Subprocessors & upstream providers
This page lists Provider’s infrastructure subprocessors and certain customer-selected upstream LLM providers that may receive Customer Content when Customer selects, enables, configures, provides credentials for, or routes traffic to the relevant provider or model.
A “Subprocessor” is a third party engaged by Provider to process Customer Personal Data on Provider’s behalf in connection with hosting, operating, securing, supporting, or maintaining the Routero AI service (“Service”).
Unless expressly stated otherwise in an Order Form or Data Processing Addendum, customer-selected upstream LLM providers are not Provider’s infrastructure subprocessors. Their data handling, retention, training-on-data, security, data residency, and cross-border transfer practices are governed by their own terms, privacy policies, data-processing terms, and Customer-selected settings.
Self-hosted operators of Routero AI will have a different list. Operators should publish their own Subprocessors page reflecting their actual stack.
Customer-selected Upstream LLM Providers
When Customer routes traffic through the Service, the prompt, context, metadata, and other request information may be forwarded to the upstream LLM provider selected, enabled, configured, or credentialed by Customer for the relevant model or route.
These upstream LLM providers are third-party services selected or configured by Customer. Unless expressly agreed otherwise in an Order Form or Data Processing Addendum, they are not Provider’s infrastructure subprocessors. Their data handling, retention, training-on-data, security, data residency, and cross-border transfer practices are governed by their own terms, privacy policies, data-processing terms, and Customer-selected settings. Customer is responsible for reviewing each provider’s terms and determining whether the provider is appropriate for Customer’s use case and legal obligations.
The following providers are configured as supported destinations in the active deployment (supported_providers.json):
| Upstream LLM Provider | Endpoint | Purpose | Provider's data handling |
|---|---|---|---|
| OpenAI | https://api.openai.com/v1 | Chat completions, embeddings, etc. | per OpenAI's terms and DPA |
| Anthropic | https://api.anthropic.com | Chat completions | per Anthropic's terms |
| DeepSeek | https://api.deepseek.com/v1 | Chat completions | per DeepSeek's terms |
| Alibaba DashScope (International) | https://dashscope-intl.aliyuncs.com/compatible-mode/v1 | Chat completions, embeddings | per Alibaba Cloud terms |
| Google Gemini | (varies) | Chat completions, embeddings, multimodal | per Google AI / Cloud terms |
| xAI | https://api.x.ai/v1 | Chat completions | per xAI's terms |
| ByteDance BytePlus (Asia-Pacific) | https://ark.ap-southeast.bytepluses.com/api/v3 | Chat completions | per BytePlus terms |
| Mistral | https://api.mistral.ai/v1 | Chat completions | per Mistral's terms |
The underlying LiteLLM SDK supports 100+ additional providers; an operator can enable any of them. Customer is responsible for verifying each provider's privacy posture, including whether the provider trains on submitted data and whether opt-outs are available. Where opt-outs exist (e.g., OpenAI's "do not train" toggle, Anthropic's enterprise terms), Customer should exercise them to match Customer's risk posture.
Infrastructure Subprocessors
These providers process Customer Personal Data in connection with hosting and operating the Service.
| Subprocessor | Region | Purpose | Personal Data category |
|---|---|---|---|
| Amazon Web Services, Inc. | ap-southeast-1 (Singapore) | Compute (ECS Fargate), database (RDS PostgreSQL), cache (ElastiCache Redis), TLS load-balancing (ALB), object storage (S3 — used only for Terraform state and container artefacts), email delivery (SES), DNS (Route 53 for env subdomains), logging (CloudWatch), secret storage (KMS / IAM) | All categories — AWS hosts the database where account data, audit logs, and (where enabled) prompts and responses are stored. |
| Cloudflare, Inc. | global | Apex DNS hosting for routero.ai. No Customer Content traverses Cloudflare in the current deployment — Cloudflare provides DNS resolution only for the apex domain; the env subdomains (platform.routero.ai, platform-uat.routero.ai, platform-sandbox.routero.ai) delegate to AWS Route 53. | DNS metadata only |
Optional / operator-configured Subprocessors
Routero AI's codebase includes integrations with many observability, billing, and analytics platforms. These are off by default in the active configuration. If the operator enables any of them, the Subprocessors list must be updated before Customer Content reaches them.
Examples of integrations available in the codebase but not currently active:
- Observability: Langfuse, Helicone, Datadog, Braintrust, Galileo, Argilla, Greenscale
- Storage: Google Cloud Storage, AWS S3 (for log shipping), DynamoDB
- Notification: Slack
- Billing/usage: Lago
Operators must update this list when activating any of these.
Notice of changes
We will provide Customer with at least thirty (30) days’ prior notice of any new Subprocessor that will process Customer Personal Data on Provider’s behalf, by updating this page and/or emailing the address on Customer’s account where required by the DPA. Customers may object to a new infrastructure Subprocessor on reasonable data-protection grounds as set out in the Data Processing Addendum.
We may add, remove, suspend, or modify available upstream LLM providers from time to time. Customer Content is transmitted to an upstream LLM provider only when Customer selects, enables, configures, or routes traffic to that provider or model. Customer is responsible for reviewing the applicable provider terms before using a newly available upstream LLM provider.
Contact
Subprocessor enquiries: privacy@routero.ai