Where a model processes prompts, and who made it

A model node (nodeType:LanguageModel) carries two marks, and they answer two different questions:

Mark Field Question Values
πŸ‡ͺπŸ‡Ί / 🌍 / ❔ Processing dataResidency (+ dataRetention) Where are our prompts processed? Eu, Global, Unknown β€” open: a module may add a region code such as CH
🏳️ Origin modelOrigin (+ modelMaker) Where is the model's maker based? ISO country code: CN (Z.ai, Moonshot, DeepSeek, Qwen), US (OpenAI, Anthropic, xAI, Meta, Google), FR (Mistral), CA (Cohere), any other ISO code

The two marks are independent. GLM 5.3 is made in China and can be processed in the EU; Claude is made in the US and is processed wherever Anthropic or Azure route it. Both are open string-constant vocabularies (policy open-vocabulary-string-constants): DataResidency and ModelOrigin in MeshWeaver.AI.

The rule: only Eu is EU

DataResidency.IsEu is true for Eu and nothing else. Only an unset or blank mark becomes Unknown. Any other value stays as authored, because the vocabulary is open: CH stays CH, and so does a typo. None of them ever counts as EU, and each satisfies only a requirement that names exactly that value. DataResidency.Satisfies(actual, required) never admits Unknown, even when the requirement itself names Unknown.

The mark describes the route, not the model:

Route Mark
eu.openrouter.ai (OpenRouter's EU region: only EU provider endpoints) Eu
openrouter.ai, api.openai.com, api.anthropic.com, the makers' own public APIs Global
Azure, DataZoneStandard or regional Standard SKU in an EU-region resource Eu, but only when declared
Azure, GlobalStandard Global, declared
Azure, undeclared Unknown: the same host serves every SKU, so the host alone proves nothing
Claude in Microsoft Foundry Global. Foundry offers Claude as Global Standard, plus a Data Zone for the US only. There is no EU zone.

Where the marks come from

The model node's own dataResidency is the only value any consumer reads. The picker badge, the provider page, tier resolution and the round's refusal all read it, so they cannot disagree. The emitters seed it with ModelProvenance.Seed, and a value authored on the node always wins:

  1. Declared by the deployment. {Section}:DataResidency and {Section}:DataRetention apply to every model of that catalog section, e.g. AzureFoundry__DataResidency=Eu for a DataZone-only account.
  2. Implied by the endpoint (DataResidency.FromEndpoint), for the hosts in the table above.
  3. Otherwise unset, which reads Unknown.

The maker and its country are inferred from the id. The org slug is tried first (z-ai/, moonshotai/, anthropic/), then the family token (Kimi-K2.6, claude-haiku-4-5, DeepSeek-V4-Flash). An id nothing recognises stays Unknown; the platform never guesses.

A ModelProvider node carries dataResidency / dataRetention too. This is a seed for the models the provider creates, never a verdict. The built-in provider node is create-if-absent, so a mark added to its configuration later reaches its model children, which are synced, and not the provider node itself.

Where the marks show

Requiring EU: fail closed

A requirement is set in one of two places. When both are set, both apply.

Who How Effect
The instance AI:RequiredDataResidency=Eu (env AI__RequiredDataResidency) The picker hides the instance's models not marked Eu. The default model, tier resolution and Auto skip them. The round refuses them, and so does the image generator.
An agent front matter requiredDataResidency: Eu (AgentConfiguration.RequiredDataResidency) Tier and Auto resolution for that agent skip non-Eu models. A round of that agent on one is refused, including a hand-off to it.

The refusal happens before any prompt leaves the process. The user sees a localized sentence naming the model, its mark and who requires EU, and the refusal is logged at Warning. An explicit pick of a non-admitted model is healed onto an admitted one, the same way an unusable pick is healed. When none is admitted, the round is refused; it never falls back to a Global model. A bare model id that matches several catalog entries with different marks reads Unknown: which entry would serve it cannot be promised.

"No endpoint" never means "a US default". Under the instance switch, every request is also checked at the point where it is built, by ChatClientCredentialResolver.InstanceRouteRefusal (called by the OpenAI, Azure OpenAI, Anthropic and Azure Foundry factories and by the image generator). A request with no endpoint is refused, because the OpenAI SDK would fall back to api.openai.com and the image generator would use the same host. A request whose endpoint is a known global host is refused too. An Azure host passes this check: the model node's own mark was already checked. Listing a provider's models (ProviderModelLister, against the maker's API) sends no prompts and is not gated.

What the instance switch does NOT cover:

Code review (policy code-review-eu-only): the reviewer's model is bound to Provider/OpenRouterEU (eu.openrouter.ai) with a pinned providerRouting region, which the review-binding change owns (MeshWeaver.Plugins#2446). Its DataResidencies.EU value "EU" reads as Eu here, because the comparison is case-insensitive. The agent-level marker requiredDataResidency: Eu is not set on Governance/Agent/reviewer yet, and that is deliberate. That agent also reviews every governed activity, and no model on the control instance is marked Eu today. Declaring the requirement now would refuse every review, including the approvals the elimination below needs. Set it in the same change that marks the EU review model.

Pinned by:

The fleet audit (2026-09-27)

A read-only audit covering every Deployments/* record on the control instance, the LanguageModel/ModelProvider nodes on four meshes (systemorph, memex, pearl, partnerre), every Azure AI Services account (az cognitiveservices account deployment list, subscription explicit), and the OpenRouter EU region (https://eu.openrouter.ai/api/v1/models/<id>/endpoints).

No chat or embedding model served by any instance is EU-only today. The only EU-only rows are the in-cluster Whisper speech model (AKS, swedencentral) and two Azure deployments that no instance references.

instance rows πŸ‡ͺπŸ‡Ί EU-only 🌍 NOT-EU ❔ UNKNOWN origin CN / US / CA / FR
memex (memex.systemorph.com) 23 0 21 2 8 / 14 / 0 / 0
memex-cloud (memex.meshweaver.cloud) 30 1 (Whisper speech) 29 0 10 / 18 / 1 / 1
pearl 5 0 4 1 (embedding not declared) 0 / 4 / 0 / 0
build 1 0 0 1 (no ai block) β€”
control (Planned) 3 0 3 0 0 / 3 / 0 / 0
partnerre 12 0 12 0 7 / 5 / 0 / 0
s-meshweaver deployments no instance references 21 2 (o1 DataZone, text-embedding-3-large Standard) 19 0 6 / 14 / 1 / 0

The Azure accounts: s-meshweaver (rg-meshweaverai, sub 7ecc5974-…), fy-meshweaver3-dev-swc-001 (rg-meshweaver3-dev-swc-001, sub c45ca8ae-…) and partnerre-memex-ai (memex-aks-rg, PartnerRe tenant). All three are in swedencentral with SKU S0. Every Claude model in swedencentral is offered as GlobalStandard only. claude-haiku-4-5 v20251001 is hostedOn=anthropic, so it may be processed outside Azure.

Bring-your-own keys live as ModelProvider nodes at {user}/_Memex/<Provider>, with their models at {user}/_Provider/<Provider>/<model> and the key stored enc:v1:. They are never seeded Eu: a known global host reads Global, and anything else reads Unknown. Row-level security hides other users' BYOK nodes, so the audit counts only the auditor's own.

