Skip to content

OpenRouter AI configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On OpenRouter AI, Black Cat runs 23 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the OpenRouter AI connector needs.

Checks (23)

severity: medium API Key Without Spend Limit fix difficulty: easy #

Set a credit spend limit on the API key

  1. Open Settings → API Keys in the OpenRouter dashboard
  2. Edit the key and set a credit limit appropriate to its use

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium API Key Without Expiry fix difficulty: easy #

Set an expiry date so the key rotates

  1. Edit the key in Settings → API Keys
  2. Set an expires_at date and plan rotation before it lapses

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Disabled API Key Not Deleted fix difficulty: easy #

Delete disabled keys that are no longer needed

  1. Review the disabled key in Settings → API Keys
  2. Delete it if it is no longer required

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Stale API Key fix difficulty: easy #

Rotate or delete keys with no recent usage

  1. Confirm the key is genuinely unused
  2. Delete it, or rotate it if it must stay

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium BYOK Spend Uncapped fix difficulty: medium #

Include BYOK usage in the key spend limit

  1. Edit the key in Settings → API Keys
  2. Enable include_byok_in_limit so BYOK usage counts against the cap

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low API Key Spend Limit Without Reset Interval fix difficulty: easy #

Set a reset interval on the key's spend limit

  1. Edit the key in Settings → API Keys
  2. Set a reset interval (e.g. monthly) instead of leaving the limit as a lifetime cap

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium API Key Relies Solely On Workspace Default Guardrail fix difficulty: medium #

Assign a dedicated guardrail to the key or its creator

  1. Open the key's workspace guardrail settings
  2. Assign a guardrail directly to the key or to its creator, rather than relying only on the workspace default

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Workspace Without Guardrails fix difficulty: medium #

Configure content guardrails for the workspace

  1. Open the workspace's guardrails settings
  2. Add at least one guardrail appropriate to your use

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Workspace Without Spending Budget fix difficulty: easy #

Set a spending budget on the workspace

  1. Open the workspace's budget settings
  2. Add a budget with an appropriate reset interval

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Guardrail Without Content Filters fix difficulty: medium #

Configure at least one content filter on the guardrail

  1. Open the guardrail in the workspace settings
  2. Add a builtin or custom content filter appropriate to your use

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Guardrail Without Key Or Member Assignments fix difficulty: easy #

Assign the guardrail to keys or members, or remove it

  1. Open the guardrail in the workspace settings
  2. Assign it to the API keys or members it should govern, or delete it if unused

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low API Key Sprawl fix difficulty: medium #

Reduce the number of active API keys

  1. Audit active keys and their owners
  2. Delete keys that are unused or redundant

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low BYOK Credential Disabled Not Deleted fix difficulty: easy #

Delete disabled BYOK credentials that are no longer needed

  1. Review the disabled BYOK credential in Settings → Provisioning Keys
  2. Delete it if it is no longer required

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium BYOK Spend Ungoverned fix difficulty: easy #

Set a spend budget on the credential's workspace

  1. Open the workspace's budget settings
  2. Add a budget so BYOK spend through this credential is capped

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Excessive BYOK Provider Diversity fix difficulty: medium #

Consolidate BYOK credentials to fewer providers

  1. Review the organization's BYOK credentials in Settings → Provisioning Keys
  2. Remove credentials for providers that are no longer in active use

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Workspace Has Excessive Members fix difficulty: medium #

Review workspace membership and remove members who no longer need access

  1. Open the workspace's member settings
  2. Remove members who no longer need access to reduce blast radius

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low SCIM Mapping Stale fix difficulty: easy #

Review SCIM mappings that have not changed in over 180 days

  1. Open Settings → SCIM in the OpenRouter dashboard
  2. Confirm the mapping still reflects current provisioning intent

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Preset Targets Model Outside Workspace Allowlist fix difficulty: medium #

Restrict the preset to models allowed by its workspace's default guardrail

  1. Open the preset in Settings → Presets
  2. Remove or replace target/fallback models not covered by the workspace default guardrail's allowlist

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Disabled Preset Not Deleted fix difficulty: easy #

Delete disabled or archived presets that are no longer needed

  1. Review the disabled/archived preset in Settings → Presets
  2. Delete it if it is no longer required

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Stale Preset fix difficulty: easy #

Review presets with no recent activity

  1. Confirm the preset is genuinely still in use
  2. Delete it, or update its designated version if it must stay

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Stale File fix difficulty: easy #

Review files with no recent activity and delete if no longer needed

  1. Open Settings → Files in the OpenRouter dashboard
  2. Confirm the file is genuinely still in use
  3. Delete it if it is no longer needed

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Oversized File fix difficulty: easy #

Review large uploaded files for necessity

  1. Open Settings → Files in the OpenRouter dashboard
  2. Confirm the file's size is expected and still required
  3. Delete it if it is no longer needed

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Excessive Model Diversity fix difficulty: medium #

Review why the organization used more than 50 distinct models in 30 days

  1. Review Activity in the OpenRouter dashboard to see which models were used
  2. Restrict routing to an approved model set via workspace defaults or guardrails

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More OpenRouter AI checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial