OpenAI compatible API · Attested · Public status

Subprocessors

Platform vendors and downstream model providers used by TrustedRouter.

Verify gateway
Onebase URL to migrate
100sof models and routes
0prompt or output logs. Always.
Platform vendors9 listed.
Model providers43 listed.
Prompt accessOnly selected downstream model routes receive prompt content.
JSONMachine readable list.
Routing matters

Downstream model providers are subprocessors only when customer traffic is routed to them. For legal work, use trustedrouter/zdr, trustedrouter/e2e, or a customer-approved provider allowlist.

Platform subprocessors

Vendors used to operate TrustedRouter.

NamePurposeData accessPolicy
Google Cloud Platform Cloud hosting, Confidential Space, Cloud Run, Spanner, Bigtable, KMS, Secret Manager, and operational infrastructure. Prompt traffic on the production API terminates inside the attested gateway. GCP services store metadata, billing records, secrets, and operational logs as configured; TrustedRouter never logs or stores prompt/output content. Policy
Cloudflare DNS, public-site caching, status/trust hosting support, and edge protection for non-prompt surfaces. Public website traffic and DNS metadata. Production prompt TLS is designed to terminate inside the attested gateway, not inside the control-plane site. Policy
Stripe Card payments, stablecoin checkout, customer records, saved payment methods, invoices, and billing webhooks. Billing identity and payment metadata. No prompt/output content. Policy
PayPal Optional PayPal payment processing for prepaid credits. Billing identity and payment metadata. No prompt/output content. Policy
Amazon Web Services SES/SNS Transactional email delivery, bounce handling, complaint handling, and email-domain verification. Email address and transactional email metadata. No prompt/output content. Policy
Sentry Control-plane exception monitoring. Scrubbed control-plane errors and metadata. Sentry is not configured in the attested prompt gateway and must not receive prompts, outputs, API keys, or BYOK secrets. Policy
Axiom Operational log search and alerting. Structured operational metadata. Prompt/output content must not be logged. Policy
Exa Optional hosted web search for Responses API requests that explicitly enable the web_search tool. A model-generated search query, requested domain and country filters, and search metadata. Search runs only inside the attested gateway. Exa does not receive the original prompt or model output directly, but a generated query can reflect prompt content. Web search is blocked on ZDR, E2E/confidential, and EU privacy routes until a compatible contractual posture is approved. Policy
GitHub Source control, CI, release workflows, and public open-source repositories. Source code, CI metadata, and release artifacts. No production prompt/output content. Policy
Model provider subprocessors

Downstream model compute providers.

Unknown means no tracked public or contracted claim is currently published in the TrustedRouter catalog.

