Your AI traffic,Masked.

Send prompts to any model. Send personal data to none.Shim masks, logs, and tracks every model and agent call. All while optimizing your costs. One base URL, one minute swap.

Workup by Türkiye İş BankasıFounder InstituteGirişim Fabrikası
For coding agents

uv tool install --python 3.12 --compile-bytecode shim

More about Shim CLI

Any modelno lock-in
1 lineto setup
<100 msno slowdown

Works with

OpenAIAnthropicGoogle GeminiOllama

and more...

Enterprise, built to your spec.

On-prem deployment, high-availability SLAs, and custom features and pricing, scoped to your rollout.

The swap

One line of code. One minute setup.

Keep the client you already have. Every request, to any provider, gets redaction, policy, optimization and audit, automatically.

Beforetalking to the provider
from openai import OpenAI

client = OpenAI(
    api_key="sk-..."
)
Aftertalking to Shim
from openai import OpenAI

client = OpenAI(
    api_key="sk-shim-...",    base_url="https://api.getshim.tech/v1")
Round tripfully reversible
1Your app sends
"Müşteri ayse@ornek.com, TCKN 10000000146. Kredi limitini artırabilir miyiz?"
Shim redacts the PII
2The provider receives
"Müşteri <EMAIL_ADDRESS_75344f…>, TCKN <TR_NATIONAL_ID_1f0b9c…>. Kredi limitini artırabilir miyiz?"
The model runs on placeholders only, then replies
3The model replies, still in placeholders
"Limit artışı uygundur. <EMAIL_ADDRESS_75344f…> adresine bilgilendirme gönderilmelidir."
Shim restores the PII
4Your app gets back
"Limit artışı uygundur. ayse@ornek.com adresine bilgilendirme gönderilmelidir."

The mapping never leaves your gateway. The provider only ever sees the token form, and every substitution is written to the audit record.

See it on your own text

We challenge you! Come try us.

Paste your most sensitive text and see exactly what the provider receives, with every IBAN, card number, ID and email stripped on the way. Real engine, no signup.

Open the playground

What you see

"IBAN TR33 0006 1005 1978 6457 8413 26 hesabına iade yapalım mı?"

What AI sees

"IBAN <IBAN_CODE_9f3c8a…> hesabına iade yapalım mı?"

Dashboard

Capabilities

A cleaning station for AI traffic

Named after the cleaner shrimp: everything passes through, leaves lighter, and nothing that shouldn't travel gets carried along.

Hide personal data

Names, national IDs, IBANs, phone numbers and emails detected in Turkish and English, replaced with tokens outbound and rehydrated inbound.

Optimize your inputs

Normalize prompts and turn PDFs and spreadsheets into clean Markdown, so the model reads less noise and you pay for fewer tokens.

See what your team spends

Spend broken down by key, team, project and model, so the invoice stops being a single unexplained number.

Routing & backup

Allowlist the models a team may call, pin workloads to a region, and fall back to a second provider when one degrades.

Audit log & evidence

Who called what, with which policy in force, and what was removed. Exportable as an evidence pack.

Full visibility

Latency, error and token traces per request, with a diff view showing exactly what the provider saw.

Governance

The evidence, before anyone asks.

Shim won't certify you. It gives you the records and controls a KVKK, GDPR, DORA or EU AI Act audit runs on, right where the data moves.

  • Only what's needed leaves. Personal data is removed before the request crosses a border.
  • Region pinning. Route a workload to an EU or Türkiye endpoint and block the ones you have not approved.
  • A record you can't rewrite. Every call, policy version and redaction, queryable and exportable.
  • Bring your own keys. Provider credentials stay in your vault. Shim never becomes the owner of record.
  • A human in the loop. Flag a class of request for review before the answer reaches the user.

Wording matters here: compliance is an outcome of your whole programme, not a feature. Shim is the control and evidence layer inside it.

Policy decisions · last 24h3 active
eu-residencyanthropic → eu-central
Allowed41,208
pii-redactionTCKN, IBAN, e-mail masked
Masked9,412
model-allowlistgpt-4o-mini not approved for Ops
Blocked126
rate-limitper key, 600 rpm
Allowed183K
human-oversightcredit decisions queued for review
Held37

Pricing

Start free, pay when it carries load

Self-serve up to agency scale. Regulated deployments are scoped, because the deployment model is the cost driver.

Developer

For evaluation, prototypes, and small workloads

$0
  • 1M tokens / month
  • 1,000 requests / month
  • Native provider APIs
  • Configurable PII protection
  • Community support
Start Free
Most picked

Solo Pro

For indie hackers and production applications

$29/mo
  • 10M tokens / month
  • 100,000 requests / month
  • Budget and spend controls
  • Compliance evidence
  • Priority support
Choose Solo Pro

Agency

For agencies and growing software teams

$149/mo
  • 100M tokens / month
  • 1M requests / month
  • Team roles and permissions
  • Compliance delivery and reports
  • Onboarding call
Choose Agency

Enterprise

For custom deployment, oversight, and support needs

Let's scope it
  • Custom usage and team limits
  • Oversight workflows and reports
  • Custom deployment and support scope
  • Procurement and security review

Switching to clean Markdown cut input tokens by 72%. The exact figure varies by use case.

The questions before the yes

Straight answers to what teams ask before they clean their AI traffic.

No. Not even if we wanted to. Your key is encrypted the moment it reaches us and stays in your own vault reference. The gateway keeps the handshake, never the fingerprint.

Yes. You set the rules per workspace, so you decide what gets masked, blocked, or left alone.

Depends on what slow means to you. Reading this takes about 6 seconds. In that time, Shim would have run more than 60 times.

Yes, it is also built for Turkish, not adapted to it. We follow Turkish grammar and catch local identifiers like TCKN and IBAN that most English-first tools miss.

Any model with an API. Your favorite is almost certainly already supported, and we are very open to special requests.

You choose in advance, per route. Sensitive traffic can stop until Shim is back, while internal tools keep flowing straight to the provider.

Yes, on the Enterprise plan. We set it up to fit your own environment and rules.

Contact us to start your on-prem setup.

LiteLLM routes your requests. It was never built to protect your data inside them. Shim actually protects your data: redaction in the request path, sensitive data caught automatically, and an audit record no one can quietly rewrite. To see other tool comparisons, check our Resources menu at the top.

Have another question? Ask us here.

Put a cleaning station in front of your models.

Run a two-month pilot on your own traffic. The logs, the evidence and the numbers stay yours, whether you continue or not.

Team

Built by engineers who needed it first

Three co-founders and a GTM lead, building the infrastructure we wished we had.

MS
Mertcan Sağlam

Mertcan Sağlam

Co-founder

Engineering and product. Enterprise data infrastructure background: Migros data pipelines, OBASE lakehouse architecture.

CÇS
Can Çağatay Sevgican

Can Çağatay Sevgican

Co-founder

Engineering and product. AI engineering, full-stack development and business development.

TB
Turgay Bulut

Turgay Bulut

Co-founder

Competitive programmer. The performance and correctness engine behind the gateway core.

ÖU
Öykü Ulusay

Öykü Ulusay

Lead GTM

Entrepreneur since high school and former president of the Özyeğin University OR club. Owns the go-to-market motion.