Orq.ai logo
Agents Orchestration Frameworks · Api Tools

Orq.ai

Enterprise AI gateway from the Netherlands that routes over 500 models from 30+ providers through one OpenAI-compatible API, applying real-time guardrails, hard budget caps and audit trails to every model call and every MCP tool call.

Active GDPR compliant Free plan Pay As You Go API available 18+ Verified by Guidaio
Overview

What is Orq.ai?

Orq.ai is a Dutch control layer for enterprise AI traffic, marketed as a sovereign AI gateway. Every model call and every tool call an organisation makes is routed through a single OpenAI- and Anthropic-compatible endpoint, where security, compliance, cost and operational policies are enforced in real time, before the request reaches a provider.

The platform bundles four blocks that are normally bought separately. The AI Gateway exposes a catalogue of more than 500 models from over 30 providers behind one API key, with fallbacks, retries, cross-provider failover chains, load balancing and response caching. A Smart Router classifies each request in under 40 ms and sends it to the cheapest model that clears the quality bar. Customers can bring their own provider keys, in which case billing and residency stay with that provider, or connect fine-tuned and self-hosted models through Azure AI Foundry, Vertex AI or any OpenAI-compatible endpoint. An MCP Gateway extends the same guardrails, per-team scoped access and audit trail to remote MCP servers, so tool calls from Claude Code, Cursor or Codex are governed exactly like model calls.

AI Observability turns every routed request into a trace carrying cost, tokens, latency and full payloads, with native OpenTelemetry ingestion, dashboards, a reporting API and a SIEM exporter for Splunk or Datadog. AI Governance adds a live Control Tower, audit logs spanning 28 entity types and 26 action types, per-project model restrictions, retention windows and per-request masking. FinOps features attribute spend in real time by team, project, customer or agent, and enforce hard caps before the bill arrives rather than alerting after it.

Managed Agents complete the set with a runtime for single- and multi-agent systems, sub-agents, versioning, cron schedules, function, HTTP, Python and MCP tools, and RAG knowledge bases with parsing, chunking, hybrid search and reranking. AI Studio, the visual workspace, holds versioned prompts, experiments, more than 40 prebuilt evaluators and human review queues.

Deployment runs from EU SaaS to a customer VPC on AWS or Azure, on-premise through a Helm chart, and fully air-gapped installations.

What it does

  • Route requests to more than 500 models from 30+ providers through a single OpenAI- and Anthropic-compatible API
  • Govern MCP tool calls with the same policies, scoped access and audit trail as model calls
  • Trace every request — cost, tokens, latency and full payloads — with native OpenTelemetry ingestion
  • Set hard budget caps and spend alerts per organisation, team, project, model, API key or agent
  • Block, reroute or redact personally identifiable information before a request ever reaches a provider
  • Run batch evaluations of prompts and models from the interface or from a CI/CD pipeline
  • Deploy managed single- and multi-agent systems with sub-agents, versioning and cron schedules
Audience

When to use Orq.ai / When not to

A quick filter to help you decide if Orq.ai is the right fit.

When to use Orq.ai

  • Platform and AI engineering teams running several LLMs in production who must account for every call
  • Organisations in regulated sectors — banking, healthcare, energy, European public sector — that need evidence, not promises
  • Compliance, GRC and risk teams working under the EU AI Act, GDPR or DORA
  • Buyers for whom European data residency is a contractual requirement rather than a preference
  • Finance and FinOps owners who need real-time cost attribution, chargeback and hard spending limits on AI

When not to use Orq.ai

  • Individuals and casual users: this is infrastructure sold to technical teams, and the terms restrict it to adults aged 18 and over
  • Anyone looking for a ready-made AI assistant — Orq.ai is a control layer you integrate, not a chatbot you open
  • Teams with no third-party or self-hosted models to route, since the platform supplies none of its own
  • Large non-technical groups, because the visual AI Studio workspace is the one seat billed per person
  • Users who need a localised product: the site, the documentation and the support are English-only
Get started

How to use Orq.ai

A typical end-to-end flow, from setup to results.

  1. Create an account on my.orq.ai with no credit card; the vendor advertises a first routed call within two minutes
  2. Claim the 1 USD of credit granted on sign-up, or connect your own provider keys to stay on BYOK
  3. Swap your base URL for the Orq.ai endpoint and leave your existing OpenAI-compatible code untouched
  4. Install the official SDK if you prefer — orq-ai-sdk for Python, @orq-ai/node for Node
  5. Watch the first traces appear immediately: observability is captured from request one, with no extra setup
  6. Add billing details to lift the 50-requests-per-day cap that applies until they are provided
  7. Set budgets, alerts and hard spend caps per workspace, project, user, API key, provider or model
  8. Configure routing rules, fallback chains, guardrails and PII redaction so policies apply to matching requests
  9. Connect remote MCP servers and scope tool access per team through the MCP Gateway
  10. Invite AI Studio seats only for the people who need the visual workspace; gateway seats stay unlimited and free
Quick read

