BerriAI

Security for AI also known as LiteLLM

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2023
Funding $1.6M
Last updated 2026-07-31

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

BerriAI builds LiteLLM, an open-source gateway giving a team one OpenAI-format interface to call more than 100 model providers. Netflix and Lemonade voices are on record, with Adobe, Rocket Money, and Samsara on Y Combinator's trusted-by list. The code is forkable, so a funded rival can rebuild the software, but customers already routing requests through it are harder to win away, since migrating the keys, budgets, and routing rules held in LiteLLM takes work. A gateway concentrating credentials is also the risk: in March 2026 two poisoned packages reached PyPI, exposed for between forty minutes and three hours by conflicting accounts, and BerriAI rebuilt its pipeline. It fits teams standardizing many models behind one gateway, weaker if cloud providers bundle comparable routing natively.

Sourced Details

Description LiteLLM is an AI gateway that lets platform teams give developers access to over 100 large language model providers through one OpenAI-format interface, with fallbacks and spend tracking across them. [f1]
Founded 2023 [f2]
HQ San Francisco, United States [f3]
Funding $1.6M total [f4]
Latest funding Seed (Y Combinator, Gravity Fund, Pioneer Fund), 2023 [f4]
Deployment SaaS, Self-hosted [f5]

Products

Product What it does
LiteLLM LiteLLM: Open-source AI gateway and proxy for 100+ LLM providers, adding virtual-key RBAC, budgets, rate limits, guardrails (PII masking, prompt-injection), and enterprise SSO and audit logs.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

LiteLLM is an open-source AI gateway and proxy for over 100 LLM providers, adding virtual-key RBAC, budgets, rate limits, guardrails for PII masking and prompt injection, and enterprise SSO and audit logs. It is mapped to the AI Defense Matrix. [f6]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 28 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 LiteLLM states the multi-provider friction clearly and names a Lemonade architect and Netflix, but the pain is qualitative and that customer corroboration sits on the vendor's own page, with no independent quantification across non-vendor sources. [s1, s3, s6]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 The open repository is MIT-licensed, with an enterprise directory under a separate license, and carries roughly 52,000 stars and 9,300 forks with a public SDK and proxy, the docs detail virtual keys, budgets, guardrails, and 100-plus providers, and the enterprise tier adds SSO and audit logs. Inspectable source and working docs let outside users verify the product's claims. [s3, s4, s5, s6, s12]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Enterprise multi-model adoption after 2023 created the routing and governance problem LiteLLM sells against, and named production use at Netflix and Lemonade is buyer-side evidence that teams are sourcing a gateway now. It lacks the Gartner category report that earned a 5 on adjacent gateways. [s1, s6, s3]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Co-founders Krrish Dholakia and Ishaan Jaffer built one of the most adopted open-source AI gateways and were backed by Y Combinator in 2023, a real signal, but neither shows a prior security exit or sustained publication record. That places the team at adequate. [s7, s3, s4]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 LiteLLM's page names Netflix as a user and carries an on-record quote from a Lemonade architect, and Y Combinator lists Rocket Money, Samsara, and Adobe as users, named references across multiple sources rather than vendor-curated anonymity. That clears the named-reference bar at 4. [s1, s6, s3]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 4/5 A roughly 1.6 million dollar seed from 2023 still funds a small team that ships one of the category's most widely used gateways, an enterprise tier, and a rebuilt release pipeline, visible output far above the capital deployed. That output-per-dollar clears what a 4 needs. [s7, s3, s8]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Buyers do use the AI gateway and LLM proxy vocabulary, but that category is still forming and contested by cloud-native and API-gateway entrants, with no analyst category report yet, so placement falls short of the corroborated 4 bar. [s5, s6, s3]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 The gateway is positioned in the model-call path and the large install base raises switching cost above a point tool, but cloud providers ship their own model gateways and the capability is broadly replicable. That puts the moat above the cluster floor yet short of structural. [s3, s2, s6]
Business Risks Cloud providers such as AWS, Azure, and Google could ship a comparable multi-model gateway with native routing, budgets, and guardrails inside platforms enterprises already pay for, removing the reason a team runs a separate LiteLLM proxy…
  • Cloud providers such as AWS, Azure, and Google could ship a comparable multi-model gateway with native routing, budgets, and guardrails inside platforms enterprises already pay for, removing the reason a team runs a separate LiteLLM proxy.
  • LiteLLM concentrates every model credential in one gateway, and the March 2026 supply-chain attack that placed two malicious packages on PyPI showed that the release path itself can be compromised, so a repeat incident could push security teams toward a vendor with a longer clean track record.
  • Most public proof is open-source adoption plus a handful of named users, and no audited revenue or customer count is disclosed, so if paid enterprise accounts stall a buyer cannot size the commercial business behind the free tool.
  • The roughly 1.6 million dollar seed is small for an enterprise motion, and a better-capitalized gateway rival or a platform vendor could outspend BerriAI on enterprise sales and support before it raises again.
  • The team shows no prior security exit, so an enterprise security review of a product that brokers every model credential may weigh the absence of a seasoned security leader against younger but security-pedigreed rivals.
Problem & Market BerriAI sells to the platform teams that have to give many developers access to many language models at once…

