NeuralRing

Network fronts — who stands at the gate

For every routable endpoint, NeuralRing records not just who runs the model, but who operates the serving front in front of it — and whether that proxy is EU/EFTA-controlled. This page shows that classification for every public model, with the captured evidence behind it.

What a serving front is

Many endpoints do not answer you directly. A CDN or edge-gateway — Cloudflare, a national CDN, an operator's own proxy — terminates the TLS connection and forwards the request on. That front is a real part of the path your prompt travels: whoever operates it can, in principle, see the connection. A front is neither good nor bad by itself; what matters is who operates it and under whose jurisdiction.

What the probe proves — and what it cannot

NeuralRing's hosting-provenance probe resolves the serving address, looks up its holder-of-record, and inspects the TLS chain and response headers against a versioned list of known CDN/gateway signatures. From that it derives one of: direct (no front detected), fronted (a declared front, EU/EFTA-sovereign or not), undeclared front (an exact marker the operator did not declare), or unknown. It identifies who OPERATES the front. It does not, and cannot, tell you where any machine physically is — that is a separate question with its own evidence, and this page never conflates the two.

The residual caveat — read this

“Direct” means no front was DETECTED, never that no front exists. A custom in-region reverse proxy leaves none of the signatures the probe looks for, so it would read as direct. This is a real limit, and we state it here rather than hide it: the classification proves the front operator when a known front is present; it is never proof of what runs behind the front, or of any location.

Declared vs. undeclared

An operator can declare its front. A declared front is honest — we mark it fronted, name the operator and its jurisdiction, and say whether it is EU/EFTA-sovereign. Declaration changes the narrative, not the exposure: a declared non-EU front still means prompts transit non-EU-controlled infrastructure, exactly as an undeclared one does. An undeclared front the probe catches is what it has always been — a contradiction of a sovereign-EU hosting claim.

How the marker list is kept honest

The signatures the probe matches are a versioned snapshot. Each verdict is pinned to the exact snapshot that produced it, captured as evidence, so an old verdict is never silently re-judged by a newer list. A CDN vendor is only added to the snapshot with real, verified signals, and its jurisdiction is the operator's controlling jurisdiction — researched, not assumed from marketing. Vendors we cannot substantiate are left out rather than guessed.

Front classification, per public model

Who OPERATES the serving front (the CDN/edge-gateway in front of this endpoint), from a captured probe — never where any box is (§0). frontResidual: a custom in-EU reverse proxy defeats detection, so “direct” means no front DETECTED, not that none exists.