Skip to main content
Opper is hosted in the EU, in Stockholm. Where a model call runs depends on the route it uses, and you can keep inference in the EU in two ways:
  • Per call, on any plan. Call an EU route, such as azure/gpt-5.5 (Sweden) or mistral/mistral-large-2512 (France). That call runs in the EU.
  • For your whole organization, on the Control Plane plan. A Model access rule with Inference location and Storage location set to EU. It is an account-level lock, not a filter in a model picker: Opper refuses every call to a route outside the EU with 403 before the request leaves Opper, whichever API key, SDK, or app sends it.

Where your data is processed

Every route in the catalog records two locations:
  • Inference location: where the model runs.
  • Storage location: where the provider keeps any content it retains, such as logs or content held for moderation. A route that retains nothing passes any storage requirement. A route that retains content without a recorded storage location counts as GLOBAL and fails an EU storage requirement.

Enforce EU-only for your organization

In the Opper platform, open Rules → Model access:
1

Start an organization allowlist

Select Set an org allowlist, or edit the existing one.
2

Set the locations

Set Inference location to EU and Storage location to EU. Use EEA instead to also allow Norway, Iceland, and Liechtenstein, or pick individual countries.
3

Review and save

Select the match counter to review the models that remain, then select Save changes. The rule applies from the next request.
The same rule through the Management API:

What the rule covers

  • Every model call: text generation, embeddings, image generation, speech, transcription, video, OCR, realtime voice, and rerank.
  • Every API key and project in the organization. A project override can narrow the rule further, but cannot allow a location the organization rule excludes.
  • Routes without a recorded location. A route with no recorded inference location, or one that retains content with no recorded storage location, counts as GLOBAL and is refused.
Inference location says where a model runs, not who operates it. Several EU routes are run by companies headquartered outside the EU, such as Azure and AWS in Sweden. To restrict by the operator’s or the model maker’s home country as well, add Provider country or Maker country to the same rule.

What a blocked call returns

A call to a route outside the EU is refused with 403 before anything reaches the provider. On chat completions:
Other endpoints return the same message in their own error shape. See What a blocked call returns.

Bare model names mix regions

A bare model name is served by a pool of routes, and a pool can span regions. In September 2026, claude-sonnet-4-6 was served from these five routes: Under that rule, a call to claude-sonnet-4-6 runs only on the routes that pass and skips the rest. Without a rule, it can run on any of them. To keep a single call in the EU without a rule, pin an EU route such as aws/claude-sonnet-4-6-eu.

Find EU routes

  • Browse: opper.ai/models/eu, or the machine-readable opper.ai/models/eu.json.
  • Query the catalog without an API key:
    inference_location and storage_location match the same way as the Rules page, so the result is what a rule with the same settings allows. limit=0 returns every match and total gives the count. Add &training=no&logging=none for routes that are both EU and zero data retention.

EU and zero data retention together

EU residency and zero data retention are separate requirements, and one rule can hold both: set the locations above and set Provider data policy to Zero data retention. See Enforce zero data retention for what that policy covers.

Enforce zero data retention

Store no content at Opper and allow only providers that neither train on nor log it.

Model access

Every allowlist field, error body, and override.

Security

Certifications, hosting, DPA, and sub-processors.

Dynamic routes

Route across EU models by price, latency, or throughput.
Last modified on September 29, 2026