Every model, by route

instances route model endpoint host SKU / route processing retention origin maker verdict evidence
memex, memex-cloud, control (Planned) Anthropic (Claude in Foundry) claude-opus-5-5 s-meshweaver.services.ai.azure.com/anthropic/ GlobalStandard 250 (v2, hostedOn azure) 🌍 Global β€” hostedOn=azure, any Azure region Anthropic is processor; no ZDR evidence πŸ‡ΊπŸ‡Έ US Anthropic NOT-EU az cognitiveservices account deployment list --name s-meshweaver + az cognitiveservices model list --location swedencentral
memex, memex-cloud, control (Planned) Anthropic (Claude in Foundry) claude-sonnet-5 s-meshweaver.services.ai.azure.com/anthropic/ GlobalStandard 500 (v2, hostedOn azure) 🌍 Global β€” hostedOn=azure, any Azure region Anthropic is processor; no ZDR evidence πŸ‡ΊπŸ‡Έ US Anthropic NOT-EU az cognitiveservices account deployment list --name s-meshweaver + az cognitiveservices model list --location swedencentral
memex, memex-cloud, control (Planned) Anthropic (Claude in Foundry) claude-haiku-4-5 s-meshweaver.services.ai.azure.com/anthropic/ GlobalStandard 100 (v20251001, hostedOn anthropic) 🌍 Global β€” hostedOn=anthropic: may be processed OUTSIDE Azure Anthropic is processor; no ZDR evidence πŸ‡ΊπŸ‡Έ US Anthropic NOT-EU az cognitiveservices account deployment list --name s-meshweaver + az cognitiveservices model list --location swedencentral
memex, memex-cloud OpenRouter global (MeshWeaver platform key) z-ai/glm-5.3 openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡¨πŸ‡³ CN Z.ai (Zhipu) NOT-EU curl https://eu.openrouter.ai/api/v1/models/z-ai/glm-5.3/endpoints β†’ ['Inceptron/inceptron/fp4', 'Mistral/mistral/nvfp4']
memex, memex-cloud OpenRouter global (MeshWeaver platform key) moonshotai/kimi-k3 openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡¨πŸ‡³ CN Moonshot AI NOT-EU curl https://eu.openrouter.ai/api/v1/models/moonshotai/kimi-k3/endpoints β†’ []
memex, memex-cloud OpenRouter global (MeshWeaver platform key) moonshotai/kimi-k2.7-code openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡¨πŸ‡³ CN Moonshot AI NOT-EU curl https://eu.openrouter.ai/api/v1/models/moonshotai/kimi-k2.7-code/endpoints β†’ ['Inceptron/inceptron/int4']
memex, memex-cloud OpenRouter global (MeshWeaver platform key) openai/gpt-5.2 openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU curl https://eu.openrouter.ai/api/v1/models/openai/gpt-5.2/endpoints β†’ []
memex, memex-cloud OpenRouter global (MeshWeaver platform key) openai/gpt-5-mini openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU curl https://eu.openrouter.ai/api/v1/models/openai/gpt-5-mini/endpoints β†’ ['Azure/azure/swedencentral']
memex, memex-cloud OpenRouter global (MeshWeaver platform key) google/gemini-3.1-pro-preview openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡ΊπŸ‡Έ US Google NOT-EU curl https://eu.openrouter.ai/api/v1/models/google/gemini-3.1-pro-preview/endpoints β†’ []
memex, memex-cloud OpenRouter global (MeshWeaver platform key) google/gemini-3.7-flash openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡ΊπŸ‡Έ US Google NOT-EU curl https://eu.openrouter.ai/api/v1/models/google/gemini-3.7-flash/endpoints β†’ []
memex, memex-cloud OpenRouter global (MeshWeaver platform key) anthropic/claude-opus-5.5 openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡ΊπŸ‡Έ US Anthropic NOT-EU curl https://eu.openrouter.ai/api/v1/models/anthropic/claude-opus-5.5/endpoints β†’ ['Amazon Bedrock/amazon-bedrock/eu-west-1', 'Google/google-vertex/europe']
memex, memex-cloud OpenRouter global (MeshWeaver platform key) anthropic/claude-opus-5 openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡ΊπŸ‡Έ US Anthropic NOT-EU curl https://eu.openrouter.ai/api/v1/models/anthropic/claude-opus-5/endpoints β†’ ['Amazon Bedrock/amazon-bedrock/eu-west-1', 'Google/google-vertex/europe']
memex, memex-cloud OpenRouter global (MeshWeaver platform key) anthropic/claude-sonnet-5 openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡ΊπŸ‡Έ US Anthropic NOT-EU curl https://eu.openrouter.ai/api/v1/models/anthropic/claude-sonnet-5/endpoints β†’ ['Amazon Bedrock/amazon-bedrock/eu-west-1', 'Google/google-vertex/europe']
memex, memex-cloud OpenRouter global (MeshWeaver platform key) deepseek/deepseek-v4-pro openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡¨πŸ‡³ CN DeepSeek NOT-EU curl https://eu.openrouter.ai/api/v1/models/deepseek/deepseek-v4-pro/endpoints β†’ []
