Portkey vs TrueFoundry
Managed Gateway or Private AI Platform?Portkey 与 TrueFoundry:托管网关,还是私有 AI 平台?
Portkey offers a managed gateway-centered suite with routing, guardrails, observability, prompts, and administration. TrueFoundry spans managed gateway options, private gateway deployment, model and service deployment, agents, MCP, governance, and cloud infrastructure. The boundary matters more than the checklist.
Portkey 提供以托管网关为中心的路由、护栏、可观测性、提示词与管理套件;TrueFoundry 则横跨托管/私有网关、模型与服务部署、智能体、MCP、治理和云基础设施。控制边界比功能清单更重要。

TL;DR
Choose it when teams want routing, policy, guardrails, logs, traces, prompts, budgets, and administration without adopting a wider deployment platform.
Choose it when the same system must cover gateway planes, private networking, model deployment, agent workloads, MCP, governance, and cloud operations.
Separate data plane, gateway plane, control plane, compute plane, metadata stores, telemetry, secrets, upgrades, backup, and support responsibility.
Decide what must stay in the VPC, what may be SaaS, who can push policy, and which team owns outages before comparing features.
适合希望获得路由、策略、护栏、日志、追踪、提示词、预算与管理,但不想采用更广部署平台的团队。
适合同一系统需要覆盖网关平面、私有网络、模型部署、智能体工作负载、MCP、治理和云运营的组织。
应分别明确数据面、网关面、控制面、计算面、元数据存储、遥测、密钥、升级、备份和支持责任。
在比较功能前,先决定什么必须留在 VPC、什么可用 SaaS、谁能发布策略、哪个团队负责故障。
Managed suite and deployment platform are different scopes托管套件与部署平台是不同范围
Portkey's core is a gateway-centered production suite. Official documentation covers a universal API gateway, routing configs, guardrails, observability, prompt management, budgets, limits, administration, and an open-source gateway path.
Portkey 的核心是以网关为中心的生产套件。官方文档覆盖通用 API 网关、路由 Config、护栏、可观测性、提示词管理、预算、限额、管理和开源网关路径。
TrueFoundry's scope includes deployment and infrastructure boundaries. Current documentation describes managed global gateway, deployable gateway plane, full control and compute planes, model and service deployment, agent and MCP access, governance, key management, monitoring, cloud-agnostic installation, and Kubernetes-oriented operations.
TrueFoundry 的范围包含部署与基础设施边界。当前文档描述托管全球网关、可部署网关 Plane、完整 Control/Compute Plane、模型与服务部署、智能体/MCP 访问、治理、密钥管理、监控、云中立安装和 Kubernetes 运营。
Portkey vs TrueFoundry side by sidePortkey 与 TrueFoundry 并排比较
| Decision surface决策面 | Portkey | TrueFoundry |
|---|---|---|
| Primary scope主要范围 | Managed gateway, guardrails, observability and prompt operations托管网关、护栏、可观测性与提示词运营 | AI gateway plus deployment, agents, MCP and infrastructure governanceAI 网关加部署、智能体、MCP 与基础设施治理 |
| Control boundary控制边界 | SaaS-centered suite with gateway self-host options to validate以 SaaS 为中心,需验证网关自托管选项 | Managed SaaS gateway, deployable gateway plane, or broader self-host platform托管 SaaS 网关、可部署网关面或更广自托管平台 |
| Model lifecycle模型生命周期 | Route and govern calls to providers路由并治理对供应商的调用 | Deploy and operate models/services in addition to routing除路由外还可部署运营模型与服务 |
| Agent and tools智能体与工具 | Gateway and MCP capabilities within the suite套件内的网关与 MCP 能力 | Agent runtime, model gateway and MCP gateway within platform scope平台范围内的智能体 Runtime、模型网关与 MCP 网关 |
| Operations运营 | Vendor-managed product with configuration and integration work厂商托管产品,团队负责配置与集成 | Potential responsibility for clusters, planes, storage, upgrades and DR可能需负责集群、各平面、存储、升级与灾备 |
| Best owner最佳负责人 | AI platform, security and application enablementAI 平台、安全与应用赋能团队 | Platform engineering, ML platform and cloud infrastructure平台工程、ML 平台与云基础设施团队 |
Choose the smallest platform that owns the boundary选择能覆盖边界的最小平台
A managed gateway suite satisfies routing, guardrail, observability, prompt, budget and administrative needs without adding model-hosting operations.
Private deployment, model and service hosting, agent runtime, MCP, Kubernetes, cloud governance, or a wider AI platform roadmap are required.
