Case Study
How Wix scaled Al-native work to 5,000 employees with Willow
Read More
Last updated: April 2026
vs

Willow vs. TrueFoundry: which AI each one can see

TrueFoundry is an enterprise AI gateway. It governs the AI traffic that goes through it, and it does that well. Willow governs that traffic too, plus the AI running on laptops and in browsers that never reaches a gateway. Which one you need depends on how much of your AI is pointed at a gateway in the first place.

TrueFoundry is the better fit when
You need HIPAA or ISO 27001 today, you want a Trust Center to audit before you buy, you need to enforce spend, you want guardrails that run before and after every tool call, or you are running the model layer yourself with serving, fine-tuning and GPU orchestration.
Willow is the better fit when
You want a gateway for MCP and tool traffic and cover for the AI that never reaches one: MCP servers set up on developer machines, skill files nobody registered, OAuth grants approved in a browser, access still live after someone leaves. Or when the people who need governed AI sit in HR, legal, finance and marketing.
How much of your AI reaches a gateway
TrueFoundry governs the AI that is pointed at its gateway, and governs it well. Willow runs a gateway for MCP and tool traffic, and also covers the AI that reaches no gateway at all. TrueFoundry additionally governs model calls, which Willow does not. The more of your AI that runs outside a gateway, the more the answer is Willow.
AT A GLANCE

What each product is, and who runs it

They cover different AI, and different people run them.

Willow and TrueFoundry cover different AI, and are run by different people.
Willow TrueFoundry
What it is A gateway for MCP and tool traffic, plus an access and enablement control plane for AI across the organization An enterprise AI gateway and agentic deployment platform, with model serving and fine-tuning alongside it
Who operates it IT and security, with employees self-serving inside the guardrails they set Platform engineering teams, on Kubernetes
What it governs Agents, MCPs, skills, plugins and AI-built apps across the company, whether or not they go through a gateway Traffic that reaches the AI Gateway, MCP Gateway or Agent Gateway, plus the models and workloads deployed on the platform
Where it runs SaaS, private cloud, hybrid, on-premises, air-gapped, EU hosting SaaS, with VPC, on-premises and air-gapped on the Enterprise tier
Compliance SOC 2 Type II attestation, GDPR compliant SOC 2 Type II, HIPAA, GDPR, and ISO 27001 for managed infrastructure

Willow admin console

A gateway for MCP and tool traffic, and a control plane for the AI that never reaches one. Curated catalog with per-server risk scoring, employee self-service, machine users, per-agent and per-action policy, endpoint discovery of unmanaged MCP servers and skills, and IT-run identity and lifecycle. SaaS, private cloud, hybrid, on-premises, air-gapped, EU hosting. SOC 2 Type II and GDPR.

TrueFoundry MCP registry

MCP servers are registered into environment groups, each with an owner. Everything registered here is governed: guardrails before and after model and tool calls, budget and rate enforcement, cost attribution, and full request tracing. Model serving, fine-tuning and GPU orchestration sit alongside it. Kubernetes-native on every deployment option, and anything not registered is outside its view.
TRUEFOUNDRY'S STRENGTHS

Where TrueFoundry is the right choice

If any of these is the deciding factor, they are the better fit and we would rather you knew now.

TRUEFOUNDRY'S STRENGTHS

You need HIPAA, or you need ISO 27001

Their Trust Center lists SOC 2 Type II, HIPAA and GDPR, and offers a SOC 2 report and a HIPAA incident-response addendum. They also list ISO 27001 for managed infrastructure. Willow holds SOC 2 Type II and GDPR, and does not hold HIPAA. If a regulator or a procurement checklist requires either certificate today, that is a real reason to choose them.
TRUEFOUNDRY'S STRENGTHS

You want to audit the vendor before you buy

They run a Trust Center listing their certifications, with a SOC 2 Type II report, two penetration test reports and a full policy packet. Willow does not have one today, and our SOC 2 documentation is available on request. If your process starts at a vendor security portal, they will get through it faster than we will.
TRUEFOUNDRY'S STRENGTHS