Pros & Cons

Pros

  • One integration point for 500+ models: a base-URL swap replaces per-provider rewrites
  • The same policies cover model calls and MCP tool calls, which few gateways currently do
  • Pricing is published meter by meter, with a working bill estimator on the pricing page
  • No markup on model traffic — models are billed at provider list prices
  • Gateway seats are unlimited and free; only the AI Studio workspace is charged per person
  • An explicit, repeated commitment that customer prompts, outputs and traces never train any model
  • An unusually wide deployment range: EU SaaS, customer VPC on AWS or Azure, on-premise Helm chart, air-gapped

Cons

  • The site contradicts itself on hosting: the EU page promises data never leaves Europe while the privacy notice describes storage on servers located in the United States
  • The security page, dated 16 November 2025, describes ISO 27001 as still in progress towards formal certification, while the pricing page advertises the platform as ISO 27001 certified
  • The same security page describes Google Cloud infrastructure spread across most GCP locations globally, which sits awkwardly with the European residency promise
  • The subprocessor list is not published; the privacy notice offers it on request only
  • The Trust Center is a fully JavaScript-rendered space, so its documents and vendor list cannot be read without interacting with it
  • Real cost is hard to forecast: spans, processed data, agent runs and seats are four separate meters, and advanced governance sits behind an unpriced Enterprise tier
  • The published postal address is incomplete, and the site, documentation and support are English-only
Pricing

Pricing & Plans

A permanent free entry point is available: an account can be opened without a credit card, comes with 1 USD of credit, and renews monthly allowances of 100,000 spans, 1 GB of processed data and 500 agent runs. Until billing details are supplied, requests are capped at 50 per day rather than charged. Beyond the included allowances, the Pay-as-you-go plan meters usage at 7 EUR per 100,000 spans, 3 EUR per GB of processed data and 0.01 EUR per agent run. The lowest recurring per-person price point is 35 EUR per AI Studio seat per month; AI Gateway seats remain unlimited and free of charge. A platform fee of 4.5% applies to credit top-ups on Orq.ai keys, and 4% on bring-your-own-key traffic beyond one million requests per month, while model traffic itself is billed at provider list prices with no markup. Optional modules are priced at 300 EUR per month for Teams and 500 EUR per month for Knowledge Bases and Agent Memory. Enterprise pricing is quoted on request.

Plan 1
  • Pay-as-you-go — free to start
  • then metered usage. Includes 100
  • 000 spans
  • 1 GB of processed data and 500 agent runs each month
  • unlimited AI Gateway seats
  • 30-day data retention
  • a 100 requests-per-minute rate limit and every product feature unlocked. Overages at 7 EUR / 100
  • 000 spans
Plan 2
  • Enterprise — custom pricing
  • quoted after an executive briefing. Adds AI Governance
  • audit logs
  • on-premise and VPC deployment
  • a SOC 2 report
  • ISO 27001
  • a HIPAA BAA
  • a custom DPA
Special offers — Discounts for startups, academic institutions, non-profits and open source projects, arranged on request through support@orq.ai · 1 USD of free credit granted when an account is created, with no credit card required
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Orq.ai handles your data.

GDPR overview

GDPR compliance is claimed explicitly and backed by concrete references. The privacy notice, last updated on 23 August 2026, sets out its lawful bases under Article 6(1), lists every data subject right, and routes requests to privacy@orq.ai, with Willem Tibosch named as the privacy contact. Answers are promised within one month, extendable by two, and free of charge except for manifestly unfounded requests under Article 12(5). Transfers outside the EEA rely on the 2021/914/EU Standard Contractual Clauses together with transfer impact assessments. Breaches are reported to the supervisory authority within 72 hours under Article 33. The competent authority is the Dutch Autoriteit Persoonsgegevens, and an Article 28 data processing agreement sits in the Trust Center. No Article 27 representative is designated, and none is needed: the publisher is established in the Netherlands.

Who owns the data?

Orq.AI Holding B.V. is the controller for the personal data described in its privacy notice, which covers the business contact details of visitors and customers. For the material customers push through the platform the roles reverse: Orq.ai acts as processor, and the Data Processing Agreement published in its Trust Center is incorporated by reference into the service terms and prevails over them on its subject matter. The vendor states it does not sell personal information and shares it only with service providers delivering the service, under written Article 28 agreements. Customers keep their own content and can export traces, experiments and datasets as CSV or JSON at any time.

