---
title: "Zuplo for Enterprise"
description:
  "One platform for API, AI Gateway, and MCP traffic — built for enterprise
  requirements. SOC 2 Type II, SSO/RBAC, audit logs, multi-cloud and self-hosted
  deployments, contractual SLAs, and the governance to scale without growing
  your platform team."
canonicalUrl: "https://zuplo.com/enterprise"
sourceUrl: "https://zuplo.com/enterprise"
pageType: "product"
generatedAt: "2026-08-03"
---

# Zuplo for Enterprise

> The unified gateway for APIs, AI, and MCP — with SOC 2, SSO/RBAC, audit logs,
> and dedicated deployments included. Run enterprise APIs without the enterprise
> rollout; most enterprise customers are in production within weeks, not months.

## At a glance

| Metric                   | Value   |
| ------------------------ | ------- |
| Edge locations worldwide | 300+    |
| Enterprise uptime SLA    | 99.999% |
| Edge latency             | <50ms   |
| Premium support response | 30 min  |

## One platform, every layer

Same auth, RBAC, and SLAs for APIs, AI, and MCP. Apply the policies and
governance you already enforce on your APIs to LLM traffic and agent tool calls
— no fragmented stack to secure or budget for.

### AI Gateway — Route LLM traffic, cap spend per team

Sit in front of every LLM call. Token budgets, semantic caching, per-team
quotas, and audit logs for every model — OpenAI, Anthropic, Bedrock, custom.

- Cost predictability across providers
- Per-tenant quotas and budgets
- Failover and load-balancing between models

[Explore AI Gateway](/ai-gateway)

### MCP Gateway — Ship MCP to customers; govern the MCP your teams use

Centralize discovery, auth, and access controls for every MCP server your agents
call — RBAC, virtual MCP servers, and segmented tool access.

- Approved-server registry for the org
- Per-role tool exposure with audit trail
- Block prompt-injection and tool abuse

[Explore MCP Gateway](/mcp-gateway)

### MCP Server — Your OpenAPI, as MCP tools

Auto-generate a compliant Model Context Protocol server from your OpenAPI spec.
Same auth, rate limits, and observability as your APIs.

- No code — generated from OpenAPI
- Inherit existing API policies
- Ship safely to agents in minutes

[Explore MCP Server](/features/mcp-servers)

### API Management — Portal, keys, rate limits, GitOps

Auth, rate limits, validation, caching, and developer portals — managed via
GitOps in TypeScript.

- Edge-deployed in 300+ locations
- Custom policies in TypeScript, not XML
- Self-service developer portal included

[Explore API Management](/api-management)

## Trust & compliance

Pass security review on the first round. **SOC 2 Type II · SAML SSO · RBAC ·
Audit logs · DPAs & BAAs available.** Everything your security, legal, and
procurement teams need — shipped as part of the platform, documented, and ready
to share under NDA.

- **SOC 2 Type II** — Independently audited security controls.
- **SAML SSO** — Okta, Azure AD, Google Workspace.
- **RBAC** — Role-based access for every workspace.
- **Audit logs** — Every config change, every action.
- **Data residency** — Region pinning across AWS, Azure, GCP.
- **Pen test on request** — Third-party report available under NDA.
- **Custom DPAs & BAAs** — Redlines welcome. Legal won't block you.
- **99.999% uptime SLA** — Contractual guarantees, not aspirations.

[Visit the Trust Center →](https://trust.zuplo.com). Request a security audit
via the Solutions Architect meeting request form.

## Deployment options

Edge, dedicated, or your cluster — same platform. Move between deployment
surfaces as your compliance, performance, and sovereignty needs evolve. Your
policies, API keys, and dashboards travel with the project.

### Managed Edge — _Fastest to value_

Serverless on 300+ data centers worldwide. Push to git, live in under a minute.

- Zero infrastructure to run
- Sub-50ms latency, globally
- Auto-scales through every spike

[Edge deployment](/features/global-high-performance)

### Managed Dedicated — _Most popular for enterprise_

Single-tenant Zuplo on the cloud of your choice — Akamai, AWS, Azure, GCP, or
Equinix. Operated by us.

