OpenRouter AI configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On OpenRouter AI, Black Cat runs 23 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the OpenRouter AI connector needs.
Checks (23)
severity: medium API Key Without Spend Limit fix difficulty: easy #
Set a credit spend limit on the API key
- Open Settings → API Keys in the OpenRouter dashboard
- Edit the key and set a credit limit appropriate to its use
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium API Key Without Expiry fix difficulty: easy #
Set an expiry date so the key rotates
- Edit the key in Settings → API Keys
- Set an expires_at date and plan rotation before it lapses
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Disabled API Key Not Deleted fix difficulty: easy #
Delete disabled keys that are no longer needed
- Review the disabled key in Settings → API Keys
- Delete it if it is no longer required
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Stale API Key fix difficulty: easy #
Rotate or delete keys with no recent usage
- Confirm the key is genuinely unused
- Delete it, or rotate it if it must stay
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium BYOK Spend Uncapped fix difficulty: medium #
Include BYOK usage in the key spend limit
- Edit the key in Settings → API Keys
- Enable include_byok_in_limit so BYOK usage counts against the cap
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low API Key Spend Limit Without Reset Interval fix difficulty: easy #
Set a reset interval on the key's spend limit
- Edit the key in Settings → API Keys
- Set a reset interval (e.g. monthly) instead of leaving the limit as a lifetime cap
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium API Key Relies Solely On Workspace Default Guardrail fix difficulty: medium #
Assign a dedicated guardrail to the key or its creator
- Open the key's workspace guardrail settings
- Assign a guardrail directly to the key or to its creator, rather than relying only on the workspace default
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Workspace Without Guardrails fix difficulty: medium #
Configure content guardrails for the workspace
- Open the workspace's guardrails settings
- Add at least one guardrail appropriate to your use
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Workspace Without Spending Budget fix difficulty: easy #
Set a spending budget on the workspace
- Open the workspace's budget settings
- Add a budget with an appropriate reset interval
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Guardrail Without Content Filters fix difficulty: medium #
Configure at least one content filter on the guardrail
- Open the guardrail in the workspace settings
- Add a builtin or custom content filter appropriate to your use
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Guardrail Without Key Or Member Assignments fix difficulty: easy #
Assign the guardrail to keys or members, or remove it
- Open the guardrail in the workspace settings
- Assign it to the API keys or members it should govern, or delete it if unused
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low API Key Sprawl fix difficulty: medium #
Reduce the number of active API keys
- Audit active keys and their owners
- Delete keys that are unused or redundant
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low BYOK Credential Disabled Not Deleted fix difficulty: easy #
Delete disabled BYOK credentials that are no longer needed
- Review the disabled BYOK credential in Settings → Provisioning Keys
- Delete it if it is no longer required
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium BYOK Spend Ungoverned fix difficulty: easy #
Set a spend budget on the credential's workspace
- Open the workspace's budget settings
- Add a budget so BYOK spend through this credential is capped
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Excessive BYOK Provider Diversity fix difficulty: medium #
Consolidate BYOK credentials to fewer providers
- Review the organization's BYOK credentials in Settings → Provisioning Keys
- Remove credentials for providers that are no longer in active use
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Workspace Has Excessive Members fix difficulty: medium #
Review workspace membership and remove members who no longer need access
- Open the workspace's member settings
- Remove members who no longer need access to reduce blast radius
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low SCIM Mapping Stale fix difficulty: easy #
Review SCIM mappings that have not changed in over 180 days
- Open Settings → SCIM in the OpenRouter dashboard
- Confirm the mapping still reflects current provisioning intent
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Preset Targets Model Outside Workspace Allowlist fix difficulty: medium #
Restrict the preset to models allowed by its workspace's default guardrail
- Open the preset in Settings → Presets
- Remove or replace target/fallback models not covered by the workspace default guardrail's allowlist
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Disabled Preset Not Deleted fix difficulty: easy #
Delete disabled or archived presets that are no longer needed
- Review the disabled/archived preset in Settings → Presets
- Delete it if it is no longer required
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Stale Preset fix difficulty: easy #
Review presets with no recent activity
- Confirm the preset is genuinely still in use
- Delete it, or update its designated version if it must stay
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Stale File fix difficulty: easy #
Review files with no recent activity and delete if no longer needed
- Open Settings → Files in the OpenRouter dashboard
- Confirm the file is genuinely still in use
- Delete it if it is no longer needed
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Oversized File fix difficulty: easy #
Review large uploaded files for necessity
- Open Settings → Files in the OpenRouter dashboard
- Confirm the file's size is expected and still required
- Delete it if it is no longer needed
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Excessive Model Diversity fix difficulty: medium #
Review why the organization used more than 50 distinct models in 30 days
- Review Activity in the OpenRouter dashboard to see which models were used
- Restrict routing to an approved model set via workspace defaults or guardrails
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10