OpenAI compatible API · Attested · Public status

HIPAA-Compatible LLM Routing — TrustedRouter

An auditable LLM API for HIPAA covered entities. Attested gateway, open-source routing code, no prompt logs by construction.

Verify gateway
Onebase URL to migrate
100sof models and routes
0prompt or output logs. Always.
HIPAA-compatible LLM routing

The LLM API whose privacy posture is verifiable, not just contractual.

HIPAA covered entities and their business associates can't legally route PHI through a service whose data-handling claims they can't audit.

TrustedRouter's prompt path runs inside a hardware-attested gateway. The source is open. The image hash is published. Privacy isn't promised — it's checkable.

Security architecture Try in playground

Verify the gatewaycurl
# Live attestation, bound to a nonce
NONCE=$(openssl rand -hex 16)
curl -s "https://api-azure.trustedrouter.com/attestation?nonce=$NONCE"

# Returns a JWT signed by the CPU's root key.
# image_digest matches the artifact published at
# trustedrouter.com/security — verifiable end to end.
No retention

Prompts and outputs aren't stored.

The attested binary never writes request or response bodies. Token counts and metadata only. The schema is in source.

Verifiable

Read the code that handles PHI.

Every byte that touches a prompt body flows through open-source code you can audit. Your security team doesn't have to take our word.

Multi-provider

Route to providers with strong posture.

Anthropic Claude, GPT-5, Gemini, Llama via Tinfoil, GLM, DeepSeek — pick by published per-provider retention and ZDR status.

What HIPAA buyers actually need

Verifiability beats audit theater.

An auditable prompt path. Open source lets your security team trace exactly what happens to PHI from request entry to provider hand-off. No reverse engineering.

Provider transparency. Each model page publishes the upstream provider's posture — zero-retention contracts, confidential compute, end-to-end encryption claims — with links to source. You route deliberately.

BAA where it matters. Direct BAAs with TR + the upstream provider you select. The attestation gives you what BAAs can't: cryptographic proof of which code processed a specific request.

Fail-closed gateway. If attestation can't verify, the gateway stops accepting requests. There is no degraded mode that processes PHI without proof.

Self-host option. Run the same open-source gateway inside your own VPC. Same image hash, same attestation chain, same verifiability.

Honest scope

What attestation doesn't cover.

Attestation proves the running binary is the published binary. It doesn't prove the binary is bug-free — open-source code can have flaws and we welcome reports.

It doesn't bypass nation-state actors with physical access to the cloud provider. The threat model is "operator can't see PHI" + "code is what was published," not "absolute secrecy from all adversaries."

Upstream providers handle prompts according to their own policies. We publish each one's posture on the model pages so you can route accordingly.

Live catalog evidence

Current routes, prices, privacy, and measured performance.

Catalog facts come from the routes currently configured in TrustedRouter. Performance uses the same cached metadata snapshot as the public leaderboard. Prompts and outputs are not part of these measurements.

392public models
49providers
1270configured routes
250ZDR routes
8provider E2EE routes
1071recent availability samples
Model Providers Context Input Output Privacy Measured route
Anthropic: Claude Opus 4.8anthropic/claude-opus-4.8
3 routes
1,000,000 $5.25/1M $26.25/1M varies 5 cited scores 1598 ms TTFT anthropic · 100.00% available · n=5
OpenAI: GPT-5.5openai/gpt-5.5
4 routes
1,050,000 $5.25/1M $31.5/1M ZDR 3 cited scores Warming up
Google: Gemini 3.5 Flashgoogle/gemini-3.5-flash
+1
7 routes
1,048,576 $1.575/1M $9.45/1M ZDR measured google-ai-studio · 0.00% available · n=14
MoonshotAI: Kimi K2.7 Codemoonshotai/kimi-k2.7-code
+8
19 routes
262,144 $0.735/1M to $0.9975/1M $3.675/1M to $4.2/1M ZDR 5 cited scores measured inceptron · 0.00% available · n=16
Z.ai: GLM 5.2z-ai/glm-5.2
+22
45 routes
1,048,576 $0.714/1M to $1.575/1M $1.575/1M to $5.5125/1M E2EE 4 cited scores 2657 ms TTFT phala · 100.00% available · n=91
MiniMax: MiniMax M3minimax/minimax-m3
+8
21 routes
1,048,576 $0.2835/1M to $0.63/1M $1.155/1M to $2.52/1M ZDR 4 cited scores 2056 ms TTFT wafer · 100.00% available · n=24
AnthropicPolicy varies 12 models 1807 ms p50 · n=27
GMI CloudPolicy varies 53 models 2549 ms p50 · n=16
OpenAIZDR on prepaid 33 models 1337 ms p50 · n=29
Atlas CloudPolicy varies 73 models measured · n=25
Google AI StudioPolicy varies 11 models measured · n=28
Google Vertex AIZDR on prepaid 9 models measured · n=29
Lightning AIPolicy varies 17 models 1429 ms p50 · n=26
KimiPolicy varies 11 models 1365 ms p50 · n=26

Browse every modelReview provider policiesOpen the full leaderboardSnapshot 2026-08-05T03:33:05Z

Workspace access

Sign in

Choose a sign in method to access your TrustedRouter workspace.

By signing in you agree to the terms of service and privacy policy.