Skip to main content
Comparison

Arbitex Gateway vs. Portkey

Portkey is a developer-focused AI gateway built for engineering teams managing multi-model LLM traffic — routing, load balancing, caching, and observability. Its buyer is the engineering lead. Its product is bought to solve an infrastructure problem. When the compliance officer, CISO, or CCO enters the conversation — as regulators and examiners increasingly require — Portkey's governance gap becomes visible immediately. Arbitex Gateway is built for the buyer who owns the compliance problem.

Feature Comparison

CapabilityPortkeyArbitex Gateway
Pre-built compliance bundles (GLBA, SOX, BSA/AML, SEC Reg FD) No compliance bundles for any financial services framework — no GLBA, SOX, BSA/AML, or SEC Reg FD mapping; every control must be custom-built and custom-maintained by the institution's own engineering team 12 compliance frameworks enforced as executable policy bundles — activate a framework and the correct detectors, enforcement actions, and audit controls apply automatically at the model boundary
Audit log retention adequate for SEC Reg FD (6-year requirement) Production tier imposes a 30-day default log retention cap — a 72-month gap against SEC Reg FD's six-year minimum retention requirement for broker-dealer electronic records Full retention capability designed for regulatory examination — 90-day audit buffer with SIEM-ready export to all 7 connectors; retention period configurable to meet framework requirements
Tamper-proof audit logging Observability-grade telemetry — latency, token counts, error rates; not a cryptographically chained, tamper-evident record structured for SEC or FINRA examination tamper-proof audit log — every request, every enforcement decision captured in a cryptographically verifiable, immutable record that survives regulatory examination
Real-time DLP inspection and MNPI detection No DLP layer — no pattern matching, no ML-based entity detection, no inspection or enforcement at the model boundary; MNPI in trading desk prompts reaches AI providers undetected 80+ pattern detectors + ML-based entity recognition — dual-method DLP inspects every request and response; MNPI-adjacent content flagged or blocked before reaching any AI provider
Hybrid deployment — NPI data stays in your infrastructure SaaS-only — no hybrid deployment option, no customer VPC model; institutions where NPI is in the AI prompt stream cannot use Portkey under GLBA Safeguards Rule data classification requirements Hybrid Outpost — data plane runs inside the institution's own VPC; AI traffic inspected and governed before it leaves their environment; only policy config and anonymized telemetry reach Arbitex systems
RS256-signed OAuth tokens with JWKS key discovery Shared-secret (HS256) token model — both issuer and verifier must hold the same secret; no JWKS endpoint for automated key discovery; no kid-based key rotation; compromise of the shared secret affects all tokens RS256 asymmetric signing — private key signs, public key verifies via JWKS endpoint at /.well-known/jwks.json; zero-downtime key rotation via kid claims; compatible with any standard JWT library
Enterprise SIEM integration (7 connectors) Observability data is developer tooling — institutions running Splunk, Sentinel, Elastic, Datadog, Sumo Logic, QRadar, or Cortex XSIAM must build custom integrations to ingest Portkey data into their SOC Native connectors for all 7 SIEM platforms — Splunk, Microsoft Sentinel, Elastic, Datadog, Sumo Logic, IBM QRadar, and Cortex XSIAM; AI governance events flow directly into existing SOC tooling
Vendor accountability and compliance audit support Engineering lead owns the compliance controls they built on Portkey — no vendor support for custom compliance configurations, no attestation documentation, no vendor accountability when examiners ask Purpose-built AI governance platform — compliance controls are vendor-maintained, vendor-supported, and designed to meet the evidence requirements of OCC, SEC, and FINRA examination

Where Arbitex Gateway Wins

30-day log retention against a six-year SEC requirement

Portkey's Production tier retains logs for 30 days. SEC Reg FD requires broker-dealers to retain electronic communications and associated records for a minimum of six years, with the first two years in an immediately accessible format. The gap between 30 days and six years is not a configuration problem — it is a product architecture that was not designed for regulated financial services workloads. Beyond retention period, Portkey's logs are observability telemetry — not the non-alterable, evidence-grade records that SEC and FINRA examination practice requires. Arbitex's tamper-proof audit log is designed for evidence-grade retention: immutable, verifiable, and structured for regulatory examination from day one.

MNPI at the model boundary is an enforcement surface, not a policy document

Trading desk AI workflows — analyst summarization, research assistant tools, deal analysis — routinely handle prompts that may contain material non-public information. Portkey has no DLP layer, no detection of MNPI-adjacent content patterns, and no policy enforcement at the model boundary. An institution that routes trading desk AI traffic through Portkey has no mechanism to prevent MNPI from reaching an external AI provider and no record demonstrating that MNPI was not transmitted. Arbitex inspects every request in real time — 80+ pattern detectors combined with ML-based entity recognition — and flags or blocks MNPI before the request reaches any model, producing a verifiable record that it did.

Shared-secret tokens versus RS256 asymmetric signing

Portkey authenticates integrations using API keys and, where tokens are issued, uses the HS256 shared-secret model. HS256 requires both the token issuer and the verifier to hold the same secret — if that secret is exposed anywhere in the institution's infrastructure, all tokens issued with it are compromised. There is no JWKS endpoint for automated public key discovery and no kid-based key rotation mechanism. Arbitex issues RS256-signed OAuth tokens: asymmetric cryptography where the private key signs and the public key verifies via the JWKS endpoint at /.well-known/jwks.json, with zero-downtime key rotation via kid claims. For financial institutions where the vendor risk management program evaluates credential security and key management practices, this is a verifiable architectural gap in Portkey's credential model.

The compliance officer is not Portkey's buyer — until it is your problem

Portkey is sold to engineering leads. It has no compliance narrative for financial services — no GLBA framing, no SOX positioning, no SEC Reg FD audit trail story. The engineering lead who deployed Portkey does not hold the compliance accountability that GLBA, SOX, and SEC Reg FD assign to the institution. When the compliance officer, CISO, or CCO is brought into the conversation — as examiners increasingly require — Portkey's governance gap becomes visible immediately. Any compliance controls the institution built on top of Portkey are now the institution's own compliance liability, with no vendor accountability behind them. Arbitex is sold to the buyer who owns the compliance problem.

Related Resources

Compliance Frameworks

Pre-built regulatory policy packs

Audit Log

Tamper-evident activity trail

DLP Protection

Inspect every AI prompt for sensitive data

Financial Services

PCI-DSS and SOX compliance

Built for the compliance officer, not just the engineering lead.

Govern every AI request across 9+ providers. Enforce GLBA, SOX, and SEC Reg FD at the model boundary. Produce the tamper-evident audit record that holds up in an OCC or SEC examination.