# LLM routers and AI data risk: how your prompt reaches the model matters

Source: https://perfraction.com/blog/llm-router-data-risk/
Author: Joshua Woo, Perfraction
Published: 2026-09-16
Topics: AI vendor risk, Data protection, Third-party risk

## Short answer

The model name tells you little about who handles your data. The same model can be reached through the provider's own API, a cloud platform such as AWS Bedrock, or an LLM router that forwards requests to downstream providers. Each intermediary is another trust boundary that may see, log or retain your prompts, documents and responses. Ask who has access, what is logged, how long it is kept, where it goes next, and whether the route can change.

## Key takeaways

- Same model, different trust boundaries.
- An intermediary may sit in the path of prompts, system instructions, documents, tool calls, metadata and responses.
- Routers may send requests to fallback providers and subprocessors in other jurisdictions.
- Every intermediary needs its own access, logging, retention and routing questions.
- Before asking which model you use, ask how you get to it.

## Why isn't the model provider the whole story?

When people talk about AI data leaks, the conversation usually jumps straight to the model provider. How your prompt gets there matters too.

The same model can sit behind very different routes:

- directly through the model provider's API;
- through AWS Bedrock or another cloud platform; or
- through a model router that sends your request to a downstream provider.

Same model, different trust boundaries. That can change who sees your data, who can keep it, where it goes and what happens to it on the way.

## What can an intermediary see?

Depending on the architecture and configuration, an intermediary may sit in the path of your prompts, system instructions, uploaded documents, tool definitions and calls, metadata and model responses.

The model name alone doesn't tell you:

- who can see that data;
- who can log or retain it;
- which downstream provider ultimately processes it;
- whether requests can be routed to fallback providers;
- which subprocessors are involved; or
- which jurisdictions the data passes through.

## Has this caused a real incident?

A recent report claimed a researcher obtained around 6TB of logs from a Chinese LLM router, allegedly containing SSH keys, cloud credentials and VPN configurations belonging to various organisations. I have not independently verified those claims, and they shouldn't be treated as established fact.

The underlying point doesn't depend on that report being true.

## What should you ask about every intermediary?

1. **Who has access?**
2. **What gets logged?**
3. **How long is it retained?**
4. **Where does it go next?**
5. **Can the route change?**
6. **What data is exposed if something goes wrong?**

So before asking which model your organisation uses, ask how you are getting to it. It's not only the destination. It's the journey.

## Frequently asked questions

### What is an LLM router?

A service that sits between your application and AI model providers and decides which provider or model handles each request, often for cost, speed or fallback reasons.

### Is using a model through AWS Bedrock the same as using the provider's API directly?

Not from a data-path perspective. The model may be the same, but the contracting party, the infrastructure, the logging and the retention terms can differ.

### What should an AI vendor due diligence ask about routing?

Who can access prompts and responses, what is logged and for how long, which downstream providers and subprocessors are used, which jurisdictions data passes through, and whether requests can be rerouted to fallback providers.

---

This article is general information, not legal advice. It reflects the position as at the date of publication.

About Perfraction: a Singapore-based fractional legal function for technology companies, led by Joshua Woo. Perfraction is a legal consultancy and not a law firm. We do not provide legal advice or legal representation. Our services are limited to strategic advisory, legal operations, and regulatory consulting. For legal advice, please consult a qualified lawyer or licensed law firm.
Contact: josh@perfraction.com · Book a call: https://calendly.com/perfraction/30min · Questionnaire: https://perfraction.com/questionnaire