Reuse rights

The vendor's position on reuse is unusually explicit: prompts, outputs and traces are never used to train models, neither its own nor anyone else's. Personal data it collects on its own account is processed under contract, legal obligation, legitimate interest or consent, and business contact details may be enriched from public sources such as LinkedIn on a legitimate-interest basis. Technical browsing data — IP address, region, browser, operating system and page history — is logged to run and improve the website, and non-essential cookies are set only with consent that can be withdrawn. On their own material, customers keep the controls: per-request input and output masking, PII redaction, configurable auto-deletion windows, and zero-data-retention routing that restricts traffic to providers which store nothing.

Data retention & training

Retention summary
Platform data is kept for 30 days on Pay-as-you-go and for a custom period on Enterprise. Customers can set their own auto-deletion windows, mask inputs and outputs per request, and enable zero-data-retention routing so traffic only reaches providers that store nothing. Anything a customer classifies as personally identifiable is never stored and is wiped as soon as the rules engine finishes its evaluation, while versions, evaluation logs and audit logs are deleted automatically according to the plan's retention policy. On the publisher's own side, service data is kept for the length of the business relationship and at most three years afterwards, prospect data for at most three years, and any personal data under its control is deleted on verified request. Traces, experiments and datasets can be exported as CSV or JSON at any time.
Trains on customer data
No
DPA available
Yes
GDPR contact

Hosting summary

Three first-party statements coexist and do not reconcile. The commercial pages describe Orq.ai as EU-built, EU-owned and EU-hosted, promising that every request, log and cache stays inside the European Union with a choice of region, a SEAL-4 sovereignty level and 94% on the EU Cloud Sovereignty Framework. The privacy notice of 23 August 2026 places processing in the EEA but states that personal data is stored on the servers of the cloud database services the company engages, located in the United States, with transfers covered by the Standard Contractual Clauses. The security page of 16 November 2025 describes infrastructure running on Google Cloud Platform, with Cloud SQL instances, geo-redundant backups and a node in most GCP locations globally. Encryption is AES-256 at rest and TLS 1.2 in transit, with keys held in Google Secrets Manager. Customers can escape the ambiguity entirely by deploying in their own VPC on AWS or Azure, on-premise, or fully air-gapped. Headquarters are in the Netherlands, with no US parent company claimed.

Hosting countries
🇺🇸 United States
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Orq.ai.

  • The sovereignty promise is the main reason to buy this product, and the vendor's own legal pages do not confirm it: verify in writing where customer data is stored before relying on European residency for compliance
  • ISO 27001 is advertised as obtained on the pricing page and as still in progress on the security page; ask for the certificate rather than assuming the more favourable version
  • The security page certifies the data centres, not the publisher — those ISO 27001 and SOC 2 credentials belong to Google Cloud and should never be read as the vendor's own
  • Concentrating every model and tool call behind one gateway creates a single point of dependency: an outage, a pricing change or a policy misconfiguration reaches every AI feature at once
  • Usage-based billing across four separate meters makes runaway spend easy to create and hard to predict; the budget caps exist precisely because the risk is real, and they have to be configured deliberately
  • Routing through a proxy adds a party that sees prompts and outputs in transit, so the zero-data-retention and masking controls should be switched on rather than assumed
  • The terms require customers not to be sanctioned persons and to respect EU, UK and US export control and sanctions regimes, which is the user's responsibility to check, not the platform's
Setup

Setup & Integrations

Technical difficulty

Getting the first call routed is genuinely easy: open an account without a card, swap the base URL, and existing OpenAI-compatible code keeps working, with observability captured from the very first request. Official Python and Node SDKs and open documentation lower the barrier further. Running the platform properly is a different matter and assumes platform engineering skills — routing rules, guardrails, RBAC, SAML or OIDC single sign-on, Terraform, evaluation pipelines in CI/CD and SIEM export. VPC, on-premise Helm and air-gapped installations belong to an infrastructure team, which is why the Enterprise plan includes forward deployed engineers.

Deployment

Web appAPI

Integrations

OpenAI Anthropic Google AI Google Vertex AI Azure AI Foundry Amazon Bedrock Mistral Cohere Groq Cerebras DeepSeek Perplexity XAI ElevenLabs Together AI Alibaba Cloud Moonshot AI Jina Leonardo.Ai Scaleway ByteDance Fal LangChain LangGraph LlamaIndex CrewAI AutoGen DSPy Haystack Agno Mastra PydanticAI Semantic Kernel SmolAgents Instructor LiveKit Vercel AI OpenAI Agents Claude Agent SDK AWS Strands AWS Bedrock AgentCore BeeAI Claude Code Cursor Codex OpenTelemetry Splunk Datadog Okta Microsoft Entra Slack Microsoft Teams Terraform LiteLLM

Supported languages

English
Company

Behind Orq.ai

Company name
Orq.AI Holding B.V.
Founded
INFORMATION_NOT_FOUND
Country of origin
🇳🇱 Netherlands
Headquarters
Herengracht 420
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Support contact

Fundraising

March 2024 — a 1.5 million EUR round announced alongside two new products, then reported as a 2.3 million EUR pre-seed the following day
9 April 2024 — the pre-seed extended to 2.3 million EUR, announced together with the rebranding of Orquesta to Orq.ai
15 November 2024 — the publisher's own press release describes the 2.3 million EUR pre-seed round as historic
3 December 2025 — a 5 million EUR round announced to close what the company calls the AI production gap for enterprises
Total funding stated on the About page: 7.3 million EUR, backed by Seed & Speed, Galion.exe, Curiosity VC, Spacetime and Golden Egg Check

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Orq.ai.

