# Azure Service Mesh vs Tetrate Service Bridge

| Attribute | Azure Service Mesh | Tetrate Service Bridge |
|---|---|---|
| **Vioscale score** | 46.9 (4% (low)) | 52.7 (33% (low)) |
| deployment.options | `{"cloud":true,"self_hosted":true}` | `{"cloud":true,"hybrid":true,"on_prem":true,"self_hosted":true}` |
| description.long | Istio-based service mesh add-on for Azure Kubernetes Service (AKS) that provides observability, traffic management, and security capabilities for distributed microservices architectures. | An enterprise AI gateway platform based on Envoy that manages language model access, cost control, and AI agent governance. Provides unified LLM catalog, automatic model fallback, token brokering, AI guardrails, and MCP gateway capabilities. |
| features.capabilities | `{"proxy":"envoy","data_plane":"sidecar","vm_support":true,"cncf_maturity":"graduated"}` | `{"proxy":"envoy","fips_mode":true,"vm_support":true,"multicluster":true,"automatic_mtls":true,"commercial_support":true,"gateway_api_support":true,"built_in_observability":true}` |
| integrations.count | - | 12 |
| integrations.list | - | `[{"name":"AWS"},{"name":"AWS CloudMap"},{"name":"AWS AppMesh"},{"name":"Amazon EKS Distro"},{"name":"Amazon ECS Anywhere"},{"name":"Amazon EKS Anywhere"},{"name":"Istio"},{"name":"Envoy"},{"name":"Kubernetes Gateway API"},{"name":"NGINX"},{"name":"LDAP"},{"name":"SSO"}]` |
| platform.support | - | `{"linux":true}` |
| pricing | `{"type":"open_source","sourceUrl":"https://learn.microsoft.com/en-us/azure/aks/istio-about","retrievedAt":"2026-08-14T08:36:53.281Z"}` | `{"type":"quote","plans":[{"free":false,"name":"Agent Router Service","contactSales":true},{"free":false,"name":"Agent Router Enterprise","contactSales":true}],"summary":"Contact sales for pricing","freeTier":false,"sourceUrl":"https://tetrate.io/tetrate-service-bridge/","retrievedAt":"2026-08-03T13:02:27.685Z"}` |
| pricing.free_tier | - | no |
| pricing.model | open_source | commercial |
| pricing.price_level | free | unknown |
| pricing.transparent | - | no |
| reliability.status_page | yes | - |
| security.fedramp | - | yes |
| security.gdpr | - | yes |
| security.hipaa | - | yes |
| security.iso27001 | - | yes |
| security.soc2 | - | yes |

## Capabilities (Service Mesh)

| Capability | Azure Service Mesh | Tetrate Service Bridge |
|---|:--:|:--:|
| **Architecture** |  |  |
| Data plane | Sidecar | - |
| Proxy | Envoy | Envoy |
| **Security** |  |  |
| Automatic mutual TLS | - | ✓ |
| SPIFFE / SPIRE identity | - | - |
| **Traffic** |  |  |
| Traffic splitting / canary | - | - |
| Fault injection / resilience | - | - |
| **Scale** |  |  |
| Multi-cluster federation | - | ✓ |
| **Portability** |  |  |
| VM support (beyond Kubernetes) | ✓ | ✓ |
| **Observability** |  |  |
| Built-in observability | - | ✓ |
| **Standards** |  |  |
| Gateway API / GAMMA support | - | ✓ |
| **Extensibility** |  |  |
| WASM extensibility | - | - |
| **Compliance** |  |  |
| FIPS mode | - | ✓ |
| **Ecosystem** |  |  |
| CNCF maturity | Graduated | - |
| **Ops** |  |  |
| Commercial support / enterprise edition | - | ✓ |

*Source: Vioscale. Generated 2026-09-01T17:42:08.969Z. "-" = undocumented, not absent.*
