The 17 OpenRouter AI security checks Black Cat runs
Black Cat SSPM evaluates 17 security policies against your OpenRouter AI configuration on every scan, classifies each finding by risk, and provides remediation steps. Below is the full list, grouped by category.
availability
Top up credits to avoid service interruption
configuration
Set a credit spend limit on the API key
Set an expiry date so the key rotates
Delete disabled keys that are no longer needed
Rotate or delete keys with no recent usage
Include BYOK usage in the key spend limit
Configure content guardrails for the workspace
Set a spending budget on the workspace
Re-enable or remove the disabled guardrail
Reduce the number of active API keys
data protection
Disable prompt/response logging unless required and lawful
Reduce I/O logging sampling below 100%
Review observability broadcast for the workspace
Disable data-for-discount logging on the workspace
Review and restrict export of LLM prompt/response data
Restrict routing to providers that may train on or log data
identity
Reduce the number of organization admins