The proposal says “self-hosted” without a component diagram, sizing, upgrade model, backup design, support boundary, or tested recovery objective.
托管网关套件已满足路由、护栏、可观测性、提示词、预算与管理需求,无需增加模型托管运营。
需要私有部署、模型/服务托管、智能体 Runtime、MCP、Kubernetes、云治理或更广 AI 平台路线。
方案只写“自托管”,却没有组件图、容量、升级模式、备份设计、支持边界或已验证恢复目标。
Write a responsibility matrix for every plane为每个平面编写责任矩阵
List gateway data plane, control plane, compute plane, UI and API, identity, policy store, secrets, telemetry, model registry, artifact storage, databases, queues, caches, DNS, certificates, backups and disaster recovery. For each component record location, owner, access path, data classification, scaling trigger, upgrade method, RPO, RTO and vendor support. Then compare deployment options.
列出网关数据面、控制面、计算面、UI/API、身份、策略存储、密钥、遥测、模型注册表、制品存储、数据库、队列、缓存、DNS、证书、备份与灾备。逐项记录位置、负责人、访问路径、数据分类、扩容触发、升级方式、RPO、RTO 与厂商支持,再比较部署选项。
Architecture rule: a private data plane is not the same as a private control plane or a fully self-hosted product.
架构规则:私有数据面不等于私有控制面,也不等于完整自托管产品。
A control-boundary proof控制边界验证
- Draw the exact SaaS, VPC, cluster and provider network paths, including metadata and telemetry egress.
- Deploy one gateway instance, rotate secrets, update policy, upgrade, scale, back up and restore it using the documented operator path.
- Run tools, structured output, streaming and forced failures while checking routing, guardrails, logs, traces, costs and audit records.
- Test identity, private connectivity, tenancy, region and data-retention requirements with security stakeholders.
- Calculate software plus cluster, storage, egress, on-call, upgrades, DR exercises and support.
- 画出准确的 SaaS、VPC、集群与供应商网络路径,包括元数据和遥测出口。
- 按文档化运营路径部署一个网关实例,并执行密钥轮换、策略更新、升级、扩容、备份与恢复。
- 运行工具调用、结构化输出、流式和强制故障,并检查路由、护栏、日志、追踪、成本与审计记录。
- 与安全团队共同验证身份、私有连接、租户、区域和数据保留要求。
- 计算软件加集群、存储、出口、值班、升级、灾备演练与支持的成本。
Migrate policy, platform state and operator runbooks迁移策略、平台状态与运营手册
Export providers, keys, models, routes, limits, budgets, guardrails, prompts, users, roles, logs, traces and costs. Also inventory deployment manifests, secrets, network policy, storage, dashboards, alerts, backups and runbooks. Dual-run one workload, reconcile policy and evidence, then complete an upgrade and rollback before moving the next team.
导出供应商、密钥、模型、路由、限额、预算、护栏、提示词、用户、角色、日志、追踪与成本;同时盘点部署清单、上游密钥s、网络策略、存储、仪表盘、告警、备份和 Runbook。双轨运行一个负载并核对策略与证据,完成一次升级和回滚后再迁移下一团队。
Deployment control and capability discovery are complementary部署控制与能力发现互补
Portkey or TrueFoundry can govern model, gateway and platform traffic. QVeris complements that layer by helping agents discover external APIs, data and tools, and call them under controlled contracts and credentials. Preserve control-boundary metadata and trace context on every downstream capability invocation.
Portkey 或 TrueFoundry 可以治理模型、网关和平台流量;QVeris 作为互补层,帮助智能体发现外部 API、数据与工具,并在受控契约和凭证下调用。每次下游能力调用都应保留控制边界元数据与调用链上下文。
FAQ
Its documentation includes an open-source gateway and self-host paths; validate the exact components, edition, support and control-plane boundary you require.
No. Its documented platform scope also includes AI deployment, models, services, agents, MCP, governance and multiple installation patterns.
A managed SaaS gateway usually reduces initial infrastructure work; the full answer depends on security review, integration, identity and data-boundary requirements.
Control must be decomposed into data, gateway, control and compute planes. Compare exact deployment contracts rather than the word “private.”
其文档包含开源网关与自托管路径;应核对所需组件、版本、支持和控制面边界。
不是。其文档平台范围还包括 AI 部署、模型、服务、智能体、MCP、治理与多种安装模式。
托管 SaaS 网关通常减少初始基础设施工作,但还取决于安全审查、集成、身份和数据边界要求。
应把控制拆成数据、网关、控制和计算平面;比较精确部署契约,而不是比较“私有”这个词。
