DAN COWSILL / RESEARCH DELIVERABLE
OpenRouter inference providers.
Data-sovereignty due diligence.
Research snapshot · 3 July 2026 · 76 providers evaluated
An archived project deliverable, reproduced with personal branding. The findings below are the original July 2026 assessments, not a current provider recommendation. The restriction on China-bound data flows was part of this project's brief; verdicts reflect that scope rather than a universal compliance certification.
Interactive report on dcowsill.comExecutive Summary
This project conducted a data-sovereignty due-diligence review of 76 AI inference providers reachable through OpenRouter, evaluated against Canadian PIPEDA / provincial data-sovereignty requirements. US-based and allied-jurisdiction providers are acceptable for this engagement; the single red line is client data flowing to, or being processed within, mainland China (PRC residency, PRC-state or Chinese-corporate ownership, or proxying inference to a China-based upstream). One additional listed OpenRouter entry ("fake-provider") was excluded as a non-entity and is not part of the evaluated set.
Of the 76 providers assessed, 35 are a clean GO, 27 are a CONDITIONAL-GO (acceptable subject to named conditions — a signed DPA, enabling Zero Data Retention, region-pinning, or resolving an unlaunched OpenRouter integration), 8 are a CONDITIONAL-NO-GO, and 6 are an outright NO-GO. In plain terms: 62 of 76 providers clear the sovereignty bar in some form, but only 35 clear it cleanly with no material caveats. 14 of 76 fail the criteria and should not receive Canadian client data without a structural change on the provider's side.
The 14 failures cluster into four recurring patterns rather than being scattered idiosyncrasies: (1) proxy/aggregator architectures that route prompts to undisclosed or China-resident upstream models (AionLabs, AI Crucible, Infermatic, Switchpoint); (2) unverifiable or non-existent corporate entities that make accountability impossible to establish (Infermatic, "stealth"); (3) decentralized or permissionless marketplace architectures that cannot pin the physical location of inference and therefore cannot guarantee geography (AkashML, Ambient, io.net, Perceptron's default consumer license); and (4) one provider — SiliconFlow — where the underlying corporate structure itself is Chinese-founded and Beijing-headquartered with PRC state-linked investors, making it a direct instance of the red line rather than a proxy risk to it. A related fifth pattern shows up among conditional passes: several providers (nCompass, Inferact, Cirrascale, Crusoe, Avian, HeyGen, Tenstorrent) are architecturally sound but are not currently live OpenRouter integrations, so their conditional status reflects availability risk rather than a sovereignty defect.
Verdict Tally
76 providers evaluated in total (fake-provider excluded as a non-entity). 62 of 76 clear the criteria (GO + CONDITIONAL-GO), but only 35 clear it cleanly with no material caveats. 14 of 76 fail outright (8 CONDITIONAL-NO-GO + 6 NO-GO).
Full Verdict Register
All 76 evaluated providers, grouped by verdict tier. Verdicts and reasons are drawn from the master verdict index and cross-checked against each provider's individual due-diligence profile; reason text below was tightened to a single clean sentence where the master index's index-page summary had been truncated mid-clause.
