LiteLLM

BerriAI

Open Source

Self-hostable AI gateway and Python SDK that calls 100+ LLM APIs in OpenAI format with virtual keys, spend tracking and guardrails.

Curated by Tiberiu ArvaVerified

MIT core + EE pathsVersion 1.103.1Released 2026-09-30

Strengths

  • Virtual keys with per-team spend tracking
  • 100+ providers behind one OpenAI-format API
  • Built-in MCP and agent gateway

Practitioner note

A common default for platform teams that want a self-hosted LLM proxy with per-team keys and budgets. Pin exact versions and verify release provenance: on 2026-03-24 malicious litellm 1.82.7 and 1.82.8 packages were published to PyPI with a credential stealer (the official Docker images were not affected), so anyone who installed them should rotate secrets.

Warning

LiteLLM: Open core: code outside the enterprise/ directory is MIT, but enterprise/ is under the BerriAI Enterprise License, which allows production use only with a paid BerriAI subscription (dev/test use is free). Enterprise features such as SSO and audit logs sit behind that license.

Governance posture

Reviewed 2026-09-30
YesData residency

When self-hosted, no data or telemetry is stored on LiteLLM servers; data stays in the operator's infrastructure.

Source
YesDeployment model

Self-hosted proxy via CLI or Docker container; Terraform modules for AWS and GCP in the repo. (self-hosted)

Source
PartialAudit logging

Audit logs exist but are listed as a LiteLLM Enterprise feature (commercial license).

Source
YesSOC 2

BerriAI states SOC 2 Type II, with the report in the LiteLLM Trust Center. Self-hosted deployments rely on the operator's own controls.

Source
UnknownISO 27001

ISO 27001 is listed on trust.litellm.ai, but the public page did not confirm certification status; the data-security docs name only SOC 2 Type II.

UnknownISO 42001

ISO 42001 is listed on trust.litellm.ai, but the public page did not confirm certification status.

N/AEU AI Act

Routing and proxy infrastructure, not an AI system placed on the market; obligations rest with the deployer and model providers. (role: not-applicable)

YesLicense risk

MIT core, but enterprise/ is under a commercial BerriAI license that requires a subscription for production use. (medium)

Source

EU AI Act obligations

Risk tier: Not applicable · as of 2026-08-23

Source-backed information mapped from LiteLLM's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.