How do you govern where model providers process imported content?
Imported customer content is restricted in code to an approved model-provider path. Provider data collection is configured to be denied, and the permitted routing set is governed separately from model choice. Production routing and sub-processor disclosures still require operating review, so we do not present source policy as a universal geographic guarantee.
An agency running client sites inherits our vendor choices whether or not it sees them. That makes an undisclosed processing location a problem we would be creating for someone else.
The application has a fail-closed residency policy for imported content, while the provider account allowlist and data-collection setting are operational controls that must also be verified.
The public sub-processor list and provider agreements must be reconciled with the live routing configuration before making a geographic processing claim.
What this answer is based on
- Sub-processor disclosure and data-boundary policy
Related answers
Last updated August 3, 2026