BerriAI sells to the platform teams that have to give many developers access to many language models at once. LiteLLM frames the problem as the friction of calling 100-plus providers, each with its own API shape, while tracking cost, enforcing budgets, and controlling who can call what. The product translates every provider into the OpenAI request and response format so a team writes against one interface instead of many.

The pain is documented by the buyers, not only the vendor. The company page states that Netflix uses LiteLLM to give developers Day 0 access to new models, and a named Lemonade principal architect describes the relief from managing multiple models in his own words. That is a buyer who owns the problem describing it directly.

The category demand is broad and developer-led. Y Combinator describes LiteLLM as an open-source LLM gateway used across named enterprises, and the repository draws tens of thousands of stars, which shows the routing-and-governance problem is felt widely rather than argued by one vendor. [s1, s6, s3]

Product Capabilities LiteLLM ships as both a Python SDK and a proxy server that acts as the gateway in front of model providers…

LiteLLM ships as both a Python SDK and a proxy server that acts as the gateway in front of model providers. The GitHub project describes calling 100-plus LLM APIs in the OpenAI format with cost tracking, guardrails, load balancing, and logging, and the docs walk through standing up virtual keys and a first request. The same gateway adds budgets, rate limits per key and team, and routing across providers.

The security features live alongside the routing. The product offers guardrails that screen prompts and responses, including PII handling and prompt-injection checks, and the enterprise tier adds SSO, JWT auth, and audit logs on top of the open-source core for a self-managed deployment. BerriAI sells the enterprise tier to organizations giving model access to a large number of developers.

The open repository is the external validation a buyer can inspect. Roughly 52,000 stars, 9,300 forks, and a large contributor base under the MIT license, with the enterprise directory separately licensed, let a security or platform team read the code and the release history directly, a different assurance model than a closed gateway offers, and the docs portal documents the providers and the proxy setup beyond marketing claims. [s3, s4, s5, s11, s12]

Competitive Positioning LiteLLM competes as the open-source default in a gateway category that closed vendors and cloud platforms also contest…

LiteLLM competes as the open-source default in a gateway category that closed vendors and cloud platforms also contest. Portkey and Cloudflare market their own AI gateways with routing, caching, and guardrails, Kong brings API-gateway heritage to the same job, and the major cloud providers ship native model routers. LiteLLM's edge is an install base and a provider-coverage breadth that a closed competitor has to win one integration at a time.

The company's structural advantage is depth in the call path rather than a data moat. Because the gateway brokers every model request and holds the keys, replacing it means re-plumbing each integration, which raises switching cost above a point tool, though that advantage comes from adoption rather than proprietary data that a rival could not assemble.

