Find out what your people are actually sending to AI.
Two weeks, observe-first, nothing blocked. At the end you get a board-ready report: which AI tools and models are in use, what sensitive data would have left the business, and what that usage costs today versus routed.
Research through 2025–26 has consistently found the majority of workplace AI use running through consumer accounts with no processor agreement, no logging and no retention control. Banning it doesn't work — people just stop telling you. The workable posture is to provide a governed alternative, and to do that you first have to know what you're replacing.
The three questions it answers
What is in use?
Which AI tools, providers and models your teams and applications are calling — by team, by application, by volume. Including the ones nobody told IT about.
What is leaving?
Every prompt is scanned against DLP detectors — personal data, payment details, credentials, secrets, source code. You get the categories and counts, anonymised. Not a list of who typed what.
What does it cost?
Actual spend across every provider, per team, alongside what the same traffic would have cost routed to the best-value model that could handle it.
How the two weeks run
We agree the scope — a pilot group, a department, or a set of applications — and what "sensitive" means for your business. Nothing is installed on anyone's device.
Applications change a base URL and a key — two lines. People get a chat workspace at your own subdomain with the models you approve. No retraining, no new tool to learn.
Every policy runs in log-only mode. Nothing is blocked, nothing is masked, nobody's work is interrupted — so what you measure is real behaviour rather than behaviour under observation.
We walk your leadership through the findings, then agree which policies to switch from log-only to enforcing. That switch is a toggle — the platform is already in place.
What lands on the board table
- AI usage inventory — tools, providers, models and volumes, broken down by team and application.
- Sensitive-data exposure — what would have left the business, by category and count, with representative redacted examples.
- Prompt-injection and abuse attempts — what the shields saw, if anything, over the observation window.
- Cost position — current spend by provider and team, against the routed equivalent.
- Governance gap analysis — your current position against GDPR Article 28 processor obligations and the EU AI Act duties that apply to you, with the ones that don't clearly marked as such. See our EU AI Act guide for how we read the timeline.
- A recommended policy set — which controls to enforce first, and what each one will and won't catch.
What we see, and what we don't
routeur.ai is metadata-only by default: provider, model, token counts, latency, cost and policy verdicts. Content retention is a separate, explicit opt-in that you control, and the assessment does not require it. Where the report quotes an example, it is redacted by the same DLP layer being measured, and included only with your agreement. Everything runs in Google Cloud in europe-west1. Read the security page and the DPA before you decide — we would rather you did.
Who this is for
| A good fit if… | Probably not yet if… |
|---|---|
| You have 200–5,000 people and AI use has grown faster than your policy. | You're a handful of engineers who already know exactly what you're sending — just start a trial. |
| Someone has asked "what's our AI governance story?" and the honest answer is a document nobody can enforce. | You've already got a governed gateway in place and are happy with it. |
| You're in a regulated or reputation-sensitive sector — financial services, legal, healthcare, insurance, public sector. | Nobody in the business is using AI yet. Come back when they are; they will be. |
| You're rolling out (or have rolled out) Copilot or ChatGPT Enterprise, and want to know what's happening outside it. | You need this to run entirely inside your own network today — talk to us about deployment options first. |
What it costs
In exchange we ask for production traffic, honest fortnightly feedback, and — only if the platform earns it — a reference or case study. You get direct access to the people who build it, routing rules designed with you rather than for you, and your pricing locked permanently. After those five places are taken the assessment becomes a paid engagement, quoted on the scoping call and credited in full against your first year.
Work out your number
What routing would be worth to you.
Set three values. We show the arithmetic underneath rather than asking you to believe a headline percentage.
Net saving, after paying us
$1,080
$12,960 a year
- Routing saving
- $1,225
- Starter · 5 seats
- −$145
- Net per month
- $1,080
$5,000 × 35% routine × 70% cheaper = $1,225 saved a month, against $145 for 5 Starter seats — routing covers the platform 8.4× over.
Routine requests moved from a frontier model to a small one typically cost around 70% less; we apply that reduction only to the share of traffic you set, and to nothing else. Your real figure depends on your workload — the dashboard reports actual savings against going direct, per request, once you're live. Seat pricing is list price; usage above your plan's pooled allowance is billed separately at the rates on this page.