Dan Cowsill.
← The project behind the report

Where does
the data go?

OpenRouter inference-provider due diligence.

Research snapshot · 3 July 2026 · 76 providers

35 GO Met the study’s criteria 27 Conditional GO Subject to named conditions 8 Conditional NO-GO Standard access did not meet the brief 6 NO-GO Did not meet the study’s criteria

01 Executive summary

From the original report

This project conducted a data-sovereignty due-diligence review of 76 AI inference providers reachable through OpenRouter, evaluated against Canadian PIPEDA / provincial data-sovereignty requirements. US-based and allied-jurisdiction providers are acceptable for this engagement; the single red line is client data flowing to, or being processed within, mainland China (PRC residency, PRC-state or Chinese-corporate ownership, or proxying inference to a China-based upstream). One additional listed OpenRouter entry ("fake-provider") was excluded as a non-entity and is not part of the evaluated set.

Of the 76 providers assessed, 35 are a clean GO, 27 are a CONDITIONAL-GO (acceptable subject to named conditions — a signed DPA, enabling Zero Data Retention, region-pinning, or resolving an unlaunched OpenRouter integration), 8 are a CONDITIONAL-NO-GO, and 6 are an outright NO-GO. In plain terms: 62 of 76 providers clear the sovereignty bar in some form, but only 35 clear it cleanly with no material caveats. 14 of 76 fail the criteria and should not receive Canadian client data without a structural change on the provider's side.

The 14 failures cluster into four recurring patterns rather than being scattered idiosyncrasies: (1) proxy/aggregator architectures that route prompts to undisclosed or China-resident upstream models (AionLabs, AI Crucible, Infermatic, Switchpoint); (2) unverifiable or non-existent corporate entities that make accountability impossible to establish (Infermatic, "stealth"); (3) decentralized or permissionless marketplace architectures that cannot pin the physical location of inference and therefore cannot guarantee geography (AkashML, Ambient, io.net, Perceptron's default consumer license); and (4) one provider — SiliconFlow — where the underlying corporate structure itself is Chinese-founded and Beijing-headquartered with PRC state-linked investors, making it a direct instance of the red line rather than a proxy risk to it. A related fifth pattern shows up among conditional passes: several providers (nCompass, Inferact, Cirrascale, Crusoe, Avian, HeyGen, Tenstorrent) are architecturally sound but are not currently live OpenRouter integrations, so their conditional status reflects availability risk rather than a sovereignty defect.

02 Full provider register

All 76 original assessments

Showing all 76 providers

GO 35 in the original review

AI21

ai21

Amazon Bedrock

amazon-bedrock

Amazon Nova

amazon-nova

Anthropic

anthropic

Arcee AI

arcee-ai

Cerebras

cerebras

Cirrascale

cirrascale

Cohere

cohere

DigitalOcean

digitalocean

Fireworks AI

fireworks

FriendliAI

friendli

Google AI Studio

google-ai-studio

Google Vertex AI

google-vertex

Groq

groq

Inceptron

inceptron

Inflection AI

inflection

Ionstream

ionstream

Mancer

mancer

MARA

mara

Mistral AI

mistral

Modular

modular

Morph

morph

Nebius

nebius

NextBit

nextbit

OpenAI

openai

Perplexity

perplexity

Phala

phala

Recraft

recraft

Reka

reka

Relace

relace

SambaNova

sambanova

Together AI

together

Upstage

upstage

Wafer

wafer

Weights & Biases

wandb

Conditional GO 27 in the original review

Avian

avian

Azure

azure

Baseten

baseten

Black Forest Labs

black-forest-labs

Chutes

chutes

Clarifai

clarifai

Cloudflare

cloudflare

Crusoe

crusoe

Darkbloom

darkbloom

No Chinese sub-processor, model origin, or PRC ownership — the core red line is clear — but the complete absence of provider geofencing (inference can run on a Mac in any jurisdiction) and no DPA/SOC 2/independent audit limit it to non-personal or low-sensitivity workloads for now.

Research references (10)

Selected links recorded in the original provider profile; not reverified for this presentation.