GO — 35 Providers
| Provider | Verdict | Reason |
|---|---|---|
| AI21 ai21 | GO | AI21 (Israel) is a first-party model developer with strong enterprise compliance (SOC 2 Type II, ISO 27001/27017/27018/42001) and a contractual no-training commitment; no China data-flow risk. Main residual risk is company financial instability, not sovereignty. |
| Amazon Bedrock amazon-bedrock | GO | US AWS service with enterprise-grade compliance, no China-bound data flow, customer-controlled retention (incl. ZDR), and no PRC ownership ties; the sole caveat is an opt-in provider_data_share mode for select Anthropic frontier models. |
| Amazon Nova amazon-nova | GO | Amazon's own first-party foundation models served exclusively on AWS infrastructure with no external sub-processor, no proxy to China, and no training on customer data; ZDR and Canadian region selection are available. |
| Anthropic anthropic | GO | No data-sovereignty blockers identified for Canadian client workloads routed via OpenRouter. |
| Arcee AI arcee-ai | GO | US-based, US-owned, US-hosted open-weight model developer with no PRC ownership or Chinese sub-processors and a self-hosted VPC option; default public terms permit training on customer inputs unless an Enterprise contract is signed. |
| Cerebras cerebras | GO | US publicly traded semiconductor company (Nasdaq: CBRS) running 100% of inference on its own Wafer-Scale Engine silicon in US and Canadian (Montreal) data centers, with no Chinese ownership, data centers, or sub-processors. |
| Cirrascale cirrascale | GO | US-based bare-metal GPU infrastructure provider with no China connection and a clean no-training privacy policy; not yet an active OpenRouter provider, so direct contractual engagement is recommended. |
| Cohere cohere | GO | Canadian-headquartered first-party model developer running all inference on Google Cloud US-Central with exclusively US sub-processors and zero China ties; negotiate ZDR and a DPA for enterprise workloads. |
| DigitalOcean digitalocean | GO | US publicly traded cloud provider (NYSE: DOCN) that self-hosts open-weight models — including DeepSeek — on its own US/Canadian GPUs (with a Toronto option), never proxying to DeepSeek China. |
| Fireworks AI fireworks | GO | US-headquartered, exclusively US-investor-backed provider that self-hosts all models (including DeepSeek) on its own US/EU/APAC GPUs with zero data retention and no China-based sub-processors at any layer. |
| FriendliAI friendli | GO | US Delaware corporation self-hosting open-weight models (DeepSeek, Qwen, GLM) on Nebius, Samsung Cloud, and AWS GPUs with no proxying to China-based endpoints; only gaps are a consent-by-use cross-border clause and no public DPA. |
| Google AI Studio google-ai-studio | GO | First-party Google product running entirely on Google's own US-based infrastructure; paid-tier API calls are contractually excluded from training, so paid-tier routing is recommended for client data. |
| Google Vertex AI google-vertex | GO | First-party Google Cloud service running wholly on Google's own US and allied-region infrastructure with no third-party proxying, contractual no-training protection, and Canada data residency (Montreal). |
| Groq groq | GO | US hardware company running all models on its own custom LPU infrastructure across US, Canada, Europe, and APAC, with contractual no-training, ZDR, SOC 2 Type II, and a Canadian sovereign-AI partnership with Bell Canada. |
| Inceptron inceptron | GO | Swedish (EU) provider that self-hosts open-weight models — including Chinese-origin ones — on its own EU/US GPU infrastructure with zero-retention default and no proxy path to China. |
| Inflection AI inflection | GO | First-party model developer running inference entirely on its own US infrastructure with no proxying, no Chinese sub-processors, and no PRC ownership. |
| Ionstream ionstream | GO | US-based, US-owned bare-metal GPU-as-a-Service provider running inference on its own NVIDIA GPUs in Texas with no upstream sub-processor, no China data flow, and no training on customer data. |
| Mancer mancer | GO | Self-hosts all models on US-based GPU infrastructure with zero exposure to Chinese sub-processors or upstreams; remaining conditions concern enterprise readiness (DPA, formal ZDR, training opt-out), not sovereignty. |
| MARA mara | GO | US publicly traded company (NASDAQ: MARA) that self-hosts all served models on its own US GPU clusters, so customer data never reaches the Chinese model developer (MiniMax) or OpenAI. |
| Mistral AI mistral | GO | French (EU) first-party model developer with no China data-flow path and no PRC-state ownership; the only caveat is US sub-processor touchpoints (payments, web search, image generation) covered by EU Standard Contractual Clauses. |