The bundling threat comes from the platforms above LiteLLM. The same cloud providers whose models LiteLLM routes can offer a gateway inside the bill an enterprise already pays, and that is the bet a buyer weighs when deciding whether to standardize on an independent open-source layer rather than a platform-native one. [s3, s6, s2]

Go-to-Market & Traction BerriAI shows the named-customer proof that open-source companies usually lack…

BerriAI shows the named-customer proof that open-source companies usually lack. The company page names Netflix as a user and carries a quote from a Lemonade architect, and Y Combinator lists Rocket Money, Samsara, and Adobe among LiteLLM users, references that appear across more than one source rather than as anonymous testimonials. Converting free adoption into named enterprise use is the step that most OSS-first tools struggle to reach.

The developer base underneath that is unusually large. The repository carries roughly 52,000 stars and 9,300 forks with a broad contributor base, and the package draws hundreds of millions of downloads a month. Those downloads suggest a large developer funnel for the paid enterprise tier.

Commercial scale beyond adoption is undisclosed. BerriAI raised about 1.6 million dollars in 2023 and sells an enterprise tier, but no audited revenue figure, paid customer count, or follow-on round appears in the public record, so the size of the business behind the free tool stays unverified. [s1, s6, s7, s10, s4]

Team & Credibility BerriAI was co-founded by Krrish Dholakia and Ishaan Jaffer, who built LiteLLM into one of the most widely used open-source AI gateways…

BerriAI was co-founded by Krrish Dholakia and Ishaan Jaffer, who built LiteLLM into one of the most widely used open-source AI gateways. The Economic Times reported the two founders and the company's 2023 raise, and Y Combinator backed the company in its 2023 batch, which is verifiable founder and accelerator signal.

The artifact itself is the strongest evidence for the team. A gateway with tens of thousands of GitHub stars, thousands of forks, and a large contributor community is a demonstrated ability to build and sustain widely used infrastructure, which the public repository documents directly.

What the public sources do not show is in-domain security pedigree. Neither founder shows a prior security exit or a sustained security publication record of the kind that lifts the strongest teams in this category, which matters for a product that brokers every model credential an enterprise routes through it. [s7, s3, s4]

Trust Readiness The March 2026 supply-chain incident is the defining trust event in LiteLLM's record…

The March 2026 supply-chain incident is the defining trust event in LiteLLM's record. Attackers published two malicious packages, litellm 1.82.7 and 1.82.8, to PyPI, and Wiz called LiteLLM the latest victim of the open-source attack spree it tracks as TeamPCP. The poisoned versions were live for roughly 40 minutes before PyPI quarantined them, and BerriAI reported that users running the official Docker image, which pins dependencies, were not affected.

BerriAI's response is the readiness signal a buyer should weigh next. The company published a detailed incident page, added verified-safe versions with checksums, and rebuilt its release pipeline into a new CI/CD pipeline with isolated environments and stronger security gates before shipping a clean version. That is a concrete remediation rather than a denial, though it follows a real breach of the release path.

The structural trust question is inherent to the product's place in the stack. LiteLLM concentrates every model credential and inspects all model traffic, so a security review will ask for the audit reports, the data-handling terms, and evidence that the rebuilt pipeline holds, and the incident makes that scrutiny more likely rather than less for a small, young vendor. [s8, s9, s2]

Competitors Portkey, Cloudflare AI Gateway, Kong, NeuralTrust, Amazon Web Services…
Company Relationship Note Compare
Portkey competes with Commercial AI gateway with routing, caching, and guardrails, the closest direct competitor to LiteLLM's proxy in the same gateway slot. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Cloudflare AI Gateway competes with Platform-native AI gateway offering routing, caching, and observability, bundled into infrastructure enterprises already buy.
Kong competes with API-gateway vendor extending its gateway to AI traffic, contesting the same routing-and-governance job from an API-management heritage. N/AWe scored these companies at different scopes, so the totals measure different things.
NeuralTrust competes with Open-source AI gateway plus runtime firewall and red teaming, overlapping LiteLLM's gateway and guardrails capabilities.
Amazon Web Services adjacent Cloud provider whose Bedrock model routing could bundle a native gateway inside the bill an enterprise already pays, the bundling threat from above. N/AAmazon Web Services is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.

