Residency and regions

Four distinct classes for ownership, operation and location. They are not interchangeable and do not confer immunity from legal disclosure obligations.

EU-owned, EU-operated
An EU company owns and operates the infrastructure in the EU. A classification, not a legal guarantee against disclosure.
EU region of a non-EU parent
Processing in an EU region, but the parent company is outside the EU. The location is European; the jurisdiction is not exclusively so.
On premises at the customer
The model runs inside infrastructure the customer controls.
Catalogue entry, hosting not documented
A catalogue entry with no LLM EU inference. Its processing location is unverified.

These four labels replace the bare word sovereign, which we do not use on its own. A model is called sovereign only with its class and region beside it, because ownership, operation and jurisdiction are three different facts.

Regions in the catalogue

Region rows are configuration data, not evidence of running machines or confirmed operator contracts. Seeded endpoints use the mock: dev-mock, no model weights run. Real inference requires a configured backend per region and matching endpoints. Region configuration is not independent geolocation.

RegionCountryClassOperator (configuration)
de-berDE EU-owned, EU-operated llmeu
de-fraDE EU-owned, EU-operated llmeu
eu-ownedEU EU-owned, EU-operated llmeu
eu-regionEU EU region of a non-EU parent hyperscaler
fr-parFR EU-owned, EU-operated ovh

How to constrain it

curl https://api.llmeu.com/v1/chat/completions \
  -H "Authorization: Bearer $LLMEU_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"model":"llmeu-auto","messages":[{"role":"user","content":"Hello"}],
       "llmeu":{"residency":"eu-owned"}}'

Alternatively, set it in the policy resolved for the request. An empty eligible endpoint set returns 409 no_endpoint_for_policy; failover does not widen it.