| Modular modular | GO | US-based inference infrastructure company with no China data-flow exposure and SOC 2 Type 2 certification; Chinese-origin open-weight models are served on Modular's own US GPUs, not proxied — secure a DPA and ZDR commitment before scale use. |
| Morph morph | GO | US-based, self-hosted inference provider with strong tiered data protections, no China data flows, and data-handling policies that align with its OpenRouter badges. |
| Nebius nebius | GO | Vertically integrated GPU infrastructure provider (not a proxy/aggregator) with zero data flow to China, self-owned datacenters in EU/UK/US/Israel, and verifiable SOC 2/ISO 27001; enable ZDR to avoid the default speculative-decoding training use. |
| NextBit nextbit | GO | Spanish (EU) provider running its own physical data center in Spain, serving only self-hosted open-weight models with an explicit no-training guarantee and a GDPR-compliant DPA; no evidence of any China data flow. |
| OpenAI openai | GO | US-headquartered first-party model developer with no China-based sub-processors or PRC ownership and API data excluded from training by default; ZDR and Canada data residency require direct OpenAI coordination. |
| Perplexity perplexity | GO | US-domiciled, US-infrastructure provider with contractual no-training/ZDR guarantees, SOC 2 Type II, and a DPA with EU SCCs; even its DeepSeek R1-powered models run self-hosted on AWS in North America, never proxied to China. |
| Phala phala | GO | US-based TEE confidential-compute platform running models on its own hardware-isolated GPU infrastructure with no proxying to China-based providers; use Phala Cloud directly, not the separate Singapore-parented RedPill aggregator, for sensitive workloads. |
| Recraft recraft | GO | Model developer serving only its own proprietary image models via the OpenRouter API on US/EU cloud GPU infrastructure with no training on API data and 24-hour output deletion. |
| Reka reka | GO | US-headquartered first-party model developer training and hosting its own models on Oracle Cloud Infrastructure with zero Chinese data centers and no PRC-affiliated investors; OpenRouter routes directly to Reka's own API. |
| Relace relace | GO | US-based first-party model provider operating its own inference infrastructure with no proxying to third parties and no PRC ownership ties; verify enterprise DPA/SOC 2 and the training opt-out before client procurement. |
| SambaNova sambanova | GO | US hardware-native inference provider running all models on its own Reconfigurable Dataflow Unit chips in US and Japan data centers, with no inference data flow to China and no upstream API proxying. |
| Together AI together | GO | Well-capitalized US corporation with no Chinese ownership that explicitly self-hosts all open-weight models (including DeepSeek, Qwen) on its own North American GPUs; the optional passthrough toggle defaults off. |
| Upstage upstage | GO | South Korean, PIPA-governed entity with no China-based sub-processors, a substantively accurate no-training pledge, and SOC 2/ISO 27001/27701 certification; the residual risk is standard US sub-processor exposure common to any US-hosted provider. |
| Wafer wafer | GO | US-based inference provider that self-hosts all models on its own US/EU GPUs with no training on customer data, per-request ZDR, and no corporate or sub-processor ties to China. |
| Weights & Biases wandb | GO | W&B Serverless Inference self-hosts on CoreWeave US/EU GPUs; all models, including Chinese-origin open weights (DeepSeek, Qwen, Kimi), run from open weights on CoreWeave hardware, never proxied to upstream China APIs. |
Conditional-Go — 27 Providers
| Provider | Verdict | Reason |
|---|---|---|
| Avian avian | CONDITIONAL-GO | Architecture is clean for sovereignty (self-hosted on US Azure, no China data flow, zero retention), but the provider is not currently available on OpenRouter, the company is very small (~2 employees), and formal compliance documentation is unpublished. |
| Azure azure | CONDITIONAL-GO | US-headquartered, publicly traded corporation hosting models entirely on its own global infrastructure with no proxying and no China data flow; because OpenRouter is always in the data path and the US CLOUD Act applies, BYOK plus regional deployment in Canada East is the prudent path for sensitive workloads. |
| Baseten baseten | CONDITIONAL-GO | US-based GPU infrastructure operator that self-hosts all open-weight models on its own multi-cloud fleet (US/EU, no PRC sub-processors) with architectural Zero Data Retention and SOC 2 Type II/HIPAA — acceptable provided region-restricted deployment is configured and per-model sourcing is confirmed. |
