Where a model processes prompts, and who made it
A model node (nodeType:LanguageModel) carries two marks, and they answer two different questions:
| Mark | Field | Question | Values |
|---|---|---|---|
| πͺπΊ / π / β Processing | dataResidency (+ dataRetention) |
Where are our prompts processed? | Eu, Global, Unknown β open: a module may add a region code such as CH |
| π³οΈ Origin | modelOrigin (+ modelMaker) |
Where is the model's maker based? | ISO country code: CN (Z.ai, Moonshot, DeepSeek, Qwen), US (OpenAI, Anthropic, xAI, Meta, Google), FR (Mistral), CA (Cohere), any other ISO code |
The two marks are independent. GLM 5.3 is made in China and can be processed in the EU; Claude
is made in the US and is processed wherever Anthropic or Azure route it. Both are open
string-constant vocabularies (policy open-vocabulary-string-constants): DataResidency and
ModelOrigin in MeshWeaver.AI.
The rule: only Eu is EU
DataResidency.IsEu is true for Eu and nothing else. Only an unset or blank mark becomes
Unknown. Any other value stays as authored, because the vocabulary is open: CH stays CH,
and so does a typo. None of them ever counts as EU, and each satisfies only a requirement that
names exactly that value.
DataResidency.Satisfies(actual, required) never admits Unknown, even when the requirement itself
names Unknown.
The mark describes the route, not the model:
| Route | Mark |
|---|---|
eu.openrouter.ai (OpenRouter's EU region: only EU provider endpoints) |
Eu |
openrouter.ai, api.openai.com, api.anthropic.com, the makers' own public APIs |
Global |
Azure, DataZoneStandard or regional Standard SKU in an EU-region resource |
Eu, but only when declared |
Azure, GlobalStandard |
Global, declared |
| Azure, undeclared | Unknown: the same host serves every SKU, so the host alone proves nothing |
| Claude in Microsoft Foundry | Global. Foundry offers Claude as Global Standard, plus a Data Zone for the US only. There is no EU zone. |
Where the marks come from
The model node's own dataResidency is the only value any consumer reads. The picker badge,
the provider page, tier resolution and the round's refusal all read it, so they cannot disagree.
The emitters seed it with ModelProvenance.Seed, and a value authored on the node always wins:
- Declared by the deployment.
{Section}:DataResidencyand{Section}:DataRetentionapply to every model of that catalog section, e.g.AzureFoundry__DataResidency=Eufor a DataZone-only account. - Implied by the endpoint (
DataResidency.FromEndpoint), for the hosts in the table above. - Otherwise unset, which reads
Unknown.
The maker and its country are inferred from the id. The org slug is tried first (z-ai/,
moonshotai/, anthropic/), then the family token (Kimi-K2.6, claude-haiku-4-5,
DeepSeek-V4-Flash). An id nothing recognises stays Unknown; the platform never guesses.
A ModelProvider node carries dataResidency / dataRetention too. This is a seed for the
models the provider creates, never a verdict. The built-in provider node is create-if-absent, so a
mark added to its configuration later reaches its model children, which are synced, and not the
provider node itself.
Where the marks show
- The model picker (
/modelin the composer). Every model row carries two badges, πͺπΊ/π/β and the maker's flag. The tooltip and accessible name are in the viewer's language: "Processed in the EU only Β· retention: ZDR", "Z.ai β model maker based in China". - The provider page (Settings β Providers β a provider). Its model grid has Processing and Origin columns.
- All text comes from
[Description]/[Translation]declarations on the constants and onModelProvenanceText, in English and German.
Requiring EU: fail closed
A requirement is set in one of two places. When both are set, both apply.
| Who | How | Effect |
|---|---|---|
| The instance | AI:RequiredDataResidency=Eu (env AI__RequiredDataResidency) |
The picker hides the instance's models not marked Eu. The default model, tier resolution and Auto skip them. The round refuses them, and so does the image generator. |
| An agent | front matter requiredDataResidency: Eu (AgentConfiguration.RequiredDataResidency) |
Tier and Auto resolution for that agent skip non-Eu models. A round of that agent on one is refused, including a hand-off to it. |
The refusal happens before any prompt leaves the process. The user sees a localized sentence
naming the model, its mark and who requires EU, and the refusal is logged at Warning. An explicit
pick of a non-admitted model is healed onto an admitted one, the same way an unusable pick is
healed. When none is admitted, the round is refused; it never falls back to a Global model. A bare
model id that matches several catalog entries with different marks reads Unknown: which entry
would serve it cannot be promised.
