroutes instead of just reporting. The further the conversation gets from "cheapest proxy" and toward "prove it to an examiner," the stronger we are.

APERION Smartflow · Feature Guide 1.10 · Capability claims reflect shipped product; competitor cells are value-level and current at time of writing.