You need to enforce spend

They include budget limiting and rate limiting, cost attribution per team, user, model and application, and a budget inspector that simulates which rules apply. Willow gives you token usage visibility. Willow does not enforce budget caps, does not stop traffic at a spend threshold, and does not break cost down per MCP. If runaway AI spend is the problem, they solve it and we report on it.
TRUEFOUNDRY'S STRENGTHS

You need deep runtime guardrails

They run a Trust Center listing their certifications, with a SOC 2 Type II report, two penetration tGuardrails run before and after the model call and before and after every MCP tool call, with named execution modes and failure strategies, plus integrations with Palo Alto Prisma AIRS, CrowdStrike and Bedrock Guardrails. Willow applies guards at the gateway and, through the Chrome extension, in the browser before a request leaves the machine. TrueFoundry's coverage is deeper. If runtime threat detection is what you are buying, choose them.est reports and a full policy packet. Willow does not have one today, and our SOC 2 documentation is available on request. If your process starts at a vendor security portal, they will get through it faster than we will.
TRUEFOUNDRY'S STRENGTHS

You want tracing across the model call itself

They record which agent made each call and which user it acted for, keep the full payload, and keep blocked requests as evidence. Willow logs tool calls, guard verdicts and identity events and forwards them to Splunk, Grafana Loki, Coralogix, CrowdStrike, Panther, S3 or a webhook. TrueFoundry claims immutable audit logging and describes hash-chained, append-only storage. Willow's logs are append-only and we do not claim immutability. Ask both of us how tamper evidence is actually produced, and for which deployment.
TRUEFOUNDRY'S STRENGTHS

You are running the model layer too

Model serving, fine-tuning, GPU orchestration, routing, failover and semantic caching are their core business, and following their acquisition of Seldon AI they describe Seldon as the production-grade MLOps foundation underneath that. Willow does none of this. If you want one vendor for models and governance, that is them. Rate limiting starts at their Pro tier. Willow does not offer MCP rate limiting.
WILLOW'S STRENGTHS

Where Willow is the right choice

Willow runs a gateway too. What follows is what it does beyond one.

01

Finding and blocking the AI that never reaches a gateway

A gateway sees what is pointed at it. Anything a developer wires up directly stays invisible to it. TrueFoundry's shadow-AI product, AITori, is built that way deliberately: it watches gateway traffic rather than the machine.

What Willow does

  • A scan agent runs on macOS and Windows, deployed through Jamf, Intune, Group Policy, JumpCloud, Mosyle or Iru, or through a webhook if you already collect device scan data another way.
  • It finds MCP servers configured in Cursor, Claude Desktop, VS Code and Windsurf, Claude Code skill files, Cursor rules, and the AI coding tools installed on each machine.
  • Every discovered MCP server and skill gets a 0 to 10 risk score with a band. For managed servers the score breaks into authentication, tools weighted so write and delete count for more than read, and the guards constraining the server.
  • Policy rules allow, warn on, or block what it finds, scoped to users, groups or devices. Rules enforce once published, and servers already proxied through your gateway are always allowed.
  • Willow for Chrome covers Claude in Chrome today, and no other browser or AI. Within that scope it pauses the agent before it acts, gating send, submit, post, pay, delete, share, publish and upload by intercepting outbound requests and showing a human the full payload before anything leaves.

What TrueFoundry does

  • AITori detects coding agent traffic from Claude Code, Cursor, Copilot and Codex, which only works once those tools are already routing through the gateway.
  • It reads nothing on the machine. An MCP server a developer configures locally stays invisible to it.
  • It covers coding agents. It does not cover the AI the rest of the company uses.
  • It is offered as early access.
Bottom line
A gateway can only govern traffic configured to go through it, and TrueFoundry governs that traffic thoroughly. Plenty of AI never gets configured that way. A developer who connects an MCP server straight to a production database creates a connection every gateway is blind to.
TrueFoundry needs the tool pointed at its gateway. Willow needs nothing pointed anywhere, because it reads the machine.
Use TrueFoundry if every AI tool in your company already routes through a gateway. Use Willow if you cannot promise that.
02

What happens when an employee leaves

What happens to an employee's agent and MCP access on the day they leave.