"No endpoint" never means "a US default". Under the instance switch, every request is also
checked at the point where it is built, by ChatClientCredentialResolver.InstanceRouteRefusal
(called by the OpenAI, Azure OpenAI, Anthropic and Azure Foundry factories and by the image
generator). A request with no endpoint is refused, because the OpenAI SDK would fall back to
api.openai.com and the image generator would use the same host. A request whose endpoint is a
known global host is refused too. An Azure host passes this check: the model node's own mark was
already checked. Listing a provider's models (ProviderModelLister, against the maker's API)
sends no prompts and is not gated.
What the instance switch does NOT cover:
- Per-user bring-your-own-key models (
{user}/_Memex/β¦,{user}/_Provider/β¦,ModelProvenance.IsPersonal) stay allowed and visible. They are still marked: a BYOK model is never seededEu. It readsGlobalfor a known global host andUnknownotherwise, because the person's account settings are theirs and not established here. - CLI harnesses (Claude Code, Copilot, Codex) run on the person's own subscription, straight to
Anthropic, GitHub and OpenAI. The maintainer decided they stay. They count like BYOK: allowed,
and marked NOT-EU (
Global) with originUS. - An agent requirement applies to every model, BYOK included.
Code review (policy code-review-eu-only): the reviewer's model is bound to
Provider/OpenRouterEU (eu.openrouter.ai) with a pinned providerRouting region, which the
review-binding change owns (MeshWeaver.Plugins#2446). Its DataResidencies.EU value "EU" reads
as Eu here, because the comparison is case-insensitive. The agent-level marker
requiredDataResidency: Eu is not set on Governance/Agent/reviewer yet, and that is deliberate.
That agent also reviews every governed activity, and no model on the control instance is marked
Eu today. Declaring the requirement now would refuse every review, including the approvals the
elimination below needs. Set it in the same change that marks the EU review model.
Pinned by:
DataResidencyRoundTest: on an EU-only instance, the provider is never called for a Global or an unmarked model. The negative control (the gate disabled) fails both cases.ModelProvenanceTest: the vocabulary, the seeding, the BYOK exemption, the route guard and the localized texts.
The fleet audit (2026-09-27)
A read-only audit covering every Deployments/* record on the control instance, the
LanguageModel/ModelProvider nodes on four meshes (systemorph, memex, pearl, partnerre), every
Azure AI Services account (az cognitiveservices account deployment list, subscription explicit),
and the OpenRouter EU region (https://eu.openrouter.ai/api/v1/models/<id>/endpoints).
No chat or embedding model served by any instance is EU-only today. The only EU-only rows are the in-cluster Whisper speech model (AKS, swedencentral) and two Azure deployments that no instance references.
| instance | rows | πͺπΊ EU-only | π NOT-EU | β UNKNOWN | origin CN / US / CA / FR |
|---|---|---|---|---|---|
| memex (memex.systemorph.com) | 23 | 0 | 21 | 2 | 8 / 14 / 0 / 0 |
| memex-cloud (memex.meshweaver.cloud) | 30 | 1 (Whisper speech) | 29 | 0 | 10 / 18 / 1 / 1 |
| pearl | 5 | 0 | 4 | 1 (embedding not declared) | 0 / 4 / 0 / 0 |
| build | 1 | 0 | 0 | 1 (no ai block) |
β |
| control (Planned) | 3 | 0 | 3 | 0 | 0 / 3 / 0 / 0 |
| partnerre | 12 | 0 | 12 | 0 | 7 / 5 / 0 / 0 |
| s-meshweaver deployments no instance references | 21 | 2 (o1 DataZone, text-embedding-3-large Standard) |
19 | 0 | 6 / 14 / 1 / 0 |
The Azure accounts: s-meshweaver (rg-meshweaverai, sub 7ecc5974-β¦), fy-meshweaver3-dev-swc-001
(rg-meshweaver3-dev-swc-001, sub c45ca8ae-β¦) and partnerre-memex-ai (memex-aks-rg, PartnerRe
tenant). All three are in swedencentral with SKU S0. Every Claude model in swedencentral is offered
as GlobalStandard only. claude-haiku-4-5 v20251001 is hostedOn=anthropic, so it may be
processed outside Azure.