memex, memex-cloud OpenRouter global (MeshWeaver platform key) x-ai/grok-4.6 openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡ΊπŸ‡Έ US xAI NOT-EU curl https://eu.openrouter.ai/api/v1/models/x-ai/grok-4.6/endpoints β†’ []
memex, memex-cloud OpenRouter global (MeshWeaver platform key) qwen/qwen3-max openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡¨πŸ‡³ CN Alibaba (Qwen) NOT-EU curl https://eu.openrouter.ai/api/v1/models/qwen/qwen3-max/endpoints β†’ []
memex, memex-cloud OpenRouter global (MeshWeaver platform key) qwen/qwen3.6-35b-a3b openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡¨πŸ‡³ CN Alibaba (Qwen) NOT-EU curl https://eu.openrouter.ai/api/v1/models/qwen/qwen3.6-35b-a3b/endpoints β†’ []
memex, memex-cloud OpenRouter global (MeshWeaver platform key) qwen/qwen3.8-27b openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡¨πŸ‡³ CN Alibaba (Qwen) NOT-EU curl https://eu.openrouter.ai/api/v1/models/qwen/qwen3.8-27b/endpoints β†’ []
memex, memex-cloud OpenRouter global (MeshWeaver platform key) qwen/qwen3.8-flash openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡¨πŸ‡³ CN Alibaba (Qwen) NOT-EU curl https://eu.openrouter.ai/api/v1/models/qwen/qwen3.8-flash/endpoints β†’ []
memex, memex-cloud Embedding (OpenAICompatible β†’ OpenRouter global) openai/text-embedding-3-small openrouter.ai global routing (upstream Azure or OpenAI) 🌍 Global unknown (upstream-dependent) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU record Embedding__Endpoint=https://openrouter.ai/api/v1; eu.openrouter.ai endpoints []
memex AzureFoundry / AzureOpenAI provider (enabled, key mounted) (none configured) (endpoint "") n/a ❔ Unknown n/a - - UNKNOWN get @Provider/AzureFoundry endpoint "" models []; get @Provider/AzureOpenAI no endpoint; Features__Ai__Providers__AzureOpenAI/AzureFoundry=true; AzureFoundry__ApiKey mounted
memex Claude Code CLI (user BYOK: rbuergi/_Memex/ClaudeCode) sonnet (rbuergi/_Provider/ClaudeCode/sonnet) Anthropic 1P (user subscription; assumed) Anthropic first-party 🌍 Global user's own Anthropic terms πŸ‡ΊπŸ‡Έ US Anthropic NOT-EU systemorph search nodeType:ModelProvider partitions:all β†’ rbuergi/_Memex/ClaudeCode; Features__Ai__Clis__ClaudeCode=true
memex GitHub Copilot CLI (Features__Ai__Clis__Copilot=true) (Copilot-chosen) GitHub Copilot (assumed) GitHub Copilot ❔ Unknown GitHub Copilot terms πŸ‡ΊπŸ‡Έ US GitHub/Microsoft (+ underlying makers) UNKNOWN @Deployments/memex extraPortalConfig; no residency evidence gathered
memex-cloud Anthropic (Claude in Foundry) β€” STALE mesh node claude-opus-4-7 s-meshweaver.services.ai.azure.com/anthropic/ NO such deployment on s-meshweaver (would fail); swedencentral offers GlobalStandard only 🌍 Global as above πŸ‡ΊπŸ‡Έ US Anthropic NOT-EU memex search nodeType:LanguageModel partitions:all β†’ Provider/Anthropic/claude-opus-4-7; memex get @Provider/Anthropic models [claude-opus-4-7, claude-sonnet-4-6, claude-haiku-4-5] β‰  record [opus-5-5, sonnet-5, haiku-4-5]
memex-cloud Anthropic (Claude in Foundry) β€” STALE mesh node claude-sonnet-4-6 s-meshweaver.services.ai.azure.com/anthropic/ NO such deployment on s-meshweaver (would fail); swedencentral offers GlobalStandard only 🌍 Global as above πŸ‡ΊπŸ‡Έ US Anthropic NOT-EU memex search nodeType:LanguageModel partitions:all β†’ Provider/Anthropic/claude-sonnet-4-6; memex get @Provider/Anthropic models [claude-opus-4-7, claude-sonnet-4-6, claude-haiku-4-5] β‰  record [opus-5-5, sonnet-5, haiku-4-5]
memex-cloud azureAis (record models: [] β€” provisioned, NOT offered) Llama-4-Maverick-17B-128E-Instruct-FP8 fy-meshweaver3-dev-swc-001.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US Meta NOT-EU az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001
memex-cloud azureAis (record models: [] β€” provisioned, NOT offered) cohere-command-a fy-meshweaver3-dev-swc-001.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡¦ CA Cohere NOT-EU az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001
memex-cloud azureAis (record models: [] β€” provisioned, NOT offered) Mistral-Large-3 fy-meshweaver3-dev-swc-001.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡«πŸ‡· FR Mistral AI NOT-EU az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001
memex-cloud azureAis (record models: [] β€” provisioned, NOT offered) DeepSeek-V3.2 fy-meshweaver3-dev-swc-001.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN DeepSeek NOT-EU az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001