What Willow does

  • Extend your identity provider to every agent, MCP, tool and AI-built app, approve the catalog once, and let employees self-serve.
  • Sign-on works with eight identity providers: Okta, Azure AD, Google Workspace, Auth0, GitHub, Keycloak, JumpCloud and ADFS.
  • Automatic deprovisioning runs on SCIM, and SCIM is supported for Okta and JumpCloud only. On the other six providers, sign-on is federated but access removal is not automatic. Ask us where your provider sits before you rely on this. SCIM activity is written to its own log you can filter and export as evidence.

What TrueFoundry does

  • Revoking access means an administrator removing an agent's grants or deleting the agent outright.
  • That works on the day somebody remembers to do it.
  • There is no way to suspend an agent and keep its registration and history.
Bottom line

When someone leaves, every agent, MCP connection and OAuth token they set up stays live until something removes it. Both products revoke the access they broker. Neither revokes a token a user pasted in themselves, or an OAuth grant they approved directly. What separates them is whether the brokered part closes automatically or because a person remembered.

TrueFoundry needs an administrator to remove each agent by hand. Willow needs nobody for the access it brokers, because that closes when your identity provider closes the account.

Use TrueFoundry if you have a leaver checklist somebody owns and audits. Use Willow if you would rather not depend on one.

03

Who can operate each product

Most AI use in a company happens outside engineering. The people doing it have to be able to use the controls.

What Willow does

  • Employees connect governed tools through a self-service panel and combine them into reusable skills, pre-permissioned by identity, role and policy.
  • Approvals route through Slack.
  • At Wix this reached most of the company rather than only engineering. The figures are below.

What TrueFoundry does

  • Platform teams configure MCP servers and policies once, and agent builders pick servers from a governed catalog.
  • Governance is expressed in configuration files, API calls and admin consoles, which only works if the person who needs it can use them.
  • It is built for platform engineers and tenant administrators. Everyone else files a ticket.
Bottom line

Governance covers only the part of the company that can use it. At Wix, Willow reached roughly 5,000 weekly users across HR, legal, finance, design and R&D, most of whom would never open a console.

TrueFoundry needs a platform engineer to operate it. Willow needs IT to approve the catalog once, then employees serve themselves.

Use TrueFoundry if AI in your company stays inside engineering. Use Willow if finance, legal, HR and marketing are already using it.

04

Where each one runs, and whether the certification follows

Where each runs, and whether each vendor's certifications still cover you when you host it yourself.

What Willow does

  • Willow SaaS has nothing to install, no Kubernetes cluster to provision and no database to maintain, and it is covered by Willow's SOC 2 Type II.
  • Private cloud, hybrid and on-premises are available, and EU hosting runs on European servers with nothing to reconfigure.
  • If you self-host, you run Kubernetes too: on-premises deploys the whole platform into your own cluster through a Helm chart.

What TrueFoundry does

  • Kubernetes-native on every option, which only works if you have a team who can run and maintain a cluster. They describe the trade as higher operational complexity for deeper governance and data sovereignty.
  • VPC, on-premises and air-gapped sit on the Enterprise tier, as Willow's do.
  • Their certifications cover managed infrastructure. Self-host, and compliance is yours to establish.
Bottom line

Both offer SaaS, private cloud, on-premises and air-gapped, and both put the advanced options on their enterprise plan. Deployment itself is a draw and it is not a reason to choose between us.

TrueFoundry needs a team who can run a Kubernetes cluster, on every deployment option, and its certifications cover managed infrastructure only. Willow needs no cluster for SaaS, and one only if you self-host.

Use TrueFoundry if you already run Kubernetes and want the model layer with it. Use Willow if you want governance running without standing up infrastructure first. Whichever you shortlist, get the certification scope for your deployment confirmed in writing.

PROOF

What governed AI looks like across a whole company

Wix needed a governed way to connect employees and agents to internal tools, documentation and workflows. The AI Core team built that on Willow, and it now runs across engineering, product, design, HR, finance, legal and business teams.

~5,000

weekly active users, more than the entire Wix engineering organization

~600

governed tools and MCP servers, spanning HR, legal, finance, design and R&D

300K+

governed tool calls every week

THE BOUNDARY

What each product covers

Willow covers both of these. TrueFoundry covers the first one, and covers more of it than Willow does.