Bring-your-own keys live as ModelProvider nodes at {user}/_Memex/<Provider>, with their models
at {user}/_Provider/<Provider>/<model> and the key stored enc:v1:. They are never seeded
Eu: a known global host reads Global, and anything else reads Unknown. Row-level security hides other users' BYOK nodes, so the audit
counts only the auditor's own.
Every model, by route
| instances | route | model | endpoint host | SKU / route | processing | retention | origin | maker | verdict | evidence |
|---|---|---|---|---|---|---|---|---|---|---|
| memex, memex-cloud, control (Planned) | Anthropic (Claude in Foundry) | claude-opus-5-5 |
s-meshweaver.services.ai.azure.com/anthropic/ | GlobalStandard 250 (v2, hostedOn azure) | π Global β hostedOn=azure, any Azure region | Anthropic is processor; no ZDR evidence | πΊπΈ US | Anthropic | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver + az cognitiveservices model list --location swedencentral |
| memex, memex-cloud, control (Planned) | Anthropic (Claude in Foundry) | claude-sonnet-5 |
s-meshweaver.services.ai.azure.com/anthropic/ | GlobalStandard 500 (v2, hostedOn azure) | π Global β hostedOn=azure, any Azure region | Anthropic is processor; no ZDR evidence | πΊπΈ US | Anthropic | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver + az cognitiveservices model list --location swedencentral |
| memex, memex-cloud, control (Planned) | Anthropic (Claude in Foundry) | claude-haiku-4-5 |
s-meshweaver.services.ai.azure.com/anthropic/ | GlobalStandard 100 (v20251001, hostedOn anthropic) | π Global β hostedOn=anthropic: may be processed OUTSIDE Azure | Anthropic is processor; no ZDR evidence | πΊπΈ US | Anthropic | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver + az cognitiveservices model list --location swedencentral |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | z-ai/glm-5.3 |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | π¨π³ CN | Z.ai (Zhipu) | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/z-ai/glm-5.3/endpoints β ['Inceptron/inceptron/fp4', 'Mistral/mistral/nvfp4'] |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | moonshotai/kimi-k3 |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | π¨π³ CN | Moonshot AI | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/moonshotai/kimi-k3/endpoints β [] |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | moonshotai/kimi-k2.7-code |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | π¨π³ CN | Moonshot AI | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/moonshotai/kimi-k2.7-code/endpoints β ['Inceptron/inceptron/int4'] |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | openai/gpt-5.2 |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | πΊπΈ US | OpenAI | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/openai/gpt-5.2/endpoints β [] |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | openai/gpt-5-mini |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | πΊπΈ US | OpenAI | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/openai/gpt-5-mini/endpoints β ['Azure/azure/swedencentral'] |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | google/gemini-3.1-pro-preview |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | πΊπΈ US | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/google/gemini-3.1-pro-preview/endpoints β [] |
|
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | google/gemini-3.7-flash |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | πΊπΈ US | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/google/gemini-3.7-flash/endpoints β [] |
|
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | anthropic/claude-opus-5.5 |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | πΊπΈ US | Anthropic | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/anthropic/claude-opus-5.5/endpoints β ['Amazon Bedrock/amazon-bedrock/eu-west-1', 'Google/google-vertex/europe'] |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | anthropic/claude-opus-5 |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | πΊπΈ US | Anthropic | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/anthropic/claude-opus-5/endpoints β ['Amazon Bedrock/amazon-bedrock/eu-west-1', 'Google/google-vertex/europe'] |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | anthropic/claude-sonnet-5 |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | πΊπΈ US | Anthropic | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/anthropic/claude-sonnet-5/endpoints β ['Amazon Bedrock/amazon-bedrock/eu-west-1', 'Google/google-vertex/europe'] |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | deepseek/deepseek-v4-pro |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | π¨π³ CN | DeepSeek | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/deepseek/deepseek-v4-pro/endpoints β [] |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | x-ai/grok-4.6 |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | πΊπΈ US | xAI | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/x-ai/grok-4.6/endpoints β [] |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | qwen/qwen3-max |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | π¨π³ CN | Alibaba (Qwen) | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/qwen/qwen3-max/endpoints β [] |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | qwen/qwen3.6-35b-a3b |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | π¨π³ CN | Alibaba (Qwen) | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/qwen/qwen3.6-35b-a3b/endpoints β [] |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | qwen/qwen3.8-27b |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | π¨π³ CN | Alibaba (Qwen) | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/qwen/qwen3.8-27b/endpoints β [] |
| memex, memex-cloud | OpenRouter global (MeshWeaver platform key) | qwen/qwen3.8-flash |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | π¨π³ CN | Alibaba (Qwen) | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/qwen/qwen3.8-flash/endpoints β [] |
| memex, memex-cloud | Embedding (OpenAICompatible β OpenRouter global) | openai/text-embedding-3-small |
openrouter.ai | global routing (upstream Azure or OpenAI) | π Global | unknown (upstream-dependent) | πΊπΈ US | OpenAI | NOT-EU | record Embedding__Endpoint=https://openrouter.ai/api/v1; eu.openrouter.ai endpoints [] |
| memex | AzureFoundry / AzureOpenAI provider (enabled, key mounted) | (none configured) |
(endpoint "") | n/a | β Unknown | n/a | - | - | UNKNOWN | get @Provider/AzureFoundry endpoint "" models []; get @Provider/AzureOpenAI no endpoint; Features__Ai__Providers__AzureOpenAI/AzureFoundry=true; AzureFoundry__ApiKey mounted |
| memex | Claude Code CLI (user BYOK: rbuergi/_Memex/ClaudeCode) | sonnet (rbuergi/_Provider/ClaudeCode/sonnet) |
Anthropic 1P (user subscription; assumed) | Anthropic first-party | π Global | user's own Anthropic terms | πΊπΈ US | Anthropic | NOT-EU | systemorph search nodeType:ModelProvider partitions:all β rbuergi/_Memex/ClaudeCode; Features__Ai__Clis__ClaudeCode=true |
| memex | GitHub Copilot CLI (Features__Ai__Clis__Copilot=true) | (Copilot-chosen) |
GitHub Copilot (assumed) | GitHub Copilot | β Unknown | GitHub Copilot terms | πΊπΈ US | GitHub/Microsoft (+ underlying makers) | UNKNOWN | @Deployments/memex extraPortalConfig; no residency evidence gathered |
| memex-cloud | Anthropic (Claude in Foundry) β STALE mesh node | claude-opus-4-7 |
s-meshweaver.services.ai.azure.com/anthropic/ | NO such deployment on s-meshweaver (would fail); swedencentral offers GlobalStandard only | π Global | as above | πΊπΈ US | Anthropic | NOT-EU | memex search nodeType:LanguageModel partitions:all β Provider/Anthropic/claude-opus-4-7; memex get @Provider/Anthropic models [claude-opus-4-7, claude-sonnet-4-6, claude-haiku-4-5] β record [opus-5-5, sonnet-5, haiku-4-5] |
| memex-cloud | Anthropic (Claude in Foundry) β STALE mesh node | claude-sonnet-4-6 |
s-meshweaver.services.ai.azure.com/anthropic/ | NO such deployment on s-meshweaver (would fail); swedencentral offers GlobalStandard only | π Global | as above | πΊπΈ US | Anthropic | NOT-EU | memex search nodeType:LanguageModel partitions:all β Provider/Anthropic/claude-sonnet-4-6; memex get @Provider/Anthropic models [claude-opus-4-7, claude-sonnet-4-6, claude-haiku-4-5] β record [opus-5-5, sonnet-5, haiku-4-5] |
| memex-cloud | azureAis (record models: [] β provisioned, NOT offered) | Llama-4-Maverick-17B-128E-Instruct-FP8 |
fy-meshweaver3-dev-swc-001.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | Meta | NOT-EU | az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001 |
| memex-cloud | azureAis (record models: [] β provisioned, NOT offered) | cohere-command-a |
fy-meshweaver3-dev-swc-001.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | π¨π¦ CA | Cohere | NOT-EU | az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001 |
| memex-cloud | azureAis (record models: [] β provisioned, NOT offered) | Mistral-Large-3 |
fy-meshweaver3-dev-swc-001.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | π«π· FR | Mistral AI | NOT-EU | az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001 |
| memex-cloud | azureAis (record models: [] β provisioned, NOT offered) | DeepSeek-V3.2 |
fy-meshweaver3-dev-swc-001.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | π¨π³ CN | DeepSeek | NOT-EU | az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001 |
