Zero Data Retention LLM API — Verifiable in Source
Zero data retention as a structural property of the open-source code, not just a contract clause. Multi-provider routing with the same posture.
Zero data retention as a verifiable property, not a contract clause.
"ZDR" usually means a clause in your enterprise agreement. The operator promises not to retain. You hope they comply.
TrustedRouter's ordinary synchronous and streaming prompt path does not write request or response bodies to persistent storage. Batch is a separate opt-in encrypted-retention mode. The code that handles your prompts is open-source. The image hash is published. You can verify the real-time path without trusting us.
# Per-request record (token counts, timing, model id)
{
"request_id": "req_...",
"workspace_id": "...",
"model_id": "anthropic/claude-sonnet-4.6",
"input_tokens": 12,
"output_tokens": 84,
"cost_microdollars": 218,
"provider": "anthropic",
"region": "us-central1",
"created_at": "..."
}
# What's NOT in here:
# - prompt body
# - response body
# - user inputs of any kind
# Audit the schema:
# github.com/.../storage_models.py
Zero, by construction.
The attested binary doesn't open a write handle to a prompt path. The retention isn't a policy choice; it's a structural property of the code.
Check it yourself.
Grep the source for any code that touches request bodies. There isn't any. The image hash you build is the hash the enclave reports.
Including upstream where possible.
For providers with their own ZDR posture (Anthropic, OpenAI Enterprise, Tinfoil, GCP Confidential), we route under their stronger guarantees and surface that on each model page.
What ZDR doesn't cover.
Upstream providers have their own retention behavior. We can route to providers that match your posture and we publish each one's known stance on the model pages.
Attestation proves the running binary is the published binary. It doesn't prove the binary is bug-free.
If you can't trust the GCP Confidential Space attestation chain at all, hosted attestation doesn't save you. Self-hosting lets you pin and publish your own image digest under your own controls.
Current routes, prices, privacy, and measured performance.
Catalog facts come from the routes currently configured in TrustedRouter. Performance uses the same cached metadata snapshot as the public leaderboard. Prompts and outputs are not part of these measurements.
| Model | Providers | Context | Input | Output | Privacy | Measured route |
|---|---|---|---|---|---|---|
Anthropic: Claude Opus 4.8anthropic/claude-opus-4.8 |
3 routes | 1,000,000 | $5.25/1M | $26.25/1M | varies 5 cited scores | 2886 ms TTFT anthropic · 58 tok/s · 100.00% available · n=5 |
OpenAI: GPT-5.5openai/gpt-5.5 |
4 routes | 1,050,000 | $5.25/1M | $31.5/1M | ZDR 3 cited scores | 2180 ms TTFT openai · 100.00% available · n=5 |
Google: Gemini 3.5 Flashgoogle/gemini-3.5-flash |
7 routes | 1,048,576 | $1.575/1M | $9.45/1M | ZDR | 1997 ms TTFT google-ai-studio · 100.00% available · n=17 |
MoonshotAI: Kimi K2.7 Codemoonshotai/kimi-k2.7-code |
19 routes | 262,144 | $0.735/1M to $0.9975/1M | $3.675/1M to $4.2/1M | ZDR 5 cited scores | 1485 ms TTFT inceptron · 100.00% available · n=45 |
Z.ai: GLM 5.2z-ai/glm-5.2 |
45 routes | 1,048,576 | $0.714/1M to $1.575/1M | $1.575/1M to $5.5125/1M | E2EE 4 cited scores | 4152 ms TTFT parasail · 29 tok/s · 97.44% available · n=231 |
MiniMax: MiniMax M3minimax/minimax-m3 |
21 routes | 1,048,576 | $0.2835/1M to $0.63/1M | $1.155/1M to $2.52/1M | ZDR 4 cited scores | 1785 ms TTFT minimax · 69 tok/s · 100.00% available · n=41 |
Browse every modelReview provider policiesOpen the full leaderboardSnapshot 2026-08-07T04:33:46Z