LiteLLM
BerriAI
Self-hostable AI gateway and Python SDK that calls 100+ LLM APIs in OpenAI format with virtual keys, spend tracking and guardrails.
Curated by Tiberiu ArvaVerified
Strengths
- Virtual keys with per-team spend tracking
- 100+ providers behind one OpenAI-format API
- Built-in MCP and agent gateway
Practitioner note
A common default for platform teams that want a self-hosted LLM proxy with per-team keys and budgets. Pin exact versions and verify release provenance: on 2026-03-24 malicious litellm 1.82.7 and 1.82.8 packages were published to PyPI with a credential stealer (the official Docker images were not affected), so anyone who installed them should rotate secrets.
Warning
Governance posture
Reviewed 2026-09-30When self-hosted, no data or telemetry is stored on LiteLLM servers; data stays in the operator's infrastructure.
SourceSelf-hosted proxy via CLI or Docker container; Terraform modules for AWS and GCP in the repo. (self-hosted)
SourceAudit logs exist but are listed as a LiteLLM Enterprise feature (commercial license).
SourceBerriAI states SOC 2 Type II, with the report in the LiteLLM Trust Center. Self-hosted deployments rely on the operator's own controls.
SourceISO 27001 is listed on trust.litellm.ai, but the public page did not confirm certification status; the data-security docs name only SOC 2 Type II.
ISO 42001 is listed on trust.litellm.ai, but the public page did not confirm certification status.
Routing and proxy infrastructure, not an AI system placed on the market; obligations rest with the deployer and model providers. (role: not-applicable)
MIT core, but enterprise/ is under a commercial BerriAI license that requires a subscription for production use. (medium)
SourceEU AI Act obligations
Risk tier: Not applicable · as of 2026-08-23Source-backed information mapped from LiteLLM's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.
This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.
Explore the category
Compare this tool against the rest of its category and the cloud platform foundation layer.
Return to the category grid to compare governance posture across every tracked tool.
Review Microsoft Foundry, Amazon Bedrock, and Gemini Enterprise Agent Platform as the foundation layer.
Track releases, deprecations, license changes, and other market movements.