memex-cloud azureAis (record models: [] β€” provisioned, NOT offered) gpt-5.4 fy-meshweaver3-dev-swc-001.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001
memex-cloud azureAis (record models: [] β€” provisioned, NOT offered) gpt-5.3-codex fy-meshweaver3-dev-swc-001.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001
memex-cloud azureAis (record models: [] β€” provisioned, NOT offered) DeepSeek-V4-Pro fy-meshweaver3-dev-swc-001.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN DeepSeek NOT-EU az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001
memex-cloud Speech (in-cluster whisper) whisper-swiss-german whisper-swiss-german:8080 (AKS memexaks-cluster) self-hosted pod πŸ‡ͺπŸ‡Ί Eu stays in our cluster; no third party πŸ‡ΊπŸ‡Έ US OpenAI (Whisper base weights; fine-tune maker not established) EU-only @Deployments/memex-cloud extraPortalConfig Speech__Endpoint; az aks show -n memexaks-cluster -g memex-aks-rg --subscription 7ecc5974-… --query location β†’ swedencentral
pearl OpenRouter global (our platform account) anthropic/claude-sonnet-5 openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡ΊπŸ‡Έ US Anthropic NOT-EU curl https://eu.openrouter.ai/api/v1/models/anthropic/claude-sonnet-5/endpoints β†’ ['Amazon Bedrock/amazon-bedrock/eu-west-1', 'Google/google-vertex/europe']
pearl OpenRouter global (our platform account) openai/gpt-5.2 openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU curl https://eu.openrouter.ai/api/v1/models/openai/gpt-5.2/endpoints β†’ []
pearl OpenRouter global (our platform account) openai/gpt-5-mini openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU curl https://eu.openrouter.ai/api/v1/models/openai/gpt-5-mini/endpoints β†’ ['Azure/azure/swedencentral']
pearl OpenRouter global (our platform account) google/gemini-3.7-flash openrouter.ai global routing (any provider) 🌍 Global no ZDR filter set πŸ‡ΊπŸ‡Έ US Google NOT-EU curl https://eu.openrouter.ai/api/v1/models/google/gemini-3.7-flash/endpoints β†’ []
pearl Embedding (not declared in record) ? ? ❔ Unknown ? ? ? UNKNOWN record Embedding__Endpoint=https://openrouter.ai/api/v1; eu.openrouter.ai endpoints []
build (no ai block) (none declared) - - ❔ Unknown - - - UNKNOWN @Deployments/build notes: "No ai block β€” no chat provider"; build mesh has no MCP server here
partnerre AzureFoundry (models endpoint) β€” offered LanguageModel node DeepSeek-V4-Pro partnerre-memex-ai.services.ai.azure.com/models NO deployment of this name; account holds only GlobalStandard deployments 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN DeepSeek NOT-EU az cognitiveservices account deployment list --name partnerre-memex-ai
partnerre AzureFoundry (models endpoint) β€” offered LanguageModel node DeepSeek-V3-0324 partnerre-memex-ai.services.ai.azure.com/models NO deployment of this name; account holds only GlobalStandard deployments 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN DeepSeek NOT-EU az cognitiveservices account deployment list --name partnerre-memex-ai
partnerre AzureFoundry (models endpoint) β€” offered LanguageModel node DeepSeek-V4-Flash partnerre-memex-ai.services.ai.azure.com/models NO deployment of this name; account holds only GlobalStandard deployments 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN DeepSeek NOT-EU az cognitiveservices account deployment list --name partnerre-memex-ai
partnerre AzureFoundry (models endpoint) β€” offered LanguageModel node Kimi-K2.6 partnerre-memex-ai.services.ai.azure.com/models NO deployment of this name; account holds only GlobalStandard deployments 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN Moonshot AI NOT-EU az cognitiveservices account deployment list --name partnerre-memex-ai
partnerre Azure deployment (not referenced by a LanguageModel node (embedding use: not established)) Kimi-K2.7-Code partnerre-memex-ai.services.ai.azure.com GlobalStandard 20 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN Moonshot AI NOT-EU az cognitiveservices account deployment list --name partnerre-memex-ai
partnerre Azure deployment (not referenced by a LanguageModel node (embedding use: not established)) DeepSeek-V4-Pro-0813 partnerre-memex-ai.services.ai.azure.com GlobalStandard 20 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN DeepSeek NOT-EU az cognitiveservices account deployment list --name partnerre-memex-ai