G Gemini Enterprise Agent PlatformO OpenRouterE Eden AIP PortkeyR Requesty AIL LiteLLMA Amazon BedrockA Azure AI FoundryL LangfuseL LangSmithH HeliconeT TrueFoundry
FAQ

Frequently asked questions

What exactly is Orq.ai?
An enterprise AI gateway that routes more than 500 models from over 30 providers, plus MCP tool calls, through a single OpenAI- and Anthropic-compatible API, with observability, governance and cost management built into the same layer.
Do I have to rewrite my code to use it?
No. The gateway works standalone: you swap your base URL and keep your OpenAI-compatible code. Official SDKs are published for Python (orq-ai-sdk) and Node (@orq-ai/node), and the platform can also be driven from a CLI, Terraform or webhooks.
Is there a free plan?
Yes. An account opens without a credit card and includes 1 USD of credit plus monthly allowances of 100,000 spans, 1 GB of processed data and 500 agent runs. Until billing details are added, requests are limited to 50 per day rather than billed.
How much does the platform cost?
Beyond the included allowances, 7 EUR per 100,000 spans, 3 EUR per GB of processed data and 0.01 EUR per agent run. AI Studio seats cost 35 EUR per seat per month, and are the only per-person charge. A 4.5% platform fee applies to Orq.ai credit top-ups, and 4% on bring-your-own-key traffic above one million requests a month.
Are my prompts and outputs used to train models?
No. The vendor states that prompts, outputs and traces are never used to train models, its own or anyone else's. Retention is controlled through configurable auto-deletion, and inputs and outputs can be masked per request.
Where is the data actually hosted?
This one deserves care. The EU page states that every request, log and cache stays inside the European Union, while the privacy notice says personal data is stored on cloud database servers located in the United States, and the security page describes Google Cloud infrastructure spread across most GCP locations globally. The three statements do not reconcile, and the point is worth raising with the vendor before signing.
Is Orq.ai GDPR compliant?
Compliance is claimed explicitly. An Article 28 data processing agreement is published in the Trust Center, transfers outside the EEA rely on the 2021/914/EU Standard Contractual Clauses, and the competent supervisory authority is the Dutch Autoriteit Persoonsgegevens. Requests go to privacy@orq.ai.
Is there a public API and documentation?
Yes. Open documentation is published at docs.orq.ai, alongside Python and Node SDKs, a CLI with more than 40 command groups, Terraform support, webhooks and an MCP server that lets the platform be operated from coding assistants.
Can the platform be self-hosted?
Yes, on the Enterprise plan. Customers can deploy in their own VPC on AWS or Azure through the marketplaces, or fully on-premise with a single Helm chart, including air-gapped environments with no outbound connection.
Are there discounts?
Yes. The pricing page advertises discounts for startups, academic institutions, non-profits and open source projects, arranged by contacting support@orq.ai for a tailored proposal.
Conclusion

Should you pick Orq.ai?

Orq.ai is a coherent piece of infrastructure that does one job thoroughly: put every AI call an organisation makes behind a single governed door, then measure it, cap it and log it. The breadth is real — routing, observability, governance, FinOps, managed agents and RAG in one product — and so is the engineering pragmatism, since a base-URL swap is genuinely all it takes to start. Pricing transparency stands well above the sector average, with every meter published and a working estimator on the pricing page, and the absence of any markup on model traffic is a meaningful commitment rather than a slogan.

Two reservations deserve attention before a purchase. The European sovereignty argument, which is the company's loudest claim, is not confirmed by its own legal pages: the privacy notice places personal data on servers in the United States and the security page describes Google Cloud infrastructure spread across most GCP regions worldwide. Separately, the security page still presents ISO 27001 as a certification in progress while the pricing page advertises it as obtained. Neither point makes the product weaker on its merits, but both are exactly the kind of question a regulated buyer will have to settle in writing. The undisclosed subprocessor list and the JavaScript-only Trust Center make that verification slower than it should be.

The audience is unambiguous: platform, AI and compliance teams inside organisations already running LLMs at scale, not end users. For them, the free entry tier and unlimited gateway seats make an evaluation almost costless. For everyone else, this is infrastructure they will never touch directly. Verify the hosting and certification claims with the vendor before committing.