Provider ZDR Confidential compute Provider E2EE Purpose Policy source
Tinfoil
tinfoil
yes yes yes Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Tracked as a confidential inference provider with attested provider compute and no prompt/output logging claims.
Policy source
Meta via OpenRouter
meta
no no no Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
TrustedRouter sends requests through its attested gateway to OpenRouter, which routes them to Meta. This downstream route is not marked zero-retention, confidential-compute, or end-to-end encrypted.
Policy source
Anthropic
anthropic
no unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Not currently marked ZDR in TrustedRouter. Anthropic may offer contracted or account-specific data-retention terms, but this provider is excluded from trustedrouter/zdr until that posture is reverified.
Policy source
OpenAI
openai
prepaid only unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Contracted Zero Data Retention is active for TrustedRouter's managed OpenAI account, effective July 28, 2026, and live enforcement was verified on July 29, 2026. This guarantee applies only to TrustedRouter-funded prepaid routes; customer BYOK credentials use the data controls on the customer's own OpenAI organization or project.
Policy source
Google AI Studio
google-ai-studio
no unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Not currently marked ZDR in TrustedRouter. Google AI Studio and the Gemini Developer API have product- and billing-specific data-use terms, so this route stays outside trustedrouter/zdr.
Policy source
Google Vertex AI
google-vertex
prepaid only unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
TrustedRouter's managed Vertex AI account is covered by contractual Zero Data Retention. This guarantee applies only to TrustedRouter-funded prepaid routes. TrustedRouter does not invoke Google Search or Maps grounding or Gemini Live session resumption on these routes. Google AI Studio is classified separately.
Policy source
Cerebras
cerebras
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Tracked as provider-ZDR. Cerebras documents zero-retention inference and ZDR-compliant ephemeral prompt caching that is never persisted.
Policy source
DeepSeek
deepseek
no unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Not ZDR. DeepSeek's published privacy policy says prompts/inputs may be collected and personal data may be used to train or improve machine learning models and algorithms.
Policy source
Mistral
mistral
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. This is separate from any no-training or enterprise retention commitments Mistral may offer.
Policy source
Kimi
kimi
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Kimi/Moonshot policy source is linked for users who need to review API retention and processing terms.
Policy source
Z.AI
zai
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Z.AI/BigModel policy source is linked for users who need to review API retention and processing terms.
Policy source
Together
together
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Tracked as provider ZDR. Together documents that inference inputs and outputs are not stored by default; temporary prompt caching may be used for performance, and sharing content for training is opt-in.
Policy source
Fireworks AI
fireworks
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Fireworks publishes security, privacy, and zero-retention documentation; enable a contracted ZDR posture before marking this provider as ZDR.
Policy source
xAI Grok
grok
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
xAI documents no training on API requests and 30-day default audit retention, with ZDR as an enterprise feature.
Policy source
Novita AI
novita
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Novita's privacy policy says personal information is not used for model training; customer-content processing is governed by customer agreements.
Policy source
Phala
phala
yes yes no Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Phala publishes TDX/GPU attestation and signed request receipts, but TrustedRouter does not yet verify the complete receipt chain on every routed request. The route is therefore not classified as provider E2EE and is excluded from trustedrouter/e2e.
Policy source
SiliconFlow
siliconflow
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. SiliconFlow's privacy policy source is linked for retention and interaction-data terms.
Policy source
Venice
venice
no no no Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Mixed model-specific posture. TrustedRouter cannot independently verify a complete chain from a live Venice endpoint through immutable source and hardware measurements to committed model weights. Venice is therefore not tracked as confidential or E2EE. Exact routes marked Private in Venice's live catalog qualify only as policy-backed ZDR through endpoint-specific records; Anonymized routes do not.
Policy source
Parasail
parasail
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Tracked as ZDR for serverless and dedicated inference. Parasail documents no storage or logging of submitted input on those service paths, retention only while generating and delivering output, and no training on input or output. Batch service is excluded from this claim; TrustedRouter does not route Parasail traffic through batch.
Policy source
Lightning AI
lightning
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Lightning's general privacy and security documentation is linked for retention review.
Policy source
GMI Cloud
gmi
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
GMI runs isolated/VPC GPU inference, but that is network isolation, NOT an attested TEE — so no confidential-compute, zero-retention, or E2EE claim is marked. Retention/training terms are unverified (the published policy page is JavaScript-only and would not render).
Policy source
FriendliAI
friendli
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Friendli's legal/privacy terms are linked for users who need to review API data handling.
Policy source
Baseten
baseten
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Baseten's inference and security documentation are linked for users who need to review API data handling.
Policy source
Telnyx
telnyx
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR or confidential-compute claim is tracked here. Telnyx's privacy policy is linked for users who need to review inference data handling.
Policy source
Wafer
wafer
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Wafer supports request-scoped ZDR via Wafer-ZDR: required on supported models; model-level support differs, so TrustedRouter keeps provider-level claims conservative.
Policy source
Crusoe
crusoe
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Crusoe's Managed Inference docs and pricing/catalog pages are linked for model and API data-handling review.
Policy source
Makora
makora
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Makora's inference and privacy documentation are linked for users who need to review API data handling.
Policy source
Chutes
chutes
yes yes no Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Chutes documents no prompt/output storage or training and serves these routes in confidential-compute TEEs. Standard API calls are not marked provider end-to-end encrypted.
Policy source
DigitalOcean Gradient AI
digitalocean
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. DigitalOcean's Gradient AI model and pricing documentation is linked for data-handling review.
Policy source
Cloudflare Workers AI
cloudflare-workers-ai
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Cloudflare's Workers AI documentation is linked for model and data-handling review.
Policy source
Inceptron
inceptron
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Inceptron documents zero retention by default: API prompts and outputs are processed transiently and discarded after processing.
Policy source
Morph
morph
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Morph's public paid tier documents up to 30 days of content retention. Zero retention is reserved for enterprise contracts.
Policy source
Atlas Cloud
atlas-cloud
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Atlas Cloud publishes a platform zero-retention policy, while its aggregated model routes can involve downstream providers. TrustedRouter keeps the public route tier conservative pending downstream-path contractual verification.
Policy source
StreamLake
streamlake
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked. StreamLake's public privacy policy is linked for API data-handling review.
Policy source
Neurometric AI
neurometric
no no no Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Neurometric states that TrustedRouter requests run with upstream trace logging disabled: prompts and completions are not written to observability or object storage, and only aggregate request counts and token totals are retained. This is classified as no-store, not contractual ZDR or confidential compute.
Policy source
DeepInfra
deepinfra
no unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Tracked as no-store, not strict ZDR. DeepInfra documents memory-only handling and no training for ordinary inference, but reserves the right to log a small portion of requests for debugging or security. Google- and Anthropic-backed routes also inherit those vendors' terms.
Policy source
Nebius Token Factory
nebius
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Marked ZDR via TrustedRouter's arrangement — Nebius RETAINS inputs/outputs by default (for speculative decoding); zero retention is an opt-in control, which the deployed Nebius account has enabled. Nebius does not train on customer data.
Policy source
MiniMax
minimax
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. MiniMax's product privacy overview is linked for users who need to review API/open-platform terms.
Policy source
Thinking Machines Lab
thinkingmachines
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Thinking Machines Lab's model and pricing documentation is linked for model capability and API review.
Policy source
Xiaomi MiMo
xiaomi
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Xiaomi MiMo's open-platform terms are linked for users who need to review API data handling.
Policy source
Alibaba Cloud Model Studio
alibaba
unknown unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
No provider-ZDR claim is tracked here. Alibaba Cloud Model Studio model availability and pricing are linked for users who need to review API data handling and regional deployment scope.
Policy source
Cohere
cohere
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Marked ZDR — Cohere does not retain prompt/response content for TrustedRouter's configured account and does not train on customer API data. (Not a confidential-compute/TEE provider.)
Policy source
Voyage AI
voyage
yes unknown unknown Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.
Marked ZDR — Voyage AI does not retain prompt content for TrustedRouter's configured account and does not train on customer API data. (Not a confidential-compute/TEE provider.)
Policy source
Workspace access

Sign in

Choose a sign in method. New email and OAuth accounts include $0.10 in starter credit; wallet-only accounts start at $0.

By signing in you agree to the terms of service and privacy policy.