Skip to main content
Opper is certified to ISO/IEC 27001:2022 and hosted in the EU, in Stockholm. Opper does not train on your data, keeps prompts and outputs in traces only for the retention period set in Rules (none on the Gateway plan), and can enforce EU-only inference and zero data retention for every call in your organization. Files you upload or store are kept until you delete them. Certificates, policies, and the current sub-processor list are on the trust center at trust.opper.ai. Security covers the gateway and the platform. The AI Gateway decides where calls can go at request time, and the platform is how everything underneath is hosted and protected. This page covers both.

Certifications

The certificate and Opper’s security policies are available at trust.opper.ai.

EU-hosted by default

Opper’s primary production environment runs in AWS Stockholm (eu-north-1), with a second production environment at evroc, also in Stockholm. Opper’s own data (traces, usage records, stored files, and backups) is hosted there. The one thing that leaves Opper’s footprint is the model call itself, and you can constrain even that at the gateway. Use model access rules to:
  • Restrict calls to EU routes, by inference location and by where providers store content
  • Pin specific countries that calls can route to
  • Require provider data practices, including the Zero data retention policy
The gateway refuses any call that violates these rules before it leaves the platform. See Keep AI inference in the EU and Enforce zero data retention. If your policy requires European ownership at every hop, not only EU hosting, Opper also runs as a separate sovereign instance on evroc, the Swedish cloud. See Sovereign AI.

We don’t train on your data

Opper never uses customer data to train models, and never shares it with providers for training.

What each plan includes

On every plan, Opper keeps a usage record for each call (cost, tokens, latency, status, provider, model, and any X-Opper-Tags, with no prompts or responses) for 5 years, for billing. Logs lists these records call by call. See opper.ai/pricing for prices.

Configure Opper storage and provider data requirements

Opper trace storage is controlled by Opper retention. With no applicable enabled retention rule, Opper records usage metadata but does not store traces. With tracing on, spans, inputs, and outputs are kept for the effective retention period, up to 30 days. Check your organization’s saved rules to see each project’s effective period. Provider data requirements are set separately, in Model access. Neither setting configures the other: turning Opper tracing off does not restrict providers, and selecting a provider data policy does not turn Opper tracing off. Enforce zero data retention walks through setting both.

One sub-processor for every model

Most AI vendors require a separate DPA amendment for every model provider you turn on. Opper doesn’t. Opper is your one AI sub-processor, so you can add or remove models without rewriting contracts.
  • Opper’s platform sub-processors, with their purpose and location, are listed on the trust center at trust.opper.ai.
  • Model providers are listed at opper.ai/providers, with each provider’s locations, training and logging practices, and DPA status. You choose which ones your calls can reach with model access.
With an EU-only model access rule, model calls run only on EU routes and Opper’s own storage stays in Stockholm, so prompts and outputs are processed in the EU.

Encryption

  • At rest: AWS RDS with KMS-managed keys. Uploaded files use S3 SSE-S3.
  • In transit: TLS on every public endpoint.
  • Backups: encrypted in AWS Backup. Daily snapshots kept 5 weeks, weekly snapshots 14 months. Only Opper engineers can restore.

Data isolation

Each organization’s data is isolated at the application layer. Uploaded files live in a private S3 bucket with objects segregated per organization. Service-to-service traffic is restricted to a private AWS VPC.

Deletion

  • Delete a project → all associated traces and events are removed.
  • Set Opper retention to 0 → new calls do not store traces. Existing traces keep their original expiry dates.
  • Uploaded files persist until you delete them (DELETE /v3/files/{id}, or an expiry you set). Scopes with an enabled 0-day Opper retention rule can’t hold files: uploads are rejected, and existing files are scheduled for permanent deletion after you confirm the file count and save. A provider data policy in Model access does not trigger file deletion by itself.

DPA and contact

Standard DPA and Standard Contractual Clauses are available on request. Contact hello@opper.ai.

Controls that put this in your code

Keep AI inference in the EU

Enforce EU-only inference and storage for every call.

Enforce zero data retention

Store no content at Opper and allow only providers that neither train on nor log it.

Model access

Restrict which providers, regions, and models calls can reach.

Opper retention

Choose how long content is kept, or keep none of it at all.

Checks

Block or redact sensitive content before the model sees it.

Spend limits

Cap what an organization can spend in a calendar month.

Models

See which models you can reach, and which ones are EU-hosted.

Models

The full catalog, with EU-hosted models marked.

Apps

Use Opper as the provider for your editor, agent, or CLI.
Last modified on October 7, 2026