partnerre Azure deployment (not referenced by a LanguageModel node (embedding use: not established)) DeepSeek-V4-Flash-0731 partnerre-memex-ai.services.ai.azure.com GlobalStandard 20 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN DeepSeek NOT-EU az cognitiveservices account deployment list --name partnerre-memex-ai
partnerre Azure deployment (not referenced by a LanguageModel node (embedding use: not established)) gpt-5-mini partnerre-memex-ai.services.ai.azure.com GlobalStandard 200 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name partnerre-memex-ai
partnerre Azure deployment (Anthropic endpoint partnerre-memex-ai/anthropic, provider models [] and no LanguageModel nodes) claude-opus-5-5 partnerre-memex-ai.services.ai.azure.com GlobalStandard 40 (v2 hostedOn azure) 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US Anthropic NOT-EU az cognitiveservices account deployment list --name partnerre-memex-ai
partnerre Azure deployment (Anthropic endpoint partnerre-memex-ai/anthropic, provider models [] and no LanguageModel nodes) claude-sonnet-5 partnerre-memex-ai.services.ai.azure.com GlobalStandard 80 (v2 hostedOn azure) 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US Anthropic NOT-EU az cognitiveservices account deployment list --name partnerre-memex-ai
partnerre Azure deployment (Anthropic endpoint partnerre-memex-ai/anthropic, provider models [] and no LanguageModel nodes) claude-haiku-4-5 partnerre-memex-ai.services.ai.azure.com GlobalStandard 80 (v2 hostedOn azure) 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US Anthropic NOT-EU az cognitiveservices account deployment list --name partnerre-memex-ai
partnerre Azure deployment (not referenced by a LanguageModel node (embedding use: not established)) text-embedding-3-small partnerre-memex-ai.services.ai.azure.com GlobalStandard 120 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name partnerre-memex-ai
(s-meshweaver, unreferenced) Azure AI Services deployment o4-mini s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment gpt-4.1-mini s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment gpt-4o-mini s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment o3-mini s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment gpt-4.1 s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment gpt-4o s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment o1 s-meshweaver.services.ai.azure.com DataZoneStandard πŸ‡ͺπŸ‡Ί Eu abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI EU-only az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment gpt-5-chat s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment gpt-5-mini s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment gpt-5-nano s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment gpt-5 s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment gpt-5.1-chat s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment embed-v-4-0 s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡¦ CA Cohere NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment gpt-5.4 s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment Kimi-K2.5 s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN Moonshot AI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment text-embedding-3-large s-meshweaver.services.ai.azure.com Standard πŸ‡ͺπŸ‡Ί Eu abuse monitoring (default) πŸ‡ΊπŸ‡Έ US OpenAI EU-only az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment DeepSeek-V4-Pro s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN DeepSeek NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment DeepSeek-V4-Flash s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN DeepSeek NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment Kimi-K2.6 s-meshweaver.services.ai.azure.com GlobalStandard 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN Moonshot AI NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment DeepSeek-R1-0528 s-meshweaver.services.ai.azure.com GlobalStandard (Disabled) 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN DeepSeek NOT-EU az cognitiveservices account deployment list --name s-meshweaver
(s-meshweaver, unreferenced) Azure AI Services deployment DeepSeek-V3-0324 s-meshweaver.services.ai.azure.com GlobalStandard (Disabled) 🌍 Global abuse monitoring (default) πŸ‡¨πŸ‡³ CN DeepSeek NOT-EU az cognitiveservices account deployment list --name s-meshweaver