BOTH PRODUCTS

AI that goes through a gateway: both products govern it

Willow and TrueFoundry both run a gateway for MCP and tool traffic, with identity, RBAC, guards, approvals and audit logs on every call. TrueFoundry adds model calls, routing, failover and cost enforcement on that traffic, which Willow does not do.
WILLOW ONLY

AI that never reaches a gateway: only Willow governs it

An MCP a developer configured locally and never registered. A skill file on a laptop. An OAuth grant an employee approved in a browser. An AI-built app connected with a personal key. The agents, tools and connections still live after someone has left. None of this routes through a gateway, so a gateway cannot govern it. Some of it is visible elsewhere, in your identity provider or your endpoint tooling, in pieces. Willow puts it in one inventory, scores it, and can act on it.
DECIDE

Which one fits your company

Five checks you can run yourself.

Ask a developer to open their MCP client config. Count the servers IT has never approved.
Search your identity provider for OAuth grants to AI tools nobody filed a ticket for.
Pick three people who left last quarter. Confirm whether their agent and MCP connections are actually closed.
Count how many people outside engineering use AI on work data, and how many could name your approved tool list.
Check whether your AI spend is attributable to a team, and whether anything stops it.

Mostly the first four: your risk sits outside the gateway. Choose Willow.

Mostly the last one, or you run your own models: your risk sits inside the gateway. Choose TrueFoundry.

Both: run TrueFoundry for model traffic and Willow for everything else, and expect to reconcile two sets of policy and two audit trails.

Cloudflare approach

Portals run on Cloudflare's global network as part of Cloudflare One.
Portals run on Cloudflare's global network as part of Cloudflare One.
The trade is that you inherit a global network, its latency profile, and its resilience.
What each one costs

TrueFoundry: free Developer tier, Pro at $499 a month, Pro Plus at $2,999 a month, Enterprise on request. SSO and audit logs start at Pro Plus. VPC, on-premises and air-gapped are Enterprise only.

Willow: free for up to 5 users, $15 per seat above that, and an enterprise tier. SCIM provisioning and on-premises deployment sit on the enterprise tier.

Both of us gate something. Compare the tier that includes the controls you actually need, and make each vendor tell you which tier that is.

FAQS

Common questions

What is the difference between Willow and TrueFoundry?
TrueFoundry is an AI gateway and deployment platform. It governs the model and tool traffic pointed at it, and runs model serving, fine-tuning and GPU orchestration alongside. Willow runs a gateway for MCP and tool traffic and also covers the AI that never reaches one: MCP servers on developer machines, skill files nobody registered, OAuth grants approved in a browser, and access still live after someone leaves.
Can we run both?
Yes, and some companies do, usually because TrueFoundry is already governing their model traffic. Willow governs MCP and tool traffic through its own gateway and also covers what never routes through one. If you keep TrueFoundry for the model layer, Willow answers the question it cannot: what is installed across the company, who has access, and what is still live after someone leaves.
Does TrueFoundry do shadow AI discovery?
For coding agents, through a product called AITori, which only sees traffic already routing through their gateway and is offered as early access. It does not read the machine, so it misses anything configured locally, and it does not cover cloud platforms or identity providers. Willow's discovery runs on the endpoint through a scan agent and in the browser through an extension, and blocks what it finds once you publish a policy rule.
Do we need Kubernetes to run Willow?
Not for SaaS. Willow SaaS has nothing to install and no cluster to provision. If you self-host, you do: on-premises runs the whole platform in your own Kubernetes cluster through a Helm chart, and hybrid needs a cluster for the runtime component. TrueFoundry is Kubernetes-native across all of its deployment options.
How long does a Willow rollout take?
A fourteen day sequence. Days one to three deploy by Helm to on-premises or hybrid, or start on SaaS with nothing to install. Days four to seven, identity sync with Okta, Azure AD or JumpCloud. Days eight to ten, connect tools. Days eleven to fourteen, endpoint and audit.

Other Willow comparisons

More on how Willow works

Your agents are already in the wild.

Give them a Basecamp. Go from AI chaos to AI work, in minutes.