| Black Forest Labs black-forest-labs | CONDITIONAL-GO | German-headquartered, EU/GDPR-governed company with no PRC ownership or sub-processors, but its default API terms grant a perpetual, irrevocable license to train on customer inputs/outputs — contradicting its own OpenRouter 'No training' badge. |
| Chutes chutes | CONDITIONAL-GO | Architecturally self-hosted on decentralized Bittensor infrastructure with no evidence of proxy routing to China and strong hardware-enforced privacy guarantees, but OpenRouter classifies Chutes as 'prompts retained for unknown period' (not ZDR), and its SOC 2 claim is unverifiable. |
| Clarifai clarifai | CONDITIONAL-GO | Acceptable US-based self-hosted inference provider — the China red line is not crossed — but a May 2026 Nebius acqui-hire (engineering team departed, inference IP licensed away) creates existential uncertainty about Clarifai's viability as an independent provider. |
| Cloudflare cloudflare | CONDITIONAL-GO | US-based, publicly traded company with no PRC ownership that self-hosts open-weight models on its own global GPU network (not a proxy); the one condition is that Workers AI has no region-pinning capability, so inference could land in any of 335+ global edge locations. |
| Crusoe crusoe | CONDITIONAL-GO | US-vertically-integrated AI infrastructure company with zero Chinese ownership or subprocessors and a contractual commitment not to train on or retain customer data, but the OpenRouter provider slug is not yet live. |
| Darkbloom darkbloom | CONDITIONAL-GO | No Chinese sub-processor, model origin, or PRC ownership — the core red line is clear — but the complete absence of provider geofencing (inference can run on a Mac in any jurisdiction) and no DPA/SOC 2/independent audit limit it to non-personal or low-sensitivity workloads for now. |
| Decart decart | CONDITIONAL-GO | Well-capitalized Israeli-founded company (US Delaware entity) that self-hosts open-weight LLMs on its own US/EU multi-silicon infrastructure, but one of its two OpenRouter models (GLM 5.2 / Z.ai) is absent from its own model catalog, leaving that model's serving path unresolved and possibly proxied through Z.ai's Singapore/China infrastructure. |
| DekaLLM dekallm | CONDITIONAL-GO | Does not trigger the China red line — an Indonesian state-linked company self-hosting open-weight models on its own NVIDIA GPUs in Indonesian data centers — but data resides in Indonesia (not a PIPEDA-adequate jurisdiction) and government access is permitted under Indonesia's PDP Law. |
| Featherless featherless | CONDITIONAL-GO | Strong for data sovereignty by default — self-hosted US/EU infrastructure, no prompt logging, no international transfer — but enterprise-governance gaps (no DPA, no SOC 2/ISO, no Canadian representative) mean regulated enterprise workloads need a negotiated DPA first. |
| GMICloud gmicloud | CONDITIONAL-GO | Self-hosts open-weight models on its own US-based NVIDIA GPUs and does not proxy to Chinese upstream APIs, but data may be processed in Taiwan without a published transfer mechanism, and no ZDR commitment is published. |
| HeyGen heygen | CONDITIONAL-GO | No China data-flow risk and backed by strong US VC investors, SOC 2 Type II, and all-US subprocessors, but it is not currently a live OpenRouter inference provider, and its training-on-inputs practice requires careful opt-out handling for client data. |
| Inception AI inception | CONDITIONAL-GO | Substantially lower sovereignty risk than proxy/aggregator providers, with no PRC ties or upstream model proxying, but the training-data license is default opt-in and compliance certifications (SOC 2/ISO) are unpublished outside the enterprise tier. |
| Inference.net inference-net | CONDITIONAL-GO | US-based company with no evidence of China data flow and a privacy policy that forbids data sharing/training, but the `inference-net` OpenRouter slug is currently inactive, so approval is conditional on that path going live. |
| Liquid AI liquid | CONDITIONAL-GO | US-based model developer with no China data-flow, PRC ownership, or sub-processors, but its privacy policy explicitly permits training on user inputs/outputs with no opt-out — contradicting its own 'No training' badge. |
| ModelRun modelrun | CONDITIONAL-GO | Technical architecture (self-hosted US GPUs, Zero Data Retention, no proxying to MoonshotAI/China) is sound, but extreme corporate opacity (no identified founder, ~1-year-old company at a residential address, no DPA, no SOC 2/ISO) makes this a high vendor-risk provider. |