| memex-cloud | azureAis (record models: [] β provisioned, NOT offered) | gpt-5.4 |
fy-meshweaver3-dev-swc-001.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001 |
| memex-cloud | azureAis (record models: [] β provisioned, NOT offered) | gpt-5.3-codex |
fy-meshweaver3-dev-swc-001.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001 |
| memex-cloud | azureAis (record models: [] β provisioned, NOT offered) | DeepSeek-V4-Pro |
fy-meshweaver3-dev-swc-001.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | π¨π³ CN | DeepSeek | NOT-EU | az cognitiveservices account deployment list --name fy-meshweaver3-dev-swc-001 |
| memex-cloud | Speech (in-cluster whisper) | whisper-swiss-german |
whisper-swiss-german:8080 (AKS memexaks-cluster) | self-hosted pod | πͺπΊ Eu | stays in our cluster; no third party | πΊπΈ US | OpenAI (Whisper base weights; fine-tune maker not established) | EU-only | @Deployments/memex-cloud extraPortalConfig Speech__Endpoint; az aks show -n memexaks-cluster -g memex-aks-rg --subscription 7ecc5974-β¦ --query location β swedencentral |
| pearl | OpenRouter global (our platform account) | anthropic/claude-sonnet-5 |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | πΊπΈ US | Anthropic | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/anthropic/claude-sonnet-5/endpoints β ['Amazon Bedrock/amazon-bedrock/eu-west-1', 'Google/google-vertex/europe'] |
| pearl | OpenRouter global (our platform account) | openai/gpt-5.2 |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | πΊπΈ US | OpenAI | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/openai/gpt-5.2/endpoints β [] |
| pearl | OpenRouter global (our platform account) | openai/gpt-5-mini |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | πΊπΈ US | OpenAI | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/openai/gpt-5-mini/endpoints β ['Azure/azure/swedencentral'] |
| pearl | OpenRouter global (our platform account) | google/gemini-3.7-flash |
openrouter.ai | global routing (any provider) | π Global | no ZDR filter set | πΊπΈ US | NOT-EU | curl https://eu.openrouter.ai/api/v1/models/google/gemini-3.7-flash/endpoints β [] |
|
| pearl | Embedding | (not declared in record) |
? | ? | β Unknown | ? | ? | ? | UNKNOWN | record Embedding__Endpoint=https://openrouter.ai/api/v1; eu.openrouter.ai endpoints [] |
| build | (no ai block) | (none declared) |
- | - | β Unknown | - | - | - | UNKNOWN | @Deployments/build notes: "No ai block β no chat provider"; build mesh has no MCP server here |
| partnerre | AzureFoundry (models endpoint) β offered LanguageModel node | DeepSeek-V4-Pro |
partnerre-memex-ai.services.ai.azure.com/models | NO deployment of this name; account holds only GlobalStandard deployments | π Global | abuse monitoring (default) | π¨π³ CN | DeepSeek | NOT-EU | az cognitiveservices account deployment list --name partnerre-memex-ai |
| partnerre | AzureFoundry (models endpoint) β offered LanguageModel node | DeepSeek-V3-0324 |
partnerre-memex-ai.services.ai.azure.com/models | NO deployment of this name; account holds only GlobalStandard deployments | π Global | abuse monitoring (default) | π¨π³ CN | DeepSeek | NOT-EU | az cognitiveservices account deployment list --name partnerre-memex-ai |
| partnerre | AzureFoundry (models endpoint) β offered LanguageModel node | DeepSeek-V4-Flash |
partnerre-memex-ai.services.ai.azure.com/models | NO deployment of this name; account holds only GlobalStandard deployments | π Global | abuse monitoring (default) | π¨π³ CN | DeepSeek | NOT-EU | az cognitiveservices account deployment list --name partnerre-memex-ai |
| partnerre | AzureFoundry (models endpoint) β offered LanguageModel node | Kimi-K2.6 |
partnerre-memex-ai.services.ai.azure.com/models | NO deployment of this name; account holds only GlobalStandard deployments | π Global | abuse monitoring (default) | π¨π³ CN | Moonshot AI | NOT-EU | az cognitiveservices account deployment list --name partnerre-memex-ai |
| partnerre | Azure deployment (not referenced by a LanguageModel node (embedding use: not established)) | Kimi-K2.7-Code |
partnerre-memex-ai.services.ai.azure.com | GlobalStandard 20 | π Global | abuse monitoring (default) | π¨π³ CN | Moonshot AI | NOT-EU | az cognitiveservices account deployment list --name partnerre-memex-ai |
| partnerre | Azure deployment (not referenced by a LanguageModel node (embedding use: not established)) | DeepSeek-V4-Pro-0813 |
partnerre-memex-ai.services.ai.azure.com | GlobalStandard 20 | π Global | abuse monitoring (default) | π¨π³ CN | DeepSeek | NOT-EU | az cognitiveservices account deployment list --name partnerre-memex-ai |