Not established by the audit

  1. The running pods' configuration. The records are not the pods. Overlay-only helm keys and live environments were not read.
  2. Embeddings on pearl and partnerre. Pearl's record declares no Embedding__* key. partnerre has no control record; its account holds text-embedding-3-small GlobalStandard, which is probably the one in use, but that is not proven.
  3. Retention. It was not checked whether any Azure account has approved modified abuse monitoring (zero retention), whether OpenRouter has account-level ZDR or provider filters, or what Inceptron's terms are. On GLM 5.3, the EU Mistral endpoint is tagged nvfp4, not zdr.
  4. Inceptron's location. OpenRouter lists it in its EU region, and that is the only basis for calling it EU.
  5. GitHub Copilot CLI residency was not researched, so it is Unknown. The build instance's mesh was not reachable.

Proposed elimination (not executed)

Every change below is a record change or an Azure deployment change. Each goes through a governed Hosting/InstanceAction / Governance/Activity on the control instance, and each needs the maintainer's approval. Nothing here has been applied.

The target tiers, as the maintainer decided, are all served through eu.openrouter.ai on our OpenRouter account:

tier model EU providers
heavy anthropic/claude-opus-5.5 Amazon Bedrock eu-west-1, Google Vertex europe
standard, review z-ai/glm-5.3 Inceptron, Mistral
light openai/gpt-6-luna Azure (eu)
utility mistralai/mistral-small-2603 Mistral (eu)

These apply to memex, memex-cloud and pearl. Pearl runs on our OpenRouter account, not a key of its own, and moves to the EU endpoint with the others.

partnerre is out of this scope. It uses its own OpenRouter Business account, so its models are its own to choose. They are marked the same way, with processing decided by its own route.

  1. Route the tiers above through the EU region. Use an OpenRouterEU provider section at https://eu.openrouter.ai/api/v1, which is marked Eu by its endpoint. It is config-seeded, and its chart and Hosting rendering are owned by the fleet-switch work.
  2. Drop or mark the models with no EU route: moonshotai/kimi-k3, openai/gpt-5.2, google/gemini-3.1-pro-preview, google/gemini-3.7-flash, deepseek/deepseek-v4-pro, x-ai/grok-4.6 and every Qwen model. None of them has an EU provider on OpenRouter. The tiers above replace them; any that stay offered are marked Global.
  3. Embeddings: deploy text-embedding-3-small as DataZoneStandard on s-meshweaver (offered in swedencentral) and point Embedding__Endpoint there. It is the same model, so no re-index is needed. The alternative is mistralai/mistral-embed on eu.openrouter.ai, which does need a re-index.
  4. Claude in Foundry (memex, memex-cloud, control) has no EU zone. The heavy tier moves to Claude through eu.openrouter.ai. Any Foundry Claude still offered is marked Global.
  5. Azure GlobalStandard deployments on our accounts: redeploy as DataZoneStandard where swedencentral offers it (gpt-5-mini, gpt-5.4, Mistral-Large-3, DeepSeek-V4-Flash 2026-04-23). Mark the rest only. Delete the unreferenced s-meshweaver deployments.
  6. Declare the marks on the records: {Section}__DataResidency per provider section (Anthropic__DataResidency=Global; AzureFoundry__DataResidency=Eu only once its deployments are DataZone or regional), and AI__RequiredDataResidency=Eu on each instance that must be EU-only. 🚨 Measured on core main: the portal chart renders none of these keys yet, and it renders no OpenRouter__Endpoint or OpenRouterEU__* either. Its ConfigMap names every key explicitly, so a record that sets them reaches no container until the chart adds them.

Incidental findings from the audit, not about residency: