AI infrastructure for Saudi Arabia

LLM Gateway for Saudi Arabia: Routing AI Across Global and In-Kingdom Models

One API to access and intelligently route across global and locally hosted AI models — based on data residency, quality, cost, and latency. Built for enterprises operating under Saudi Arabia's data and AI regulatory landscape.

What an AI gateway does — and why the region needs one built for it

An AI gateway sits between your applications and the model providers you use. Instead of your engineering team wiring up separate integrations for OpenAI, Anthropic, Gemini, and every other provider, a gateway gives you one API and one key, and routes each request to wherever it needs to go — the model best suited for that request's cost, quality, and latency requirements.

That's the model most AI gateways were built around, and it works well for teams operating in the US and EU. It breaks down the moment data residency becomes a real requirement rather than a nice-to-have — which, for enterprises operating in Saudi Arabia, it increasingly is.

The gap: global AI infrastructure wasn't built with Saudi residency in mind

Saudi Arabia's Personal Data Protection Law (PDPL) governs how personal data — including data sent to a third-party AI model — can be collected, processed, and transferred outside the Kingdom. SDAIA (the Saudi Data and AI Authority) has published an AI Adoption Framework that public-sector entities are expected to follow when procuring AI systems. Financial institutions face an additional layer under SAMA's cloud computing framework, which governs what a bank can send to an external service at all.

None of this means every byte of data must physically stay inside Saudi Arabia — PDPL's transfer rules permit cross-border processing under the right safeguards, and treating "everything must stay local" as a blanket rule is itself inaccurate. What it does mean is that routing decisions need to account for where data is allowed to go, not just which model is cheapest or fastest. That's a dimension most AI gateways don't have, because most weren't built with a jurisdiction like Saudi Arabia's in mind.

AI gateway, AI router, LLM gateway — same category, different names

These terms get used somewhat interchangeably, and it's worth being clear about it rather than picking one and hoping the reader translates: an AI gateway, an AI router, and an LLM gateway all describe the same category of infrastructure — a single layer that sits between your applications and every model provider you use, making a routing decision on each request. Mizan is all three, by whichever name you're searching for it.

How Mizan routes: one API, every model, residency-aware

Mizan gives you a single API key and routes each request across the providers you use — OpenAI, Anthropic, Gemini, Bedrock, and others — by changing nothing but the model name in your code. On top of that baseline, routing decisions can account for:

  • Data residency — where a given request is and isn't allowed to go
  • Quality — which model performs best for a given task
  • Cost — provider pricing and Mizan's own routing/caching savings
  • Latency — response time, including the effect of regional distance to a provider's infrastructure

Locally hosted models in Saudi Arabia are supported as part of this routing layer where they're available — the regional infrastructure landscape (national initiatives like HUMAIN, and Saudi's own large language model effort, ALLaM, among others) is still maturing, and Mizan's routing is built to extend to it rather than assume it away.

Built with Saudi privacy requirements in mind

Mizan includes Aman, a layer that scans requests and strips personally identifiable information — emails, credit card numbers, ID numbers, addresses — before they reach a model, whether that model is hosted globally or in-Kingdom. Aman is built with Saudi data-residency and privacy requirements in mind.

To be direct about what that does and doesn't mean: Mizan does not claim formal PDPL certification, and using Mizan is not a substitute for your own compliance review. What we've built is infrastructure designed around these requirements — the compliance judgment is yours to make.

Beyond routing: visibility and cost, without losing the plot

Routing is the core of what Mizan does. Two things sit on top of it because most teams that adopt a gateway end up needing them anyway: full visibility into what every request costs and who generated it (including usage that never touches Mizan's API directly, via connected admin keys), and automatic cost optimization — Mizan routes to the most cost-efficient model that still meets your quality bar, and caches responses so you don't pay for the same call twice.

Who this is for

  • Engineering teams consolidating multiple provider integrations behind one API, without giving up the ability to route by region
  • Enterprises with mixed global and local model needs — using the best available model for each task, regardless of where it's hosted
  • Regulated industries — banking and financial services operating under SAMA's cloud framework, and public-sector organizations following SDAIA's AI Adoption Framework — that need routing decisions to be residency-aware by design, not bolted on after the fact

For a closer look at the routing mechanics — how Mizan decides where each request goes.For why residency belongs in that decision at all — Residency-Aware Routing.To see how Mizan compares to other gateways — Best AI Gateways for Saudi Arabia.

Questions, answered.

Does Mizan guarantee my data stays in Saudi Arabia?+

No — and we wouldn't want to overstate this. Mizan supports routing to locally hosted models in Saudi Arabia where they're available, and lets you make residency-aware routing decisions. Whether a specific request needs to stay in-Kingdom, and which providers satisfy that, is a decision you make with your own compliance review — Mizan is infrastructure for that decision, not a certification of it.

Is Mizan PDPL compliant?+

We don't claim formal PDPL certification. Mizan is built with Saudi data-residency and privacy requirements in mind — including Aman, which strips PII before requests reach a model — but compliance is a judgment your organization needs to make about your own use case, not a badge a vendor can hand you.

Can I route to local Saudi-hosted models today?+

Mizan's routing layer is built to support locally hosted models in Saudi Arabia as they become available through the region's infrastructure providers. Today, most routing happens across the major global providers (OpenAI, Anthropic, Gemini, Bedrock, and others); local-model support extends as that landscape matures.

How is this different from a global gateway like OpenRouter or LiteLLM?+

Global gateways route across providers, but data-residency for Saudi Arabia and the wider region generally isn't part of that picture — OpenRouter's own documentation, for example, covers in-region routing for the EU and US only. Mizan is built with Saudi Arabia and the GCC as the primary market, not an afterthought.

What happens to requests that don't need residency controls?+

They route the same way any request through Mizan does — to whichever model best fits the cost, quality, and latency you need. Residency-aware routing is an additional dimension Mizan can apply, not a mode you have to opt into for everything.

Route your AI the way your data actually needs to move.

One API key. Every model — global and, where available, local.

Access Mizan