OpenAI compatible API · Attested · Public status

Subprocessors

Platform vendors and downstream model providers used by TrustedRouter.

Verify gateway
Onebase URL to migrate
100sof models and routes
Noneprompt logs by default
Platform vendors9 listed.
Model providers41 listed.
Prompt accessOnly selected downstream model routes receive prompt content.
JSONMachine readable list.
Routing matters

Downstream model providers are subprocessors only when customer traffic is routed to them. For legal work, use trustedrouter/zdr, trustedrouter/e2e, or a customer-approved provider allowlist.

Platform subprocessors

Vendors used to operate TrustedRouter.

NamePurposeData accessPolicy
Google Cloud Platform Cloud hosting, Confidential Space, Cloud Run, Spanner, Bigtable, KMS, Secret Manager, and operational infrastructure. Prompt traffic on the production API terminates inside the attested gateway. GCP services store metadata, billing records, secrets, and operational logs as configured; prompt/output content is not stored by default. Policy
Cloudflare DNS, public-site caching, status/trust hosting support, and edge protection for non-prompt surfaces. Public website traffic and DNS metadata. Production prompt TLS is designed to terminate inside the attested gateway, not inside the control-plane site. Policy
Stripe Card payments, stablecoin checkout, customer records, saved payment methods, invoices, and billing webhooks. Billing identity and payment metadata. No prompt/output content. Policy
PayPal Optional PayPal payment processing for prepaid credits. Billing identity and payment metadata. No prompt/output content. Policy
Amazon Web Services SES/SNS Transactional email delivery, bounce handling, complaint handling, and email-domain verification. Email address and transactional email metadata. No prompt/output content. Policy
Sentry Control-plane exception monitoring. Scrubbed control-plane errors and metadata. Sentry is not configured in the attested prompt gateway and must not receive prompts, outputs, API keys, or BYOK secrets. Policy
Axiom Operational log search and alerting. Structured operational metadata. Prompt/output content must not be logged. Policy
Exa Optional hosted web search for Responses API requests that explicitly enable the web_search tool. A model-generated search query, requested domain and country filters, and search metadata. Search runs only inside the attested gateway. Exa does not receive the original prompt or model output directly, but a generated query can reflect prompt content. Web search is blocked on ZDR, E2E/confidential, and EU privacy routes until a compatible contractual posture is approved. Policy
GitHub Source control, CI, release workflows, and public open-source repositories. Source code, CI metadata, and release artifacts. No production prompt/output content. Policy
Model provider subprocessors

Downstream model compute providers.

Unknown means no tracked public or contracted claim is currently published in the TrustedRouter catalog.

