Routing with residency enforcement
Menu Items is a routing layer. It does not host models. It reads what a request contains, determines which providers are legally eligible, then picks the best one left. The boundary is applied before selection on every call.
Decision record
req_01JQ…- Jurisdiction
- CN · PIPL
- Payload class
- regulated
- 01
data_class = health_record
CN resident endpoints only
In regioncn-beijing
- 02
model = deepseek-v4-pro
2 endpoints pass policy
In regioncn-beijing
- 03
candidate = ap-southeast-1
Excluded, outside jurisdiction
Refused - 04
candidate = zai/glm-5.3
Excluded, region undisclosed
Refused - 05
selected
deepseek-v4-pro via cn-beijing
In regioncn-beijing
Only endpoints inside the jurisdiction were eligible, so price never selected an endpoint outside the requested jurisdiction.
- 5
- Steps between request and endpoint
- 0
- Cross-border fallback paths
- 404
- Status when the eligible set is empty
- Per-request
- Reason recorded for every selection
They do not exist
Pipeline
Request to endpoint
Five steps run in a fixed order. Reordering them changes the product's legal behaviour, so the order cannot be configured.
Read the payload
The router extracts data class, modality, jurisdiction, requested model, context length, tool use and streaming requirement from the request and its declared context. It does not infer them from the endpoint that receives the call.
Resolve the jurisdiction
A jurisdiction attaches at the key, workspace or individual call, in that order of precedence. The caller's network location is not used.
Remove ineligible providers
Endpoints outside the declared jurisdiction are excluded before prices or latency are compared.
Order what remains
The router ranks eligible endpoints by price and latency, then considers cache state and context fit. Each input describes an endpoint that policy has already approved.
Selection and refusal
The best-ranked endpoint is selected and the decision is recorded. If no endpoint remains, the request fails with the constraint that emptied the set. The router does not widen the candidate set after that.
Signals
Payload signals
Only the listed inputs can remove a provider. The router never infers them from network location.
| Signal | Where it is read from | What it does to the candidate set |
|---|---|---|
| jurisdiction | Declared at key, workspace or call | Removes every provider outside the jurisdiction |
| data_class | Declared per request or per route | Selects which jurisdiction rules apply at all |
| modality | From content parts in the request | Excludes endpoints that cannot serve the input type |
| context_length | Computed from the assembled prompt | Excludes endpoints whose window cannot hold it |
| tool_use | From declared tools and tool history | Excludes endpoints without tool support, and flags hops |
| streaming | From the request | Excludes endpoints that cannot stream in-region |
The gate
Residency gate
The residency gate sits between steps three and four. Price comparisons and endpoint ranking occur only after it.
| Request class | JP | KR | SG | MY | HK | TW | CN | Unbound |
|---|---|---|---|---|---|---|---|---|
| Regulated personal data | Route | Route | Route | Route | Route | Route | Route | |
| Customer records, any modality | Route | Route | Route | Route | Route | Route | Route | |
| Source code | Route | Route | Route | Route | Route | Route | Route | Conditional |
| Public web text | Route | Route | Route | Route | Route | Route | Route | Route |
| Synthetic or test data | Route | Route | Route | Route | Route | Route | Route | Route |
“Conditional” means the request is served only when the endpoint publishes a verifiable region. If the provider publishes none, the entry is ineligible. The catalogue records this policy.
Failure
Failure behaviour
If no eligible endpoint remains, the request fails immediately without a cross-border retry.
The request fails immediately. The router does not retry against a provider outside the jurisdiction because that provider was never a candidate. Refusals are counted with successful traffic.
When a provider degrades
Failover retries against other providers that pass the same policy. The pool can shrink but cannot cross a border. Operators plan capacity within that boundary.
Boundaries of the claim
Router limits
Compliance remains your responsibility
The router enforces the routing rules you configure and records what it did. Filing obligations and consent remain yours. So do impact assessments.
Unpublished regions cannot be verified
Where a provider publishes no serving region, the catalogue marks it unverified and the request is refused. We do not infer a region from a latency measurement or a support page.
Providers run the compute
Menu Items routes to providers that run the compute. The catalogue lists coverage gaps.
Some wanted traffic will be refused
Some traffic will be refused.
Compared
Gateway comparison
The gateway column is an illustrative routing scenario. Menu Items records where a request ran and why it was allowed.
Example gateway with a provider list
- Region is a deployment setting
- Fallback widens the pool when something degrades
- Compliance is documented after the fact
- Coverage gaps surface as production errors
- Region is a property of every request
- Fallback is confined to eligible providers
- Each request records the enforcement decision
- Coverage gaps are published in the catalogue
Jurisdictions
Regions where enforcement is live
Try it
Account enquiries
Accounts are billed from the first request.