- Isolated infrastructure, your cloud
- Region pinning for data residency
- Capacity & throughput commitments

[Dedicated deployments](/features/multi-cloud)

### Self-Hosted — _Full control_

Helm chart on any Kubernetes cluster — EKS, AKS, GKE, OpenShift, on-prem. Hybrid
or fully air-gapped.

- Your cluster, your data plane
- Same policies, managed from one place
- Designed for the strictest compliance

[Self-hosted topology](/features/multi-cloud)

## Build your Enterprise plan

Pick the add-ons your team needs. A Solutions Architect will put together a
custom quote tailored to your usage. Custom pricing **starts at $1,000/mo**
(annual contract; volume discounts available — final pricing depends on
requests/month, SLA, and selected add-ons). Quote turnaround is usually under 24
hours.

Available add-ons:

- **Logging Plugins** — DataDog, Loki, AWS CloudWatch, and more.
- **Observability** — OpenTelemetry traces for every API stage.
- **SSO + RBAC** — Enterprise identity with role-based access.
- **Private Connectivity** — Secure tunneling, mTLS, and VPC peering.
- **Extended Retention** — Longer analytics, log, and trace history windows.
- **Enterprise Support** — Up to 30-minute response time SLA.
- **Managed Dedicated** — Zuplo deployed to your cloud of choice on dedicated
  infrastructure.
- **Self-Hosted** — Run Zuplo on your own infrastructure with full control.
- **Audit Logs** — Full audit trail of every management operation on your
  gateway.
- **WebSockets & SSE** — Real-time communication with WebSocket and Server-Sent
  Events.
- **SOC 2 Type II** — Independently audited security controls for your
  compliance review.
- **Penetration Test Report** — Third-party penetration test results available
  under NDA.
- **API Governance with Claude** — AI-powered governance to enforce consistency
  across endpoints.
- **24/7/365 Emergency Hotline** — Round-the-clock phone support for critical
  production incidents.

## Trusted by engineering teams at scale

Blockdaemon: **90%** hardware footprint reduction at scale.

> The move to Zuplo from our existing API Management vendor was easy, taking
> just over 2 months to switch mission critical systems, and we're saving over
> 70% on costs.
>
> — Ryan Waites, Senior Director, Blockdaemon
> ([case study](/customers/blockdaemon))

> Zuplo gives us the flexibility to scale efficiently, ensures security and
> compliance, and reduces operational complexity so we can focus on building new
> capabilities.
>
> — Daryl Benzel, Staff Software Engineer, Yext ([case study](/customers/yext))

AccuWeather: **1B+** end users served via Zuplo APIs.

Finsolutia: **Hours** to launch an MCP server on regulated APIs.

> We didn't touch a line of code, it's just plug and play. The results were very
> surprising, in just a couple of hours we had a great result and a fully
> working MCP Server.
>
> — Miguel Madeira, CTO & Co-Founder, Finsolutia
> ([case study](/customers/finsolutia))

## Switching from Kong, Apigee, or AWS API Gateway?

Most teams cut gateway spend by 40–70% in the first quarter.

### Zuplo vs Kong

Typical pain: self-managed control plane; plugins in Lua, hard to share across
teams; manual scaling and cluster ops. What Zuplo does: fully managed — 60s to
deploy; TypeScript-native policies in your repo; auto-scaled across 300+ edge
locations. [See the full Kong comparison](/api-gateways/kong-alternative-zuplo)

### Zuplo vs Apigee

Typical pain: XML & JSON-string policy config; long onboarding & GCP lock-in;
per-seat developer pricing. What Zuplo does: code-first config in your IDE; free
tier, deploy from GitHub in minutes; pay per request, not per seat.
[See the full Apigee comparison](/api-gateways/apigee-alternative-zuplo)

### Zuplo vs AWS API Gateway

Typical pain: region-bound and AWS-only; plumbing required for auth, rate limit,
portal; cost grows fast with custom integrations. What Zuplo does: edge-native,
multi-cloud and on-prem; batteries included — auth, keys, portal, monetization;
transparent usage pricing — no surprise egress.
[See the full AWS API Gateway comparison](/api-gateways/aws-api-gateway-alternative-zuplo)

## Enterprise FAQ

The questions security, legal, and procurement teams ask before signing.

