{
  "model_provider_subprocessors": [
    {
      "confidential_compute": true,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "tinfoil",
      "name": "Tinfoil",
      "policy": "Tracked as a confidential inference provider with attested provider compute and no prompt/output logging claims.",
      "policy_url": "https://tinfoil.sh/security-and-privacy-faq",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 3,
      "provider_e2ee": true,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": true,
      "zdr_label": "yes"
    },
    {
      "confidential_compute": false,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "meta",
      "name": "Meta via OpenRouter",
      "policy": "TrustedRouter sends requests through its attested gateway to OpenRouter, which routes them to Meta. This downstream route is not marked zero-retention, confidential-compute, or end-to-end encrypted.",
      "policy_url": "https://openrouter.ai/docs/features/privacy-and-logging",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": false,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": false,
      "zdr_label": "no"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "anthropic",
      "name": "Anthropic",
      "policy": "Not currently marked ZDR in TrustedRouter. Anthropic may offer contracted or account-specific data-retention terms, but this provider is excluded from trustedrouter/zdr until that posture is reverified.",
      "policy_url": "https://platform.claude.com/docs/en/api/data-retention",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": false,
      "zdr_label": "no"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "openai",
      "name": "OpenAI",
      "policy": "Contracted Zero Data Retention is active for TrustedRouter's managed OpenAI account, effective July 28, 2026, and live enforcement was verified on July 29, 2026. This guarantee applies only to TrustedRouter-funded prepaid routes; customer BYOK credentials use the data controls on the customer's own OpenAI organization or project.",
      "policy_url": "https://developers.openai.com/api/docs/guides/your-data#data-retention-controls-for-abuse-monitoring",
      "prepaid_zdr": true,
      "prepaid_zdr_effective_on": "2026-07-28",
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": false,
      "zdr_label": "prepaid only"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "google-ai-studio",
      "name": "Google AI Studio",
      "policy": "Not currently marked ZDR in TrustedRouter. Google AI Studio and the Gemini Developer API have product- and billing-specific data-use terms, so this route stays outside trustedrouter/zdr.",
      "policy_url": "https://ai.google.dev/gemini-api/terms",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": false,
      "zdr_label": "no"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "google-vertex",
      "name": "Google Vertex AI",
      "policy": "TrustedRouter's managed Vertex AI account is covered by contractual Zero Data Retention. This guarantee applies only to TrustedRouter-funded prepaid routes. TrustedRouter does not invoke Google Search or Maps grounding or Gemini Live session resumption on these routes. Google AI Studio is classified separately.",
      "policy_url": "https://docs.cloud.google.com/vertex-ai/generative-ai/docs/vertex-ai-zero-data-retention",
      "prepaid_zdr": true,
      "prepaid_zdr_effective_on": "2026-07-28",
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": false,
      "zdr_label": "prepaid only"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "cerebras",
      "name": "Cerebras",
      "policy": "Tracked as provider-ZDR. Cerebras documents zero-retention inference and ZDR-compliant ephemeral prompt caching that is never persisted.",
      "policy_url": "https://inference-docs.cerebras.ai/capabilities/prompt-caching",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 2,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": true,
      "zdr_label": "yes"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "deepseek",
      "name": "DeepSeek",
      "policy": "Not ZDR. DeepSeek's published privacy policy says prompts/inputs may be collected and personal data may be used to train or improve machine learning models and algorithms.",
      "policy_url": "https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html?locale=en_US",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": false,
      "zdr_label": "no"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "mistral",
      "name": "Mistral",
      "policy": "No provider-ZDR claim is tracked here. This is separate from any no-training or enterprise retention commitments Mistral may offer.",
      "policy_url": "https://docs.mistral.ai/admin/security-access/privacy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "kimi",
      "name": "Kimi",
      "policy": "No provider-ZDR claim is tracked here. Kimi/Moonshot policy source is linked for users who need to review API retention and processing terms.",
      "policy_url": "https://platform.kimi.ai/docs/agreement/userprivacy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "zai",
      "name": "Z.AI",
      "policy": "No provider-ZDR claim is tracked here. Z.AI/BigModel policy source is linked for users who need to review API retention and processing terms.",
      "policy_url": "https://open.bigmodel.cn/usercenter/agreement/privacy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "together",
      "name": "Together",
      "policy": "Tracked as provider ZDR. Together documents that inference inputs and outputs are not stored by default; temporary prompt caching may be used for performance, and sharing content for training is opt-in.",
      "policy_url": "https://docs.together.ai/docs/privacy-and-security",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 2,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": true,
      "zdr_label": "yes"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "fireworks",
      "name": "Fireworks AI",
      "policy": "No provider-ZDR claim is tracked here. Fireworks publishes security, privacy, and zero-retention documentation; enable a contracted ZDR posture before marking this provider as ZDR.",
      "policy_url": "https://trust.fireworks.ai",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "grok",
      "name": "xAI Grok",
      "policy": "xAI documents no training on API requests and 30-day default audit retention, with ZDR as an enterprise feature.",
      "policy_url": "https://docs.x.ai/docs/resources/faq-api/security",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "novita",
      "name": "Novita AI",
      "policy": "No provider-ZDR claim is tracked here. Novita's privacy policy says personal information is not used for model training; customer-content processing is governed by customer agreements.",
      "policy_url": "https://novita.ai/legal/privacy-policy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": true,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "phala",
      "name": "Phala",
      "policy": "Phala publishes TDX/GPU attestation and signed request receipts, but TrustedRouter does not yet verify the complete receipt chain on every routed request. The route is therefore not classified as provider E2EE and is excluded from trustedrouter/e2e.",
      "policy_url": "https://docs.phala.com/phala-cloud/confidential-ai/verify/overview",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 2,
      "provider_e2ee": false,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": true,
      "zdr_label": "yes"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "siliconflow",
      "name": "SiliconFlow",
      "policy": "No provider-ZDR claim is tracked here. SiliconFlow's privacy policy source is linked for retention and interaction-data terms.",
      "policy_url": "https://docs.siliconflow.com/en/legals/privacy-policy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": false,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "venice",
      "name": "Venice",
      "policy": "Mixed model-specific posture. TrustedRouter cannot independently verify a complete chain from a live Venice endpoint through immutable source and hardware measurements to committed model weights. Venice is therefore not tracked as confidential or E2EE. Exact routes marked Private in Venice's live catalog qualify only as policy-backed ZDR through endpoint-specific records; Anonymized routes do not.",
      "policy_url": "https://venice.ai/privacy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": false,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": false,
      "zdr_label": "no"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "parasail",
      "name": "Parasail",
      "policy": "Tracked as ZDR for serverless and dedicated inference. Parasail documents no storage or logging of submitted input on those service paths, retention only while generating and delivering output, and no training on input or output. Batch service is excluded from this claim; TrustedRouter does not route Parasail traffic through batch.",
      "policy_url": "https://docs.parasail.io/parasail-docs/security-and-account-management/data-privacy-retention",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 2,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": true,
      "zdr_label": "yes"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "lightning",
      "name": "Lightning AI",
      "policy": "No provider-ZDR claim is tracked here. Lightning's general privacy and security documentation is linked for retention review.",
      "policy_url": "https://lightning.ai/legal/privacy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "gmi",
      "name": "GMI Cloud",
      "policy": "GMI runs isolated/VPC GPU inference, but that is network isolation, NOT an attested TEE \u2014 so no confidential-compute, zero-retention, or E2EE claim is marked. Retention/training terms are unverified (the published policy page is JavaScript-only and would not render).",
      "policy_url": "https://gmicloud.ai/legal/privacy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "friendli",
      "name": "FriendliAI",
      "policy": "No provider-ZDR claim is tracked here. Friendli's legal/privacy terms are linked for users who need to review API data handling.",
      "policy_url": "https://friendli.ai/terms",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "baseten",
      "name": "Baseten",
      "policy": "No provider-ZDR claim is tracked here. Baseten's inference and security documentation are linked for users who need to review API data handling.",
      "policy_url": "https://docs.baseten.co/inference/overview",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "telnyx",
      "name": "Telnyx",
      "policy": "No provider-ZDR or confidential-compute claim is tracked here. Telnyx's privacy policy is linked for users who need to review inference data handling.",
      "policy_url": "https://telnyx.com/privacy-policy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "wafer",
      "name": "Wafer",
      "policy": "Wafer supports request-scoped ZDR via Wafer-ZDR: required on supported models; model-level support differs, so TrustedRouter keeps provider-level claims conservative.",
      "policy_url": "https://docs.wafer.ai/serverless/api-reference",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "crusoe",
      "name": "Crusoe",
      "policy": "No provider-ZDR claim is tracked here. Crusoe's Managed Inference docs and pricing/catalog pages are linked for model and API data-handling review.",
      "policy_url": "https://docs.crusoecloud.com/managed-inference/overview/",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "makora",
      "name": "Makora",
      "policy": "No provider-ZDR claim is tracked here. Makora's inference and privacy documentation are linked for users who need to review API data handling.",
