OpenAI compatible API · Attested · Public status

HIPAA-Compatible LLM Routing — TrustedRouter

An auditable LLM API for HIPAA covered entities. Attested gateway, open-source routing code, no prompt logs by construction.

Verify gateway
Onebase URL to migrate
100sof models and routes
0prompt or output logs. Always.
HIPAA-compatible LLM routing

The LLM API whose privacy posture is verifiable, not just contractual.

HIPAA covered entities and their business associates can't legally route PHI through a service whose data-handling claims they can't audit.

TrustedRouter's prompt path runs inside a hardware-attested gateway. The source is open. The image hash is published. Privacy isn't promised — it's checkable.

Security architecture Try in playground

Verify the gatewaycurl
# Live attestation, bound to a nonce
NONCE=$(openssl rand -hex 16)
curl -s "https://api.trustedrouter.com/attestation?nonce=$NONCE"

# Returns a JWT signed by the CPU's root key.
# image_digest matches the artifact published at
# trustedrouter.com/security — verifiable end to end.
No retention

Real-time prompts and outputs aren't stored.

The attested binary never writes request or response bodies. Token counts and metadata only. The schema is in source.

Verifiable

Read the code that handles PHI.

Every byte that touches a prompt body flows through open-source code you can audit. Your security team doesn't have to take our word.

Multi-provider

Route to providers with strong posture.

Anthropic Claude, GPT-5, Gemini, Llama via Tinfoil, GLM, DeepSeek — pick by published per-provider retention and ZDR status.

What HIPAA buyers actually need

Verifiability beats audit theater.

An auditable prompt path. Open source lets your security team trace exactly what happens to PHI from request entry to provider hand-off. No reverse engineering.

Provider transparency. Each model page publishes the upstream provider's posture — zero-retention contracts, confidential compute, end-to-end encryption claims — with links to source. You route deliberately.

BAA where it matters. Direct BAAs with TR + the upstream provider you select. The attestation gives you what BAAs can't: cryptographic proof of which code processed a specific request.

Fail-closed gateway. If attestation can't verify, the gateway stops accepting requests. There is no degraded mode that processes PHI without proof.

Self-host option. Run the same open-source gateway inside your own VPC. Same image hash, same attestation chain, same verifiability.

Honest scope

What attestation doesn't cover.

Attestation proves the running binary is the published binary. It doesn't prove the binary is bug-free — open-source code can have flaws and we welcome reports.

It doesn't bypass nation-state actors with physical access to the cloud provider. The threat model is "operator can't see PHI" + "code is what was published," not "absolute secrecy from all adversaries."

Upstream providers handle prompts according to their own policies. We publish each one's posture on the model pages so you can route accordingly.

Live catalog evidence

Current routes, prices, privacy, and measured performance.

Catalog facts come from the routes currently configured in TrustedRouter. Performance uses the same cached metadata snapshot as the public leaderboard. Prompts and outputs are not part of these measurements.

554public models
95providers
1761configured routes
314ZDR routes
35provider E2EE routes
5798recent availability samples
Model Providers Context Input Output Privacy Measured route
Anthropic: Claude Opus 4.8anthropic/claude-opus-4.8
3 routes
1,000,000 $5.275/1M $26.375/1M varies 5 cited scores 1538 ms TTFT anthropic · 91 tok/s · 100.00% available · n=3
OpenAI: GPT-5.5openai/gpt-5.5
4 routes
1,050,000 $5.275/1M $31.65/1M ZDR 3 cited scores Warming up
Google: Gemini 3.5 Flashgoogle/gemini-3.5-flash
+1
7 routes
1,048,576 $1.5825/1M $9.495/1M ZDR 1278 ms TTFT google-vertex · 107 tok/s · 100.00% available · n=7
MoonshotAI: Kimi K2.7 Codemoonshotai/kimi-k2.7-code
+10
19 routes
262,144 $0.70685/1M to $1.13096/1M $3.587/1M to $4.90575/1M ZDR 5 cited scores 2262 ms TTFT kimi · 61 tok/s · 100.00% available · n=25
Z.ai: GLM 5.2z-ai/glm-5.2
+24
44 routes
1,048,576 $0.7174/1M to $2.434307/1M $1.5825/1M to $7.029062/1M E2EE 4 cited scores 1806 ms TTFT baseten · 128 tok/s · 100.00% available · n=144
MiniMax: MiniMax M3minimax/minimax-m3
+9
21 routes
524,288 $0.24265/1M to $0.633/1M $1.0128/1M to $2.532/1M ZDR 4 cited scores 987 ms TTFT fireworks · 220 tok/s · 100.00% available · n=186
AnthropicPolicy varies 11 models 2070 ms p50 · n=51
GMI CloudPolicy varies 76 models 3851 ms p50 · n=16
OpenAIZDR on prepaid 47 models 775 ms p50 · n=472
Atlas CloudPolicy varies 78 models 2981 ms p50 · n=29
Google AI StudioPolicy varies 13 models 4801 ms p50 · n=498
Google Vertex AIZDR on prepaid 11 models 1281 ms p50 · n=28
Lightning AIPolicy varies 33 models 2137 ms p50 · n=22
KimiPolicy varies 4 models 8298 ms p50 · n=128

Browse every modelReview provider policiesOpen the full leaderboardSnapshot 2026-09-17T14:05:33.960Z

Workspace access

Sign in

Choose a sign in method to access your TrustedRouter workspace.

By signing in you agree to the terms of service and privacy policy.