Add analyzed competitors to compare them side by side with BerriAI.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 14 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

What holds a BerriAI customer, on the cited record, is the work sunk into its LiteLLM gateway, with little else alongside it. Netflix and Lemonade voices describe operational use, Adobe sits on Y Combinator's trusted-by list, and replacing the gateway means migrating its keys, budgets, routing rules, and guardrails, an inferred friction. Beyond that sunk work, a rival can match each piece: the code is open source, the guardrails run on licensable services, and SOC 2 and ISO 27001 are certifications a funded competitor can also earn. Self-managed buyers operate the software themselves, with BerriAI supplying code, releases, support, and a hosted proxy option. That install base is a head start for BerriAI, not a durable lead. A cloud provider could bundle a comparable gateway natively.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 LiteLLM is open-source software with a self-managed enterprise edition, both software-the-product, with no analyst-staffed accountability service blend, so delivery sits at the software level.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Re-pointing model traffic and migrating LiteLLM-specific keys, budgets, routing rules, and guardrail configuration is inferred friction once the gateway is embedded, but the lock-in is learned configuration rather than data gravity or a network effect.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 LiteLLM's data-security page lists SOC 2 Type I and ISO 27001 as certified with SOC 2 Type II in progress, and a March 2026 post says a Vanta recertification is underway, but these are commercial attestations that ease procurement without blocking a substitute, and the cited record documents no federal authorization or mandate for the class, so 1.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Translating 100-plus providers into one OpenAI-shaped interface and running routing, load balancing, budgets, and pre-call and post-call guardrails inline on each request at production latency is real-time distributed-systems engineering.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The named references are large engineering organizations, Netflix and Lemonade on the record plus Rocket Money, Samsara, and Adobe on Y Combinator's trusted-by list, without established paid-customer status, and the contact-sales enterprise tier addresses the procurement-gated account.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 3/3 LiteLLM is itself the gateway applications and agents route through to reach any model, infrastructure the rest of an LLM stack depends on to function rather than a plugin on a separate host platform.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 LiteLLM is open-source and forkable, the routing and guardrail backends run on licensable third-party services, and the cited record names no proprietary cross-customer corpus, so a funded rival can rebuild it from public code.
Strategic Market Segmentation BerriAI sells to the platform and machine-learning teams that hand many developers access to many models at once…

BerriAI sells to the platform and machine-learning teams that hand many developers access to many models at once. LiteLLM frames the buyer as the team giving model access across a large number of developers and projects, and the enterprise page repeats that framing, so the segment is the company that has outgrown ad-hoc per-provider integrations and needs one governed entry point.

The same product serves two adopter shapes from one codebase. A developer can install the open-source proxy for free, while a larger organization buys the self-managed enterprise tier for SSO, audit logs, and key management. That free-to-paid path lets BerriAI land bottom-up inside engineering and expand into the procurement-gated account without a separate product.

Named demand reaches well past startups. The homepage carries on-record use from Netflix and Lemonade, and Y Combinator lists Rocket Money, Samsara, and Adobe among companies that trust LiteLLM, so the buyer set spans large consumer-internet and insurance engineering organizations. The open question is how much of that adoption is the free proxy rather than the paid tier, which the public record does not separate.