Decart

decart

Well-capitalized Israeli-founded company (US Delaware entity) that self-hosts open-weight LLMs on its own US/EU multi-silicon infrastructure, but one of its two OpenRouter models (GLM 5.2 / Z.ai) is absent from its own model catalog, leaving that model's serving path unresolved and possibly proxied through Z.ai's Singapore/China infrastructure.

Research references (12)

Selected links recorded in the original provider profile; not reverified for this presentation.

DekaLLM

dekallm

Featherless

featherless

GMICloud

gmicloud

HeyGen

heygen

Inception AI

inception

Inference.net

inference-net

Liquid AI

liquid

ModelRun

modelrun

Novita AI

novita

NVIDIA

nvidia

Parasail

parasail

Poolside

poolside

QuiverAI

quiver

Sakana AI

sakana

Sourceful

sourceful

Tenstorrent

tenstorrent

xAI

xai

Enterprise API product (the route OpenRouter uses) has zero Chinese sub-processors or ownership and processes data entirely in the US, but the same corporate entity was found by the Privacy Commissioner of Canada to have violated PIPEDA in June 2026 over consumer Grok Imagine deepfakes.

Research references (12)

Selected links recorded in the original provider profile; not reverified for this presentation.

Conditional NO-GO 8 in the original review

AkashML

akashml

Ambient

ambient

Inferact

inferact-vllm

io.net

io-net

nCompass

ncompass

Perceptron

perceptron

Switchpoint AI

switchpoint

Venice.ai

venice

NO-GO 6 in the original review

AionLabs

aion-labs

AI Crucible

crucible

Infermatic

infermatic

OpenInference

open-inference

SiliconFlow

siliconflow

"stealth"

stealth

03 The 14 that did not pass

Original classification

The original report highlighted the six NO-GO and eight conditional NO-GO assessments. Their full reasons appear in the register above; the download also retains the report’s separate deep-dive section.

Note on classification: two profiles in this tier (Perceptron, Venice.ai) contain individually favourable "Conditional Go" language for a narrow scenario (Perceptron's Enterprise Production License + ZDR; Venice's TEE-only routing under strict guardrails), but the master verdict index rolls both up to CONDITIONAL-NO-GO because their default/standard access path fails the criteria (Perceptron's default Consumer Use License permits training on inputs; Venice carries material founder/reputational tail risk for general-purpose client-data use). This report follows the master index's roll-up tier as authoritative and reports the underlying nuance above.

04 Methodology & caveats

From the original report

Each provider was researched using a skill-driven parallel workflow with four concurrent research lanes: corporate OSINT (legal entity, ownership, funding, PRC ties), product & infrastructure (self-hosted vs. proxy architecture, serving-path mapping, sub-processor list), privacy & data-flow (privacy policy and Terms of Service analysis, training-on-data clauses, retention, OpenRouter badge accuracy), and reputation (litigation, regulatory findings, security incidents, public controversy). Primary sources — privacy policies, Terms of Service, corporate registries, SEC/regulatory filings, and OpenRouter's own provider metadata — were verified directly rather than relied on secondhand summaries.

  • Findings were mapped to PIPEDA's Fair Information Principles (Accountability, Consent, Limiting Collection, Openness, and cross-border transfer disclosure) to reach each verdict.
  • Live web research is inherently non-deterministic — exact wording, confidence levels, and minor facts can shift between runs. The authoritative, fully-sourced reasoning for every verdict lives in that provider's individual due-diligence profile, not in this summary.
  • "fake-provider", a placeholder entry with no real corporate identity behind it, was excluded from the evaluated set of 76 as a non-entity, not scored as a failure.
  • Several CONDITIONAL-GO and CONDITIONAL-NO-GO verdicts reflect OpenRouter availability status (slug "not available") rather than a sovereignty defect in the underlying company — these are flagged individually in the register above and should be re-verified before contracting.
  • This report is a portfolio-level roll-up for decision triage. Before contracting with any provider, review its full individual profile for the complete evidentiary basis, open questions, and recommended conditions.

This web edition reproduces the consolidated report’s provider names, verdicts, and reasons. The company branding has been removed, and selected reference links have been added from the underlying research profiles. The downloadable HTML preserves the full consolidated report.

Download the July 2026 report