| partnerre | Azure deployment (not referenced by a LanguageModel node (embedding use: not established)) | DeepSeek-V4-Flash-0731 |
partnerre-memex-ai.services.ai.azure.com | GlobalStandard 20 | π Global | abuse monitoring (default) | π¨π³ CN | DeepSeek | NOT-EU | az cognitiveservices account deployment list --name partnerre-memex-ai |
| partnerre | Azure deployment (not referenced by a LanguageModel node (embedding use: not established)) | gpt-5-mini |
partnerre-memex-ai.services.ai.azure.com | GlobalStandard 200 | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name partnerre-memex-ai |
| partnerre | Azure deployment (Anthropic endpoint partnerre-memex-ai/anthropic, provider models [] and no LanguageModel nodes) | claude-opus-5-5 |
partnerre-memex-ai.services.ai.azure.com | GlobalStandard 40 (v2 hostedOn azure) | π Global | abuse monitoring (default) | πΊπΈ US | Anthropic | NOT-EU | az cognitiveservices account deployment list --name partnerre-memex-ai |
| partnerre | Azure deployment (Anthropic endpoint partnerre-memex-ai/anthropic, provider models [] and no LanguageModel nodes) | claude-sonnet-5 |
partnerre-memex-ai.services.ai.azure.com | GlobalStandard 80 (v2 hostedOn azure) | π Global | abuse monitoring (default) | πΊπΈ US | Anthropic | NOT-EU | az cognitiveservices account deployment list --name partnerre-memex-ai |
| partnerre | Azure deployment (Anthropic endpoint partnerre-memex-ai/anthropic, provider models [] and no LanguageModel nodes) | claude-haiku-4-5 |
partnerre-memex-ai.services.ai.azure.com | GlobalStandard 80 (v2 hostedOn azure) | π Global | abuse monitoring (default) | πΊπΈ US | Anthropic | NOT-EU | az cognitiveservices account deployment list --name partnerre-memex-ai |
| partnerre | Azure deployment (not referenced by a LanguageModel node (embedding use: not established)) | text-embedding-3-small |
partnerre-memex-ai.services.ai.azure.com | GlobalStandard 120 | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name partnerre-memex-ai |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | o4-mini |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | gpt-4.1-mini |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | gpt-4o-mini |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | o3-mini |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | gpt-4.1 |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | gpt-4o |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | o1 |
s-meshweaver.services.ai.azure.com | DataZoneStandard | πͺπΊ Eu | abuse monitoring (default) | πΊπΈ US | OpenAI | EU-only | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | gpt-5-chat |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | gpt-5-mini |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | gpt-5-nano |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | gpt-5 |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | gpt-5.1-chat |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | embed-v-4-0 |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | π¨π¦ CA | Cohere | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | gpt-5.4 |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | πΊπΈ US | OpenAI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | Kimi-K2.5 |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | π¨π³ CN | Moonshot AI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | text-embedding-3-large |
s-meshweaver.services.ai.azure.com | Standard | πͺπΊ Eu | abuse monitoring (default) | πΊπΈ US | OpenAI | EU-only | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | DeepSeek-V4-Pro |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | π¨π³ CN | DeepSeek | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | DeepSeek-V4-Flash |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | π¨π³ CN | DeepSeek | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | Kimi-K2.6 |
s-meshweaver.services.ai.azure.com | GlobalStandard | π Global | abuse monitoring (default) | π¨π³ CN | Moonshot AI | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | DeepSeek-R1-0528 |
s-meshweaver.services.ai.azure.com | GlobalStandard (Disabled) | π Global | abuse monitoring (default) | π¨π³ CN | DeepSeek | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
| (s-meshweaver, unreferenced) | Azure AI Services deployment | DeepSeek-V3-0324 |
s-meshweaver.services.ai.azure.com | GlobalStandard (Disabled) | π Global | abuse monitoring (default) | π¨π³ CN | DeepSeek | NOT-EU | az cognitiveservices account deployment list --name s-meshweaver |
Not established by the audit
- The running pods' configuration. The records are not the pods. Overlay-only helm keys and live environments were not read.