**Is Zuplo SOC 2 compliant?** Yes. Zuplo is SOC 2 Type II audited. Our latest
report is available under NDA — your team can request it from your Solutions
Architect during evaluation, along with our penetration test results and HIPAA /
BAA documentation.

**Can Zuplo run inside our cloud account or data center?** Three options. (1)
Managed Edge — serverless on 300+ data centers worldwide. (2) Managed Dedicated
— single-tenant Zuplo that we operate on Akamai, AWS, Azure, GCP, or Equinix,
with region pinning for data residency. (3) Self-Hosted — Helm chart on any
Kubernetes cluster (EKS, AKS, GKE, OpenShift, on-prem), in either Hybrid or
fully air-gapped modes. The same policies, dashboards, and analytics work across
all three.

**How does Zuplo handle SSO, RBAC and provisioning?** Enterprise plans include
SAML SSO with Okta, Azure AD, Google Workspace, and any SAML 2.0 IdP. Role-based
access is enforced per workspace, with custom roles available on request. SCIM
provisioning is on the roadmap; in the meantime, JIT provisioning is supported
on first SSO login.

**What does the migration from our legacy gateway look like?** Most teams are in
production within weeks, not months. We map your existing policies (Apigee XML,
Kong plugins, AWS API Gateway, Azure APIM) to Zuplo's TypeScript policy model,
run side-by-side traffic during cutover, and your Solutions Architect owns the
migration plan end-to-end. AccuWeather migrated 1B+ users from Apigee.
Blockdaemon switched in just over two months and saved 70%+ on costs.

**How is enterprise pricing structured?** Enterprise plans start at $1,000/month
on an annual contract, with volume-based discounts. Pricing is based on
requests/month, selected add-ons (SSO/RBAC, dedicated infrastructure, premium
support, etc.), and your SLA tier. No per-seat fees. A Solutions Architect will
put together a custom quote — typical turnaround is under 24 hours.

**Who do we talk to during procurement and security review?** Every enterprise
customer gets a named Solutions Architect for evaluation, an Account Executive
for commercial, and a Customer Success Manager post-signature. We handle custom
contracts, redlines, DPAs, BAAs, and security questionnaires (SIG, CAIQ,
custom). For Premium support, you also get a 24/7/365 emergency hotline and a
30-minute response SLA on critical incidents.

**How does Zuplo support governance across many teams?** Centralized policy
enforcement — define auth, rate limits, logging, and validation once, and apply
them across every team and project. OpenAPI specs are linted in CI; AI-assisted
governance can flag endpoints deploying without authentication. Audit logs
capture every management operation, exportable to your SIEM of choice.

**Does the enterprise plan cover AI Gateway, MCP Gateway, and MCP servers?** Yes
— all of it. API Management, AI Gateway, MCP Gateway, and the auto-generated MCP
Server capability are included in every Zuplo plan, including Enterprise. Same
auth, same RBAC, same audit logs across all of them. You apply the same
governance to LLM traffic and MCP agent tool calls that you apply to your APIs,
and pay only for traffic you actually send.

**What observability tools does Zuplo integrate with?** OpenTelemetry traces for
every request stage, plus first-class logging plugins for Datadog, Splunk, New
Relic, Loki, AWS CloudWatch, and Azure Monitor. Real-time event feeds,
exportable analytics, and a full audit trail are part of every Enterprise plan.

## Next steps

- Start for free: https://portal.zuplo.com/signup
- Book a meeting with a Solutions Architect:
  `/schedule-call?utm_content=enterprise-final-cta`
- Request a security audit (Solutions Architect meeting request form)
- Build a custom Enterprise plan and get a quote (usually under 24 hours):
  `/schedule-call?utm_content=enterprise-addons`