| Novita AI novita | CONDITIONAL-GO | Self-hosts 200+ open-weight models on its own global GPU infrastructure with no evidence of China data flow and a SOC 2 Type II audit, but the legal entity name is not found in US registries and the founder team has China-nexus ties (PPIO/PPTV). |
| NVIDIA nvidia | CONDITIONAL-GO | US public company with no China data-flow risk that runs inference on its own US-based DGX Cloud, but the API Trial Terms permit NVIDIA to collect prompts/outputs to improve its models with no opt-out — a PIPEDA problem until production terms are confirmed. |
| Parasail parasail | CONDITIONAL-GO | Self-hosts all models (including Chinese-origin DeepSeek, Qwen, GLM, Kimi) on its own global GPU fleet with no proxying to mainland China, but no public sub-processor list exists for upstream GPU infrastructure and certification is only SOC 2 Type I. |
| Poolside poolside | CONDITIONAL-GO | US-based foundation-model creator that trains and serves its own open-weight models from US infrastructure with no proxy-to-China flow, but a minority investment by Redpoint Ventures China warrants client disclosure and the company faces material financial instability. |
| QuiverAI quiver | CONDITIONAL-GO | Canadian-headquartered proprietary SVG-generation API company with no PRC data-flow risk, but its Terms of Service grant an unusually broad perpetual license to user content, and the OpenRouter slug is not currently an active provider. |
| Sakana AI sakana | CONDITIONAL-GO | Tokyo-based Japanese corporation with no PRC ownership ties and a sovereign-AI mission is acceptable in itself, but its Fugu orchestration product has a transparency deficit (undisclosed agent pool, no DPA, contradictory no-training badge). |
| Sourceful sourceful | CONDITIONAL-GO | UK company with no PRC ownership or identified China-based inference, storing data on Google Cloud UK/EU under SOC 2/ISO certification, but its Riverflow proxy sends prompt data to unnamed third-party diffusion models via US infrastructure with no ZDR badge. |
| Tenstorrent tenstorrent | CONDITIONAL-GO | US/Canada-based AI hardware company with no China data-flow risk and a strong sovereignty profile, but it is not currently an active OpenRouter provider and does not operate an inference API service. |
| xAI xai | CONDITIONAL-GO | Enterprise API product (the route OpenRouter uses) has zero Chinese sub-processors or ownership and processes data entirely in the US, but the same corporate entity was found by the Privacy Commissioner of Canada to have violated PIPEDA in June 2026 over consumer Grok Imagine deepfakes. |
Conditional-No-Go — 8 Providers
| Provider | Verdict | Reason |
|---|---|---|
| AkashML akashml | CONDITIONAL-NO-GO | Fundamental architecture — a permissionless decentralized compute marketplace where node operators in any jurisdiction, including China, can process inference — is incompatible with PIPEDA's accountability principle for personal data via OpenRouter's default routing. |
| Ambient ambient | CONDITIONAL-NO-GO | Infrastructure is a Proof-of-Work blockchain with globally distributed miners and no inference-location guarantees or OpenRouter region badge, and the self-host-vs-proxy architecture for Chinese-origin models (Z.ai GLM, MoonshotAI Kimi) is unverified. |
| Inferact inferact-vllm | CONDITIONAL-NO-GO | Architecture (self-hosted vLLM on US GPU infrastructure, no proxying to Chinese upstream APIs) would be favourable, but the company is pre-launch with no published privacy policy, Terms of Service, DPA, or SOC 2 — a prospective candidate, not a usable one yet. |
| io.net io-net | CONDITIONAL-NO-GO | OpenRouter's default IO Intelligence API routing sends requests across a decentralized P2P GPU marketplace spanning 130+ countries with no geo-residency guarantee, so inference could land on GPUs physically located in China. |
| nCompass ncompass | CONDITIONAL-NO-GO | Has pivoted away from its AI inference API product entirely and is no longer an operating inference provider — the OpenRouter slug is listed as not available with no active models to evaluate. |
| Perceptron perceptron | CONDITIONAL-NO-GO | US-based, self-hosted model developer with zero identifiable China ties is workable only under an Enterprise Production License with ZDR; the default Consumer Use License is a No-Go because it permits AI training on user inputs, so standard access fails the criteria. |
| Switchpoint AI switchpoint | CONDITIONAL-NO-GO | An LLM routing layer, not an inference provider — it can proxy requests to China-resident DeepSeek through its automated router with no documented mechanism for the end-user to prevent that routing. |