Provider ZDR Confidential compute Provider E2EE Purpose Policy source
Tinfoil
tinfoil
yes yes yes Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Tracked as a confidential inference provider with attested provider compute and no prompt/output logging claims.
Policy source
Venice
venice
yes yes yes Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Tracked as confidential — Venice documents no logging or storage of prompts/responses plus TEE-isolated, end-to-end-encrypted inference. (Caveat: requests Venice proxies to external frontier models inherit those providers' policies; TR routes Venice-native open models here.)
Policy source
Meta via OpenRouter
meta
no no no Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
TrustedRouter sends requests through its attested gateway to OpenRouter, which routes them to Meta. This downstream route is not marked zero-retention, confidential-compute, or end-to-end encrypted.
Policy source
Anthropic
anthropic
no unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Not currently marked ZDR in TrustedRouter. Anthropic may offer contracted or account-specific data-retention terms, but this provider is excluded from trustedrouter/zdr until that posture is reverified.
Policy source
OpenAI
openai
scheduled 2026-07-28 unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Contracted Zero Data Retention is scheduled to begin for TrustedRouter's managed OpenAI account on July 28, 2026. OpenAI remains outside trustedrouter/zdr until live activation verification passes. Once verified, the guarantee will apply only to TrustedRouter-funded prepaid routes; customer BYOK credentials use the data controls on the customer's own OpenAI organization or project.
Policy source
Google AI Studio
google-ai-studio
no unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Not currently marked ZDR in TrustedRouter. Google AI Studio and the Gemini Developer API have product- and billing-specific data-use terms, so this route stays outside trustedrouter/zdr.
Policy source
Google Vertex AI
google-vertex
no unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Not currently marked ZDR in TrustedRouter. Vertex AI documents a separate zero-data-retention configuration process, but this managed route stays outside trustedrouter/zdr until its live account settings are verified.
Policy source
Cerebras
cerebras
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Tracked as provider-ZDR. Cerebras documents zero-retention inference and ZDR-compliant ephemeral prompt caching that is never persisted.
Policy source
DeepSeek
deepseek
no unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Not ZDR. DeepSeek's published privacy policy says prompts/inputs may be collected and personal data may be used to train or improve machine learning models and algorithms.
Policy source
Mistral
mistral
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. This is separate from any no-training or enterprise retention commitments Mistral may offer.
Policy source
Kimi
kimi
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Kimi/Moonshot policy source is linked for users who need to review API retention and processing terms.
Policy source
Z.AI
zai
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Z.AI/BigModel policy source is linked for users who need to review API retention and processing terms.
Policy source
Together
together
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Tracked as provider ZDR. Together documents that inference inputs and outputs are not stored by default; temporary prompt caching may be used for performance, and sharing content for training is opt-in.
Policy source
Fireworks AI
fireworks
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Fireworks publishes security, privacy, and zero-retention documentation; enable a contracted ZDR posture before marking this provider as ZDR.
Policy source
xAI Grok
grok
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
xAI documents no training on API requests and 30-day default audit retention, with ZDR as an enterprise feature.
Policy source
Novita AI
novita
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Novita's privacy policy says personal information is not used for model training; customer-content processing is governed by customer agreements.
Policy source
Phala
phala
yes yes yes Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Tracked as a confidential AI provider with provider-side attestation and encrypted prompt transport.
Policy source
SiliconFlow
siliconflow
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. SiliconFlow's privacy policy source is linked for retention and interaction-data terms.
Policy source
Parasail
parasail
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Tracked as ZDR for serverless and dedicated inference. Parasail documents no storage or logging of submitted input on those service paths, retention only while generating and delivering output, and no training on input or output. Batch service is excluded from this claim; TrustedRouter does not route Parasail traffic through batch.
Policy source
Lightning AI
lightning
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Lightning's general privacy and security documentation is linked for retention review.
Policy source
GMI Cloud
gmi
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
GMI runs isolated/VPC GPU inference, but that is network isolation, NOT an attested TEE — so no confidential-compute, zero-retention, or E2EE claim is marked. Retention/training terms are unverified (the published policy page is JavaScript-only and would not render).
Policy source
FriendliAI
friendli
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Friendli's legal/privacy terms are linked for users who need to review API data handling.
Policy source
Baseten
baseten
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Baseten's inference and security documentation are linked for users who need to review API data handling.
Policy source
Wafer
wafer
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Wafer supports request-scoped ZDR via Wafer-ZDR: required on supported models; model-level support differs, so TrustedRouter keeps provider-level claims conservative.
Policy source
Crusoe
crusoe
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Crusoe's Managed Inference docs and pricing/catalog pages are linked for model and API data-handling review.
Policy source
Makora
makora
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Makora's inference and privacy documentation are linked for users who need to review API data handling.
Policy source
Chutes
chutes
yes yes no Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Chutes documents no prompt/output storage or training and serves these routes in confidential-compute TEEs. Standard API calls are not marked provider end-to-end encrypted.
Policy source
DigitalOcean Gradient AI
digitalocean
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. DigitalOcean's Gradient AI model and pricing documentation is linked for data-handling review.
Policy source
Cloudflare Workers AI
cloudflare-workers-ai
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Cloudflare's Workers AI documentation is linked for model and data-handling review.
Policy source
Inceptron
inceptron
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Inceptron documents zero retention by default: API prompts and outputs are processed transiently and discarded after processing.
Policy source
Morph
morph
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Morph's public paid tier documents up to 30 days of content retention. Zero retention is reserved for enterprise contracts.
Policy source
Atlas Cloud
atlas-cloud
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Atlas Cloud publishes a platform zero-retention policy, while its aggregated model routes can involve downstream providers. TrustedRouter keeps the public route tier conservative pending downstream-path contractual verification.
Policy source
StreamLake
streamlake
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked. StreamLake's public privacy policy is linked for API data-handling review.
Policy source
DeepInfra
deepinfra
no unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Tracked as no-store, not strict ZDR. DeepInfra documents memory-only handling and no training for ordinary inference, but reserves the right to log a small portion of requests for debugging or security. Google- and Anthropic-backed routes also inherit those vendors' terms.
Policy source
Nebius Token Factory
nebius
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Marked ZDR via TrustedRouter's arrangement — Nebius RETAINS inputs/outputs by default (for speculative decoding); zero retention is an opt-in control, which the deployed Nebius account has enabled. Nebius does not train on customer data.
Policy source
MiniMax
minimax
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. MiniMax's product privacy overview is linked for users who need to review API/open-platform terms.
Policy source
Thinking Machines Lab
thinkingmachines
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Thinking Machines Lab's model and pricing documentation is linked for model capability and API review.
Policy source
Xiaomi MiMo
xiaomi
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Xiaomi MiMo's open-platform terms are linked for users who need to review API data handling.
Policy source
Alibaba Cloud Model Studio
alibaba
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Alibaba Cloud Model Studio model availability and pricing are linked for users who need to review API data handling and regional deployment scope.
Policy source
Cohere
cohere
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Marked ZDR — Cohere does not retain prompt/response content for TrustedRouter's configured account and does not train on customer API data. (Not a confidential-compute/TEE provider.)
Policy source
Voyage AI
voyage
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Marked ZDR — Voyage AI does not retain prompt content for TrustedRouter's configured account and does not train on customer API data. (Not a confidential-compute/TEE provider.)
Policy source
Workspace access

Sign in

Choose a sign in method. New email and OAuth accounts include $0.10 in starter credit; wallet-only accounts start at $0.

By signing in you agree to the terms of service and privacy policy.