      "policy_url": "https://www.makora.com/privacy-policy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": true,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "chutes",
      "name": "Chutes",
      "policy": "Chutes documents no prompt/output storage or training and serves these routes in confidential-compute TEEs. Standard API calls are not marked provider end-to-end encrypted.",
      "policy_url": "https://chutes.ai/docs/core-concepts/security-architecture",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 2,
      "provider_e2ee": false,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": true,
      "zdr_label": "yes"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "digitalocean",
      "name": "DigitalOcean Gradient AI",
      "policy": "No provider-ZDR claim is tracked here. DigitalOcean's Gradient AI model and pricing documentation is linked for data-handling review.",
      "policy_url": "https://docs.digitalocean.com/products/inference/",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "cloudflare-workers-ai",
      "name": "Cloudflare Workers AI",
      "policy": "No provider-ZDR claim is tracked here. Cloudflare's Workers AI documentation is linked for model and data-handling review.",
      "policy_url": "https://developers.cloudflare.com/workers-ai/",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "inceptron",
      "name": "Inceptron",
      "policy": "Inceptron documents zero retention by default: API prompts and outputs are processed transiently and discarded after processing.",
      "policy_url": "https://www.inceptron.io/privacy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 2,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": true,
      "zdr_label": "yes"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "morph",
      "name": "Morph",
      "policy": "Morph's public paid tier documents up to 30 days of content retention. Zero retention is reserved for enterprise contracts.",
      "policy_url": "https://www.morphllm.com/privacy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "atlas-cloud",
      "name": "Atlas Cloud",
      "policy": "Atlas Cloud publishes a platform zero-retention policy, while its aggregated model routes can involve downstream providers. TrustedRouter keeps the public route tier conservative pending downstream-path contractual verification.",
      "policy_url": "https://www.atlascloud.ai/zero-data-retention",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "streamlake",
      "name": "StreamLake",
      "policy": "No provider-ZDR claim is tracked. StreamLake's public privacy policy is linked for API data-handling review.",
      "policy_url": "https://www.streamlake.ai/document/DOC/mgkci47q13qr66h9i54",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": false,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "neurometric",
      "name": "Neurometric AI",
      "policy": "Neurometric states that TrustedRouter requests run with upstream trace logging disabled: prompts and completions are not written to observability or object storage, and only aggregate request counts and token totals are retained. This is classified as no-store, not contractual ZDR or confidential compute.",
      "policy_url": "https://www.neurometric.ai/privacy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 1,
      "provider_e2ee": false,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": false,
      "zdr_label": "no"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "deepinfra",
      "name": "DeepInfra",
      "policy": "Tracked as no-store, not strict ZDR. DeepInfra documents memory-only handling and no training for ordinary inference, but reserves the right to log a small portion of requests for debugging or security. Google- and Anthropic-backed routes also inherit those vendors' terms.",
      "policy_url": "https://docs.deepinfra.com/account/data-privacy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 1,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": false,
      "zdr_label": "no"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "nebius",
      "name": "Nebius Token Factory",
      "policy": "Marked ZDR via TrustedRouter's arrangement \u2014 Nebius RETAINS inputs/outputs by default (for speculative decoding); zero retention is an opt-in control, which the deployed Nebius account has enabled. Nebius does not train on customer data.",
      "policy_url": "https://docs.studio.nebius.com/legal/legal-quick-guide",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 2,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": true,
      "zdr_label": "yes"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "minimax",
      "name": "MiniMax",
      "policy": "No provider-ZDR claim is tracked here. MiniMax's product privacy overview is linked for users who need to review API/open-platform terms.",
      "policy_url": "https://www.minimax.io/privacy-policy-v2.html",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "thinkingmachines",
      "name": "Thinking Machines Lab",
      "policy": "No provider-ZDR claim is tracked here. Thinking Machines Lab's model and pricing documentation is linked for model capability and API review.",
      "policy_url": "https://tinker-docs.thinkingmachines.ai/tinker/models/",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "xiaomi",
      "name": "Xiaomi MiMo",
      "policy": "No provider-ZDR claim is tracked here. Xiaomi MiMo's open-platform terms are linked for users who need to review API data handling.",
      "policy_url": "https://platform.xiaomimimo.com/",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "alibaba",
      "name": "Alibaba Cloud Model Studio",
      "policy": "No provider-ZDR claim is tracked here. Alibaba Cloud Model Studio model availability and pricing are linked for users who need to review API data handling and regional deployment scope.",
      "policy_url": "https://www.alibabacloud.com/help/en/model-studio/model-pricing",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "ltx",
      "name": "Lightricks LTX",
      "policy": "No provider-ZDR, confidential-compute, or E2EE claim is tracked for the LTX video API. TrustedRouter relays and does not durably store prompt or generated video content.",
      "policy_url": "https://ltx.io/terms-of-use",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "runway",
      "name": "Runway",
      "policy": "No provider-ZDR, confidential-compute, or E2EE claim is tracked for the Runway video API. TrustedRouter relays and does not durably store prompt or generated video content.",
      "policy_url": "https://runwayml.com/privacy-policy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "kling",
      "name": "Kling AI",
      "policy": "No provider-ZDR, confidential-compute, or E2EE claim is tracked for the Kling video API. TrustedRouter relays and does not durably store prompt or generated video content.",
      "policy_url": "https://kling.ai/privacy-policy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 0,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": null,
      "zdr_label": "unknown"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "cohere",
      "name": "Cohere",
      "policy": "Marked ZDR \u2014 Cohere does not retain prompt/response content for TrustedRouter's configured account and does not train on customer API data. (Not a confidential-compute/TEE provider.)",
      "policy_url": "https://cohere.com/security",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 2,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": true,
      "zdr_label": "yes"
    },
    {
      "confidential_compute": null,
      "data_access": "Prompt/output content in transit only for requests routed to this provider; request metadata needed for billing, routing, abuse controls, and support.",
      "id": "voyage",
      "name": "Voyage AI",
      "policy": "Marked ZDR \u2014 Voyage AI does not retain prompt content for TrustedRouter's configured account and does not train on customer API data. (Not a confidential-compute/TEE provider.)",
      "policy_url": "https://www.voyageai.com/privacy",
      "prepaid_zdr": false,
      "prepaid_zdr_effective_on": null,
      "privacy_tier": 2,
      "provider_e2ee": null,
      "purpose": "Downstream model inference provider when a workspace selects this provider, this model, or an alias that routes to this provider.",
      "zdr": true,
      "zdr_label": "yes"
    }
  ],
  "routing_note": "Model providers are subprocessors only for traffic routed to them. Use trustedrouter/zdr, trustedrouter/e2e, or explicit provider allowlists for sensitive legal workloads.",
  "system_subprocessors": [
    {
      "data_access": "Prompt traffic on the production API terminates inside the attested gateway. GCP services store metadata, billing records, secrets, and operational logs as configured; TrustedRouter never logs or stores prompt/output content.",
      "name": "Google Cloud Platform",
      "policy_url": "https://cloud.google.com/security/compliance",
      "purpose": "Cloud hosting, Confidential Space, Cloud Run, Spanner, Bigtable, KMS, Secret Manager, and operational infrastructure."
    },
    {
      "data_access": "Public website traffic and DNS metadata. Production prompt TLS is designed to terminate inside the attested gateway, not inside the control-plane site.",
      "name": "Cloudflare",
      "policy_url": "https://www.cloudflare.com/trust-hub/",
      "purpose": "DNS, public-site caching, status/trust hosting support, and edge protection for non-prompt surfaces."
    },
    {
      "data_access": "Billing identity and payment metadata. No prompt/output content.",
      "name": "Stripe",
      "policy_url": "https://stripe.com/privacy",
      "purpose": "Card payments, stablecoin checkout, customer records, saved payment methods, invoices, and billing webhooks."
    },
    {
      "data_access": "Billing identity and payment metadata. No prompt/output content.",
      "name": "PayPal",
      "policy_url": "https://www.paypal.com/us/legalhub/privacy-full",
      "purpose": "Optional PayPal payment processing for prepaid credits."
    },
    {
      "data_access": "Email address and transactional email metadata. No prompt/output content.",
      "name": "Amazon Web Services SES/SNS",
      "policy_url": "https://aws.amazon.com/privacy/",
      "purpose": "Transactional email delivery, bounce handling, complaint handling, and email-domain verification."
    },
    {
      "data_access": "Scrubbed control-plane errors and metadata. Sentry is not configured in the attested prompt gateway and must not receive prompts, outputs, API keys, or BYOK secrets.",
      "name": "Sentry",
      "policy_url": "https://sentry.io/privacy/",
      "purpose": "Control-plane exception monitoring."
    },
    {
      "data_access": "Structured operational metadata. Prompt/output content must not be logged.",
      "name": "Axiom",
      "policy_url": "https://axiom.co/privacy",
      "purpose": "Operational log search and alerting."
    },
    {
      "data_access": "A model-generated search query, requested domain and country filters, and search metadata. Search runs only inside the attested gateway. Exa does not receive the original prompt or model output directly, but a generated query can reflect prompt content. Web search is blocked on ZDR, E2E/confidential, and EU privacy routes until a compatible contractual posture is approved.",
      "name": "Exa",
      "policy_url": "https://exa.ai/privacy",
      "purpose": "Optional hosted web search for Responses API requests that explicitly enable the web_search tool."
    },
    {
      "data_access": "Source code, CI metadata, and release artifacts. No production prompt/output content.",
      "name": "GitHub",
      "policy_url": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
      "purpose": "Source control, CI, release workflows, and public open-source repositories."
    }
  ]
}