Product Capabilities & AI Advantages LiteLLM translates 100-plus model providers into one OpenAI-shaped interface so a team writes against a single API instead of many…

LiteLLM translates 100-plus model providers into one OpenAI-shaped interface so a team writes against a single API instead of many. The GitHub project describes a production gateway with virtual keys, spend tracking, guardrails, load balancing, and an admin dashboard, and the proxy adds per-key and per-team budgets and rate limits on top of the unified call path.

The security capabilities run inside that gateway rather than beside it. The proxy can screen prompts and responses for PII through Presidio and run prompt-injection detection, with pre-call and post-call moderation hooks available in the open-source proxy, while model-level guardrails and key or team-scoped guardrails are enterprise features. That places policy enforcement at a chokepoint gateway-mode requests pass through. The durable advantage is adoption and provider breadth, not a model edge. The guardrail backends run on third-party services such as Presidio, Lakera, and Bedrock that any rival can also license, and no named non-public dataset appears in fetched sources. What a competitor cannot copy by writing software is the install base that already routes through LiteLLM.

Sales Engagement & Go-to-Market BerriAI's visible motion is developer adoption…

BerriAI's visible motion is developer adoption. The open-source proxy is free and self-serve from GitHub, the repository carries tens of thousands of stars and thousands of forks since its 2023 creation, and the Y Combinator jobs list shows open roles, an enterprise sales motion being built. Whether teams running the free repository become paying customers is not documented in the cited record.

Named enterprise use is the strongest conversion signal in the record. The homepage names Netflix and quotes a Lemonade architect on the record, and Y Combinator lists Rocket Money, Samsara, and Adobe among companies that trust LiteLLM, references that appear across more than one source rather than as anonymous testimonials. Turning free adoption into named production use is the step that separates BerriAI from the typical open-source project.

Commercial scale behind the adoption stays undisclosed. BerriAI reports a 1.6 million dollar seed raised from Y Combinator, Gravity Fund, and Pioneer Fund, a financing Economic Times reported as planned in August 2023, and it sells an enterprise tier through a contact-sales motion, but no audited revenue, paid-customer count, or follow-on round appears in fetched sources, so the size of the business behind the free tool is unverified.

Pricing Model BerriAI publishes a clear two-tier structure rather than hiding price entirely…

BerriAI publishes a clear two-tier structure rather than hiding price entirely. The open-source tier is listed at zero dollars with the full provider coverage, virtual keys, budgets, and guardrails, while the enterprise tier is contact-sales with custom SLAs, SSO, audit logs, and a 30-day trial. The free tier is the unit that drives adoption and the paid tier is where the company captures revenue.

What the enterprise tier charges by stays private. The page invites a buyer to request pricing rather than naming a meter such as developers, projects, request volume, or seats, which fits a negotiated enterprise deal sized to each organization. The published-then-gated split tells a buyer the free proxy is meant to pull teams in before any sales conversation.

The inferable belief is that buyers pay for governed access at scale, not for the routing itself. The free tier already carries the routing and the guardrails, so the enterprise tier prices the controls a large organization needs around them, SSO, audit logs, key rotation, and support, rather than the core gateway function.

Product Delivery & Operations LiteLLM delivers as self-managed software on its open-source and enterprise paths, plus a hosted option…

LiteLLM delivers as self-managed software on its open-source and enterprise paths, plus a hosted option. A developer can self-host the open-source proxy for free, a larger organization runs the enterprise edition as a self-managed deployment in its own cloud or on-premises environment, and the site advertises a hosted proxy, with LiteLLM Cloud users identified as a deployment group in the March 2026 incident update. The tiers ship the same routing, virtual keys, budgets, and guardrails.

The release pipeline is the operational fault line the product exposes. After the March 2026 supply-chain incident, BerriAI rebuilt releases onto a new CI/CD pipeline with isolated environments, stronger security gates, and safer release separation, and it points enterprises toward the pinned Docker image whose dependency locking spared customers during the attack. The company has also published a long-running release-validation system it describes as 24-hour load tests, built to catch regressions before they reach users.