| Venice.ai venice | CONDITIONAL-NO-GO | Privacy architecture (zero data retention, TEE/E2EE options) is genuinely strong and US/EU-only infrastructure avoids the China red line, but founder regulatory history (two SEC settlements) and documented cybercrime use of the platform create material tail risk that offsets the technical strengths for default use. |
No-Go — 6 Providers
| Provider | Verdict | Reason |
|---|---|---|
| AionLabs aion-labs | NO-GO | Proxy/aggregator layer that routes requests to unnamed upstream providers and third-party hosting infrastructure that 'may change over time'; for DeepSeek-based models this means data could flow to DeepSeek's China API, with no sub-processor list, DPA, or SOC 2/ISO certification. |
| AI Crucible crucible | NO-GO | Pure proxy/aggregator that self-hosts no inference capacity — all prompts and data are transmitted to third-party upstream providers including China-based entities (DeepSeek, Moonshot/Kimi, Alibaba/Qwen, Z.AI/GLM), and this transmission cannot be disabled per its Terms of Service. |
| Infermatic infermatic | NO-GO | Unverifiable corporate identity (no registry record, no physical address, no named founder) combined with a LiteLLM proxy architecture that routes prompts to undisclosed upstream providers with no DPA or sub-processor list. |
| OpenInference open-inference | NO-GO | Poses zero China data-flow risk in itself, but its Privacy Policy and Terms of Service directly contradict each other on data retention and training, and it is an academic grant project with no DPA, SOC/ISO certification, or accountability framework. |
| SiliconFlow siliconflow | NO-GO | Chinese-founded, Beijing-headquartered company operating through a dual PRC/Singapore entity structure with no public commitment that inference data stays outside China, no DPA, and Chinese state-linked investors (Alibaba, Huawei Hubble, China Unicom). |
| "stealth" stealth | NO-GO | Not a real, identifiable provider — the OpenRouter slug returns no verifiable corporate entity, so no client data should be routed to it under any circumstances. |
Deep-Dive: The 14 That Fail
These 14 providers should not receive Canadian client data under current terms. Each is summarized below with the specific mechanism that causes the failure, drawn from its individual due-diligence profile.
No-Go (6)
Conditional-No-Go (8)
Note on classification: two profiles in this tier (Perceptron, Venice.ai) contain individually favourable "Conditional Go" language for a narrow scenario (Perceptron's Enterprise Production License + ZDR; Venice's TEE-only routing under strict guardrails), but the master verdict index rolls both up to CONDITIONAL-NO-GO because their default/standard access path fails the criteria (Perceptron's default Consumer Use License permits training on inputs; Venice carries material founder/reputational tail risk for general-purpose client-data use). This report follows the master index's roll-up tier as authoritative and reports the underlying nuance above.
Methodology & Caveats
Each provider was researched using a skill-driven parallel workflow with four concurrent research lanes: corporate OSINT (legal entity, ownership, funding, PRC ties), product & infrastructure (self-hosted vs. proxy architecture, serving-path mapping, sub-processor list), privacy & data-flow (privacy policy and Terms of Service analysis, training-on-data clauses, retention, OpenRouter badge accuracy), and reputation (litigation, regulatory findings, security incidents, public controversy). Primary sources — privacy policies, Terms of Service, corporate registries, SEC/regulatory filings, and OpenRouter's own provider metadata — were verified directly rather than relied on secondhand summaries.
- Findings were mapped to PIPEDA's Fair Information Principles (Accountability, Consent, Limiting Collection, Openness, and cross-border transfer disclosure) to reach each verdict.
- Live web research is inherently non-deterministic — exact wording, confidence levels, and minor facts can shift between runs. The authoritative, fully-sourced reasoning for every verdict lives in that provider's individual due-diligence profile, not in this summary.
- "fake-provider", a placeholder entry with no real corporate identity behind it, was excluded from the evaluated set of 76 as a non-entity, not scored as a failure.
- Several CONDITIONAL-GO and CONDITIONAL-NO-GO verdicts reflect OpenRouter availability status (slug "not available") rather than a sovereignty defect in the underlying company — these are flagged individually in the register above and should be re-verified before contracting.
- This report is a portfolio-level roll-up for decision triage. Before contracting with any provider, review its full individual profile for the complete evidentiary basis, open questions, and recommended conditions.