- Embeddings on pearl and partnerre. Pearl's record declares no
Embedding__*key. partnerre has no control record; its account holdstext-embedding-3-smallGlobalStandard, which is probably the one in use, but that is not proven. - Retention. It was not checked whether any Azure account has approved modified abuse
monitoring (zero retention), whether OpenRouter has account-level ZDR or provider filters, or
what Inceptron's terms are. On GLM 5.3, the EU Mistral endpoint is tagged
nvfp4, notzdr. - Inceptron's location. OpenRouter lists it in its EU region, and that is the only basis for calling it EU.
- GitHub Copilot CLI residency was not researched, so it is
Unknown. The build instance's mesh was not reachable.
Proposed elimination (not executed)
Every change below is a record change or an Azure deployment change. Each goes through a governed
Hosting/InstanceAction / Governance/Activity on the control instance, and each needs the
maintainer's approval. Nothing here has been applied.
The target tiers, as the maintainer decided, are all served through eu.openrouter.ai on our
OpenRouter account:
| tier | model | EU providers |
|---|---|---|
| heavy | anthropic/claude-opus-5.5 |
Amazon Bedrock eu-west-1, Google Vertex europe |
| standard, review | z-ai/glm-5.3 |
Inceptron, Mistral |
| light | openai/gpt-6-luna |
Azure (eu) |
| utility | mistralai/mistral-small-2603 |
Mistral (eu) |
These apply to memex, memex-cloud and pearl. Pearl runs on our OpenRouter account, not a key of its own, and moves to the EU endpoint with the others.
partnerre is out of this scope. It uses its own OpenRouter Business account, so its models are its own to choose. They are marked the same way, with processing decided by its own route.
- Route the tiers above through the EU region. Use an
OpenRouterEUprovider section athttps://eu.openrouter.ai/api/v1, which is markedEuby its endpoint. It is config-seeded, and its chart and Hosting rendering are owned by the fleet-switch work. - Drop or mark the models with no EU route:
moonshotai/kimi-k3,openai/gpt-5.2,google/gemini-3.1-pro-preview,google/gemini-3.7-flash,deepseek/deepseek-v4-pro,x-ai/grok-4.6and every Qwen model. None of them has an EU provider on OpenRouter. The tiers above replace them; any that stay offered are markedGlobal. - Embeddings: deploy
text-embedding-3-smallas DataZoneStandard on s-meshweaver (offered in swedencentral) and pointEmbedding__Endpointthere. It is the same model, so no re-index is needed. The alternative ismistralai/mistral-embedon eu.openrouter.ai, which does need a re-index. - Claude in Foundry (memex, memex-cloud, control) has no EU zone. The heavy tier moves to
Claude through eu.openrouter.ai. Any Foundry Claude still offered is marked
Global. - Azure GlobalStandard deployments on our accounts: redeploy as DataZoneStandard where
swedencentral offers it (
gpt-5-mini,gpt-5.4,Mistral-Large-3,DeepSeek-V4-Flash2026-04-23). Mark the rest only. Delete the unreferenced s-meshweaver deployments. - Declare the marks on the records:
{Section}__DataResidencyper provider section (Anthropic__DataResidency=Global;AzureFoundry__DataResidency=Euonly once its deployments are DataZone or regional), andAI__RequiredDataResidency=Euon each instance that must be EU-only. π¨ Measured on core main: the portal chart renders none of these keys yet, and it renders noOpenRouter__EndpointorOpenRouterEU__*either. Its ConfigMap names every key explicitly, so a record that sets them reaches no container until the chart adds them.
Incidental findings from the audit, not about residency:
- partnerre's
Provider/AzureFoundryoffers four deployment names its Azure account does not have. - memex-cloud's
Provider/Anthropicstill listsclaude-opus-4-7andclaude-sonnet-4-6, which have no deployment behind them. - The records name
anthropic/claude-opus-5.5where the meshes listanthropic/claude-opus-5.