On the self-managed paths the customer's own platform team operates the deployment while BerriAI provides the code, the release artifacts, and enterprise support, and the hosted proxy shifts that operation to BerriAI. Either way delivery sits at the software level rather than an analyst-staffed accountability service.

Earning Customers' Trust The March 2026 supply-chain attack is the defining trust event in LiteLLM's record…

The March 2026 supply-chain attack is the defining trust event in LiteLLM's record. Attackers published two malicious packages, litellm 1.82.7 and 1.82.8, to PyPI, live for about 40 minutes by LiteLLM's account, while Wiz reports publication at approximately 8:30 UTC and quarantine at 11:25 UTC, nearly three hours, a conflict the record leaves open. Wiz called LiteLLM the latest victim of the open-source attack spree it tracks as TeamPCP. BerriAI said it believed the compromise originated from a poisoned Trivy dependency in its CI/CD scanning workflow, a PyPI advisory relayed by Wiz identifies an API token exposed via the prior Trivy incident as the root cause, and the company reported that customers on the pinned Docker image were not affected.

The response is the readiness signal a buyer should weigh next. BerriAI published a detailed incident page, shipped a clean version through a rebuilt CI/CD pipeline with isolated environments and stronger gates, and verified no malicious code reached the main branch. That is concrete remediation rather than denial, though it follows a real breach of the release path for a product that holds privileged credentials.

Formal compliance collateral is vendor-claimed, self-displayed, and internally inconsistent. LiteLLM's data-security page lists SOC 2 Type I and ISO 27001 as certified and SOC 2 Type II as in progress with a certificate expected by April 15, 2025, a date already long past when the page was reviewed, while a March 2026 post says the company is partnering with Vanta to recertify SOC 2 Type 2 and ISO 27001 and is still identifying independent auditors to verify its posture. A buyer reading only these pages cannot tell which attestations are current, and the reports themselves are available on request rather than published.

These are commercial certifications rather than a federal authorization, so an enterprise security review of a gateway that can centralize access to provider credentials and model traffic leans on those attestations alongside the open code, the incident response, and the enterprise controls.

Platform Strategy & Ecosystem Positioning LiteLLM is itself the gateway that applications and agents route through to reach any model, not a plugin on someone else's platform…

LiteLLM is itself the gateway that applications and agents route through to reach any model, not a plugin on someone else's platform. The proxy is positioned as the central service a team points all model traffic at, which makes it infrastructure the rest of an organization's LLM stack depends on to function rather than an optional add-on beside a host platform.

That position is the source of both the switching cost and the bundling exposure. Because gateway deployments concentrate model requests and credentials, replacing one means repointing traffic and migrating LiteLLM-specific keys, budgets, routing rules, and guardrail configuration, friction that follows from the integration surface itself, though the cited record documents no completed migration, and the OpenAI-compatible interface it standardizes on may ease a move to another compatible gateway.

The exposure is that the platforms above LiteLLM route the same models. The cloud providers whose models LiteLLM proxies, and commercial gateway vendors, could bundle comparable routing, budgets, and guardrails natively, which would leave an independent open-source layer competing against routing a buyer already receives by default, though the cited record does not document specific substitutes or their commercial terms.

Team & Execution Capability BerriAI's credibility comes from two founders who built widely used infrastructure…

BerriAI's credibility comes from two founders who built widely used infrastructure. Krrish Dholakia and Ishaan Jaffer co-founded the company, took it through Y Combinator in 2023, and grew LiteLLM into an open-source gateway with tens of thousands of GitHub stars and thousands of forks, which the repository itself and Y Combinator's company profile document. The artifact itself, a gateway with tens of thousands of GitHub stars and thousands of forks, is the strongest evidence for the team.

The funding and accelerator signal is real but early. The company reports a raised 1.6 million dollar seed with Y Combinator support, which Economic Times covered as planned in August 2023, a credible seed for an open-source motion, though no later disclosed round appears in fetched sources, and the Y Combinator page lists open roles, active enterprise-facing hiring.

What the cited record does not show is in-domain security pedigree. It does not establish a prior security-company exit or a sustained security publication record for either founder, which matters for a product whose deployment and release path can centralize access to provider credentials and model traffic, and the March 2026 incident raises that bar rather than lowering it.

Sources

Company Detail Sources (6)
Id Source Tier Accessed
f1 LiteLLM: AI Gateway for 100+ LLMs official 2026-07-09
f2 BerriAI/litellm GitHub API (repository created date) official 2026-06-13
f3 LiteLLM AI Gateway company page on LinkedIn (About, Headquarters) official 2026-07-31
f4 Y Combinator LiteLLM profile, raised seed round other 2026-07-16
f5 AI Defense Matrix Catalog entry other 2026-06-09
f6 AI Defense Matrix Catalog mapping other 2026-06-23
Profile Analysis Sources (12)
Id Source Tier Accessed
s1 LiteLLM homepage with Netflix and Lemonade customer quotes
“Netflix uses LiteLLM to give developers Day 0 LLM access ... Our experience with LiteLLM and Langfuse at Lemonade has been outstanding.”
official 2026-06-13
s2 LiteLLM Enterprise (self-managed deployment, SSO, audit logs)
“Ideal for organizations giving LLM access to a large number of developers and projects.”
official 2026-06-13
s3 BerriAI/litellm GitHub repository (AI gateway features, README)
“Python SDK, Proxy Server (AI Gateway) to call 100+ LLM APIs in OpenAI (or native) format, with cost tracking, guardrails, loadbalancing and logging.”
official 2026-06-13
s4 BerriAI/litellm GitHub API (stars, forks, created date)
“stargazers_count 52176 forks_count 9338 created_at 2023-07-27T00:09:52Z”
official 2026-07-01
s5 LiteLLM docs (Getting Started, 100+ providers, OpenAI format)
“Call 100+ LLMs using the OpenAI Input/Output Format”
official 2026-06-13
s6 Y Combinator company page for LiteLLM (named customers, W23)
“LiteLLM is an open-source LLM Gateway with 18K+ stars on GitHub and trusted by companies like Rocket Money, Samsara, Lemonade, and Adobe.”
other 2026-06-13
s7 Economic Times on Berri AI raising 1.6 million dollars (Aug 2023)
“Berri AI, co-founded by Ishaan Jaffer and Krrish Dholakia, is planning to raise $1.6 million in funding.”
press 2026-06-13
s8 LiteLLM Security Update on the March 2026 supply-chain incident
“Customers running the official LiteLLM Proxy Docker image were not impacted ... We have now released a new safe version of LiteLLM (v1.83.0) by our new CI/CD v2 pipeline which added isolated environments, stronger security gates, and safer release separation for LiteLLM.”
official 2026-06-13
s9 Wiz on the TeamPCP supply-chain attack trojanizing LiteLLM (Mar 2026)
“LiteLLM is the latest victim of TeamPCP’s open-source attack spree.”
press 2026-06-13
s10 PyPI download statistics for the litellm package
“last_month 558038133 last_week 133535310”
other 2026-06-13
s11 LiteLLM Guardrails Quick Start (prompt injection detection, PII masking)
“Setup Prompt Injection Detection, PII Masking on LiteLLM Proxy (AI Gateway)”
official 2026-06-16
s12 BerriAI/litellm LICENSE (MIT, with an enterprise directory carve-out)
“All content that resides under the enterprise/ directory of this repository, if that directory exists, is licensed under the license defined in enterprise/LICENSE. Content outside of the above mentioned directories or restrictions above is available under the MIT license as defined below.”
official 2026-07-01
Deep-Dive Sources (12)
Id Source Tier Accessed
s1 LiteLLM homepage: Netflix and Lemonade customer quotes and pricing
