Who runs where, and under whose law
The same model on another cloud has a different legal position. Partner-operated regions have a different counterparty. The catalogue records both infrastructure and operator.
Every provider in the catalogue
The routing verdict says what happens to a jurisdiction-bound request, including cases where no residency can be guaranteed.
Providers, home jurisdiction and resident operations| Provider | Home | Resident operations | Models | Routing verdict |
|---|
| DeepSeek | CN | CN | 2 | CN-bound requests are served in-country. The provider publishes no region code below country level. |
| Alibaba Qwen | CN | CNHKJPSGUSEU | 3 | CN-bound requests use mainland regions and do not route abroad. |
| Moonshot AI (Kimi) | CN | CNSGJPEUUS | 3 | CN-bound requests route to cn-beijing or cn-hongkong; the US Bedrock profile cannot serve them. |
| Z.ai (GLM) | CN | CNSG | 3 | No serving region is published, so a jurisdiction-bound request cannot be guaranteed against this provider; the catalogue records that gap. |
| MiniMax | CN | CN | 2 | Cloud vendor and region are undisclosed, so region-bound requests are refused. |
| StepFun | CN | CN | 3 | No region mapping is published; the catalogue records the gap. |
| Tencent Hunyuan | CN | CNSG | 2 | CN-bound requests are served from ap-guangzhou; Singapore cannot serve them. |
| ByteDance (Doubao / Seed) | CN | CNSG | 3 | CN-bound requests are served from cn-beijing. Pricing is published in CNY, so rates are recorded as unverified. |
| Baidu ERNIE | CN | CN | 3 | CN-bound requests are served from cn-beijing. No public region exists outside mainland China, so other jurisdictions cannot be served. |
| DeepSeek on AWSCross-border | CN | None verified | 1 | Unverified. Gap recorded. A request bound to CN or JP cannot route here until an in-region endpoint is confirmed. |
| DeepSeek on GCPCross-border | CN | None verified | 1 | Structurally unavailable for CN-bound traffic. The catalogue includes it to show this coverage gap. |
| Qwen on AWSCross-border | CN | None verified | 1 | Unverified. Eligible after an in-region AWS endpoint is confirmed for the requested jurisdiction. |
| OpenAI | US | USEU | 3 | US- and EU-bound requests are servable; no East Asian in-region endpoint is documented. |
| Anthropic | US | US | 3 | US-bound requests are servable from a named region. Global endpoints may route dynamically; this endpoint is regional. |
| Google (Gemini) | US | USJPKRTWSGEU | 4 | A global endpoint does not identify a region. Physical residency is unverified for these models, so region-bound requests are refused. |
| Meta (Llama) | US | US | 2 | US-bound requests are servable. The open weights can also be hosted inside a stricter boundary. |
| Mistral AI | EU | EU | 3 | EU is selectable, but region-level verification is unavailable and the verdict states that limit. |
| xAI (Grok) | US | US | 2 | US- and EU-bound requests are servable from named regions; no East Asian region is published. |
8 of 18 providers do not publish a serving region or exact region code. Those entries cannot take jurisdiction-bound traffic. The catalogue records the unpublished fields.
A partner-operated region has a different counterparty
When a foreign cloud operates in-country through a domestic company, the contract, control plane and support path change. A compliance review needs those details on the record.
Cloud structures and local partners| Cloud | Regions | Operated by | What a reviewer needs to know |
|---|
| AWS China | cn-north-1 · cn-northwest-1 | Beijing Sinnet Technology (Beijing), Ningxia Western Cloud Data (Ningxia) | Separate accounts and control plane from global AWS, with ICP filing and product-availability differences. |
| Azure China | chinaeast2 and others | Shanghai Blue Cloud Technology (21Vianet) | Physically separated and independently operated and transacted. Feature parity with global Azure is not guaranteed. |
| Google Cloud | none in mainland China | - | No public mainland region appears in Google's own region inventory. Offices and points of presence are not regions. |
| AWS global | ap-northeast-1 · ap-northeast-2 · ap-east-2 | AWS-operated | Direct regions in Japan, Korea and Taiwan. Service-level residency and control-plane behaviour still require checking per service. |
| Azure global | japaneast · japanwest · koreacentral | Microsoft-operated | No Azure region in Taiwan was identified; edge and partner capacity is not a region. |
| Google Cloud global | asia-northeast1 · asia-northeast3 | Google-operated | Tokyo and Seoul compute regions. Regional data-location controls are service-specific. |
| Domestic operators | Alibaba Cloud · Tencent Cloud · Huawei Cloud · Baidu AI Cloud | Locally operated | Mainland regions and contracts are distinct from the international surfaces of the same brands. |
| Korean and Japanese providers | NAVER Cloud · KT Cloud · Sakura Internet · SoftBank | Locally operated | Domestic facilities documented; not every provider publishes a stable public region code, which is why some entries show none. |
Each jurisdiction's rule and the router's response
These entries follow documented law and observed infrastructure. They are not legal advice.
JP
Japan
APPI · Act on the Protection of Personal InformationTransfer requirement
Transfer of personal data to a third party in a foreign country requires prior opt-in consent that identifies the receiving country, unless the destination is on the adequacy allow-list or the recipient maintains equivalent measures.
