Your AI traffic,Masked.
Send prompts to any model. Send personal data to none.Shim masks, logs, and tracks every model and agent call. All while optimizing your costs. One base URL, one minute swap.



uv tool install --python 3.12 --compile-bytecode shim
Works with




and more...
Enterprise, built to your spec.
On-prem deployment, high-availability SLAs, and custom features and pricing, scoped to your rollout.
The swap
One line of code. One minute setup.
Keep the client you already have. Every request, to any provider, gets redaction, policy, optimization and audit, automatically.
from openai import OpenAI client = OpenAI( api_key="sk-..." )
from openai import OpenAI client = OpenAI( api_key="sk-shim-...", base_url="https://api.getshim.tech/v1")
The mapping never leaves your gateway. The provider only ever sees the token form, and every substitution is written to the audit record.
See it on your own text
We challenge you! Come try us.
Paste your most sensitive text and see exactly what the provider receives, with every IBAN, card number, ID and email stripped on the way. Real engine, no signup.
Open the playgroundWhat you see
"IBAN TR33 0006 1005 1978 6457 8413 26 hesabına iade yapalım mı?"
What AI sees
"IBAN <IBAN_CODE_9f3c8a…> hesabına iade yapalım mı?"
Dashboard
Capabilities
A cleaning station for AI traffic
Named after the cleaner shrimp: everything passes through, leaves lighter, and nothing that shouldn't travel gets carried along.
Hide personal data
Names, national IDs, IBANs, phone numbers and emails detected in Turkish and English, replaced with tokens outbound and rehydrated inbound.
Optimize your inputs
Normalize prompts and turn PDFs and spreadsheets into clean Markdown, so the model reads less noise and you pay for fewer tokens.
See what your team spends
Spend broken down by key, team, project and model, so the invoice stops being a single unexplained number.
Routing & backup
Allowlist the models a team may call, pin workloads to a region, and fall back to a second provider when one degrades.
Audit log & evidence
Who called what, with which policy in force, and what was removed. Exportable as an evidence pack.
Full visibility
Latency, error and token traces per request, with a diff view showing exactly what the provider saw.
Governance
The evidence, before anyone asks.
Shim won't certify you. It gives you the records and controls a KVKK, GDPR, DORA or EU AI Act audit runs on, right where the data moves.
- Only what's needed leaves. Personal data is removed before the request crosses a border.
- Region pinning. Route a workload to an EU or Türkiye endpoint and block the ones you have not approved.
- A record you can't rewrite. Every call, policy version and redaction, queryable and exportable.
- Bring your own keys. Provider credentials stay in your vault. Shim never becomes the owner of record.
- A human in the loop. Flag a class of request for review before the answer reaches the user.
Wording matters here: compliance is an outcome of your whole programme, not a feature. Shim is the control and evidence layer inside it.
Pricing
Start free, pay when it carries load
Self-serve up to agency scale. Regulated deployments are scoped, because the deployment model is the cost driver.
Developer
For evaluation, prototypes, and small workloads
- 1M tokens / month
- 1,000 requests / month
- Native provider APIs
- Configurable PII protection
- Community support
Solo Pro
For indie hackers and production applications
- 10M tokens / month
- 100,000 requests / month
- Budget and spend controls
- Compliance evidence
- Priority support
Agency
For agencies and growing software teams
- 100M tokens / month
- 1M requests / month
- Team roles and permissions
- Compliance delivery and reports
- Onboarding call
Enterprise
For custom deployment, oversight, and support needs
- Custom usage and team limits
- Oversight workflows and reports
- Custom deployment and support scope
- Procurement and security review
Switching to clean Markdown cut input tokens by 72%. The exact figure varies by use case.
The questions before the yes
Straight answers to what teams ask before they clean their AI traffic.
No. Not even if we wanted to. Your key is encrypted the moment it reaches us and stays in your own vault reference. The gateway keeps the handshake, never the fingerprint.
Yes. You set the rules per workspace, so you decide what gets masked, blocked, or left alone.
Depends on what slow means to you. Reading this takes about 6 seconds. In that time, Shim would have run more than 60 times.
Yes, it is also built for Turkish, not adapted to it. We follow Turkish grammar and catch local identifiers like TCKN and IBAN that most English-first tools miss.
Any model with an API. Your favorite is almost certainly already supported, and we are very open to special requests.
You choose in advance, per route. Sensitive traffic can stop until Shim is back, while internal tools keep flowing straight to the provider.
Yes, on the Enterprise plan. We set it up to fit your own environment and rules.
LiteLLM routes your requests. It was never built to protect your data inside them. Shim actually protects your data: redaction in the request path, sensitive data caught automatically, and an audit record no one can quietly rewrite. To see other tool comparisons, check our Resources menu at the top.
Have another question? Ask us here.
Put a cleaning station in front of your models.
Run a two-month pilot on your own traffic. The logs, the evidence and the numbers stay yours, whether you continue or not.
Team
Built by engineers who needed it first
Three co-founders and a GTM lead, building the infrastructure we wished we had.

Mertcan Sağlam
Co-founder
Engineering and product. Enterprise data infrastructure background: Migros data pipelines, OBASE lakehouse architecture.


Can Çağatay Sevgican
Co-founder
Engineering and product. AI engineering, full-stack development and business development.

Turgay Bulut
Co-founder
Competitive programmer. The performance and correctness engine behind the gateway core.