“LiteLLM has let my team provide the latest LLM models to our users usually within a day of them being released. David Leen, Staff Software Engineer, Netflix. Our experience with LiteLLM and Langfuse at Lemonade has been outstanding. Mark Koltnuk, Principal Architect, Lemonade.”
official 2026-06-17
s2 BerriAI/litellm GitHub README (open source AI Gateway, features)
“LiteLLM is an open source AI Gateway that gives you a single, unified interface to call 100+ LLM providers using the OpenAI format. Production-ready gateway, virtual keys, spend tracking, guardrails, load balancing, and an admin dashboard out of the box.”
official 2026-06-17
s3 LiteLLM Enterprise (self-managed deployment, SSO, audit logs)
“Ideal for organizations giving LLM access to a large number of developers and projects. Available as a secure, self-managed deployment. LiteLLM Enterprise adds: SSO, SCIM, 24/7 Support, OIDC/JWT-Auth, Team/Org Admins, Key/Team-based Guardrails, Secret Managers, Key Rotations.”
official 2026-06-18
s4 BerriAI/litellm GitHub API (stars, forks, created date)
“stargazers_count 50705 forks_count 8948 created_at 2023-07-27T00:09:52Z”
official 2026-06-17
s5 LiteLLM Guardrails Quick Start (PII masking, prompt injection)
“Setup Prompt Injection Detection, PII Masking on LiteLLM Proxy (AI Gateway). guardrail: presidio, supported values aporia, bedrock, lakera, presidio, mode pre_call. Model-level Guardrails: This is an Enterprise only feature.”
official 2026-07-01
s6 Y Combinator LiteLLM profile (named customers, founders)
“open-source LLM Gateway with 18K+ stars on GitHub and trusted by companies like Rocket Money, Samsara, Lemonade, and Adobe. Krrish Dholakia, Founder. Ishaan Jaffer.”
other 2026-06-17
s7 LiteLLM Security Update on the March 2026 supply-chain incident
“The compromised PyPI packages litellm 1.82.7 and 1.82.8 were live for about 40 minutes before being quarantined by PyPI. Customers running the official LiteLLM Proxy Docker image were not impacted. We released a new safe version (v1.83.0) by our new CI/CD v2 pipeline with stronger gates.”
official 2026-06-18
s8 Wiz on the TeamPCP supply-chain attack trojanizing LiteLLM (Mar 2026)
“LiteLLM is the latest victim of TeamPCP's open-source attack spree. ... The packages were published at approximately 8:30 UTC and quarantined by PyPI at 11:25 UTC . An PyPI advisory has been posted here , identifying an API token exposed via the prior Trivy incident as the root cause.”
press 2026-06-17
s9 Economic Times on Berri AI raising 1.6 million dollars (Aug 2023)
“Berri AI, co-founded by Ishaan Jaffer and Krrish Dholakia, is planning to raise $1.6 million in funding. The startup has also received support from startup accelerator Y-Combinator.”
press 2026-06-17
s10 LiteLLM Data Privacy and Security: audit and certification status
“Has the Vendor been audited / certified? SOC 2 Type I. Certified. Report available upon request on Enterprise plan. SOC 2 Type II. In progress. Certificate available by April 15th, 2025. ISO 27001. Certified. Report available upon request on Enterprise plan.”
official 2026-07-01
s11 LiteLLM Blog: LiteLLM + Vanta SOC 2 Type 2 and ISO 27001 Recertification
“We are partnering with Vanta to recertify LiteLLM's compliance for SOC 2 Type 2 and ISO 27001. As part of this process, we are also identifying independent auditors to validate and verify our compliance posture.”
official 2026-07-01
s12 LiteLLM Blog: Improve release stability with 24 hour load tests
“How we built a long-running, release-validation system to catch regressions before they reach users. Alexsander Hamir, Krrish Dholakia, Ishaan Jaffer, February 6, 2026.”
official 2026-06-18

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.