Router behaviour
Requests bound to JP run in Japanese regions. A provider without Japanese capacity cannot serve the request, regardless of price.
Regions that satisfy this jurisdiction in the catalogue
ap-northeast-1ap-northeast-3jp-east-1
KR
South Korea
PIPA · Personal Information Protection ActTransfer requirement
Cross-border transfer generally requires the data subject's consent, with disclosure of the recipient, purpose and retention; certification and adequacy routes exist for qualifying transfers.
Router behaviour
Requests bound to KR run in Korean regions. If a model has no Korean endpoint, the request fails closed and the gap is reported as a coverage fact.
Regions that satisfy this jurisdiction in the catalogue
ap-northeast-2kr-seoul-1
SG
Singapore
PDPA · Personal Data Protection Act, Transfer Limitation ObligationTransfer requirement
An overseas recipient must be bound to a standard of protection comparable to the Act's, in practice through a legally binding instrument such as the ASEAN model contractual clauses or binding corporate rules accepted under the trustmark route; this obligation is contractual rather than approval-based.
Router behaviour
Requests bound to SG run in Singapore regions. The contractual route governs liability, while in-country routing governs where the bytes actually rest.
Regions that satisfy this jurisdiction in the catalogue
ap-southeast-1sg-singapore-1
MY
Malaysia
PDPA · Personal Data Protection Act 2010, as amendedTransfer requirement
Personal data may not be transferred outside Malaysia unless the destination affords a comparable level of protection or a listed exception applies; whitelist, consent and contractual routes are used in practice, and the cross-border provisions were tightened by the 2024 amendment.
Router behaviour
Requests bound to MY run in Malaysian regions when capacity exists. If it does not, the request is refused rather than sent to a neighbouring region.
Regions that satisfy this jurisdiction in the catalogue
ap-southeast-5my-kuala-lumpur-1
HK
Hong Kong
PDPO · Personal Data (Privacy) OrdinanceTransfer requirement
There is no blanket prohibition on cross-border transfer. The data user must take all reasonable precautions and exercise due diligence that the data is not exposed to unauthorised or accidental access abroad.
Router behaviour
Requests bound to HK run in Hong Kong regions. The decision records the duty of care instead of assuming it from a provider's name.
Regions that satisfy this jurisdiction in the catalogue
ap-east-1hk-hongkong-1
TW
Taiwan
PDPA · Personal Data Protection ActTransfer requirement
International transfer may be restricted or prohibited where it would prejudice national interests or where the recipient's protections are inadequate; sectoral rules add further constraints.
Router behaviour
Requests bound to TW prefer Taiwanese regions. If no in-country option exists, a foreign endpoint is refused.
Regions that satisfy this jurisdiction in the catalogue
ap-northeast-1tw-north-1
CN
China
PIPL · Regulations on Facilitating and Regulating Cross-border Data TransfersTransfer requirement
Cross-border transfer of personal information requires one statutory mechanism, a CAC security assessment, standard-contract filing, or certification, together with separate consent and a personal-information protection impact assessment; exemptions cover limited-volume and non-personal scenarios.
Router behaviour
Requests bound to CN run only through providers operating inside mainland China. If no in-country endpoint serves the requested model, the request is refused rather than routed abroad.
Regions that satisfy this jurisdiction in the catalogue
cn-north-1cn-northwest-1cn-hangzhoucn-beijingcn-shanghaicn-guangzhou
US
United States
Sectoral federal and state privacy lawTransfer requirement
No single federal transfer regime; obligations arise from sector rules and state law. US in-region routing is offered for parity with the incumbent, not as the product's differentiator.
Router behaviour
Requests bound to US are decrypted and processed in US regions, where only US-running providers are eligible.
Regions that satisfy this jurisdiction in the catalogue
us-east-1us-east-2us-west-2
EU
European Union
GDPR · Chapter VTransfer requirement
Transfers outside the EEA require an adequacy decision or appropriate safeguards such as standard contractual clauses, with a transfer impact assessment.
Router behaviour
Requests bound to EU run in EEA regions only.
Regions that satisfy this jurisdiction in the catalogue
eu-central-1eu-west-1eu-north-1
How these facts were established
- 01
Provider documentation first
Model facts, prices and context windows come from providers' documentation, pricing pages and release notes. When a provider quotes only local currency, the USD field remains unverified; we do not convert it with an unsourced rate.
- 02
Cloud region inventories for location
Physical locations come from cloud providers' region inventories and compliance pages. We do not infer them from claims about market presence.
- 03
Absence is recorded as absence
Where no region code or partner could be established, the entry carries unverified. 18 catalogue entries currently contain at least one such field.
- 04
Observation dates
Every page gives the observation date. Regions and prices change.
Dated 4 Oct 2026Not legal advice
How providers are grouped
Featured
9
Current China-based labs, prioritised in this catalogue.
Cross-border deployments
3
The same weights served by different infrastructure, which is a different legal position.
Included
6
Frontier and open-weight models from European and American labs.
Coverage gap in a specific jurisdiction?
Start
Jurisdiction-bound API access