If customer data can reach an agent, the first question is whether a tool is an option at all. This page puts what the vendors’ own pages say side by side. It takes one model on one cloud, routing tier and region at a time: where prompts are processed, what is kept and for how long, and who can see it.
It is not a compliance determination, and it is not your contract. Every line is a summary of one passage on the vendor’s own page, in plain words rather than the vendor’s, and kept to what that passage covers. Each links to the page and gives the section and the date it was read. Where the vendor’s page gives only a mark in a table, the line reports that mark. Read the page, and your own agreement, before you rely on one.
It covers the call to the model and nothing else. If an agent tool runs its own loop, sandbox or storage, where those run is a separate question, and this page does not answer it. A private model endpoint covers the model call only, not the rest of a hosted agent.
“Not stated” means no sentence on the pages read answers it. It says nothing about what a contract says.
Covered: Claude Opus 4.8 and Claude Fable 5 on all three clouds, and GPT-4o on Microsoft Foundry. A selection, not a survey. Rendered 2026-10-03; the date on each line is the day it was read. Treat every line as unverified after the date under its cloud.
Each cloud offers a narrow option that keeps processing in one place and wider ones that let it move. The names differ, and sharing a column does not mean two clouds’ options reach equally far.
| Cloud | Narrowest | Middle | Widest |
|---|---|---|---|
| AWS (Amazon Bedrock) | In-Region | Geographic | Global |
| Microsoft (Microsoft Foundry) | Azure geography | Data Zone | Global |
| Google (Gemini Enterprise Agent Platform) | Locational endpoints | Jurisdictional multi-region endpoints | Global endpoints |
| Option | What AWS’s pages say it means |
|---|---|
| In-Region | AWS’s page: for In-Region inference, data residency is confined strictly to one Region. |
| Geographic | AWS’s page: for Geographic (Geo) Cross-Region inference, data residency is bounded by a geography, with all EU Regions as its example; inside that geography, but not beyond it, prompts and outputs may travel. |
| Global | AWS’s page: for Global Cross-Region inference, no geographic limit applies, and processing may happen in any commercial Region. |
Covered on this cloud:
Claude Opus 4.8: commercial Region · In-Region · us-east-1; commercial Region · Geographic · eu-central-1; commercial Region · In-Region · eu-central-1; AWS GovCloud (US) · In-Region · us-gov-west-1
Claude Fable 5: commercial Region · In-Region · us-east-1; commercial Region · Geographic · eu-central-1; AWS GovCloud (US) · In-Region · us-gov-west-1
| Question | What the vendor’s pages say, and where it applies |
|---|---|
| Offered here? | Claude Opus 4.8: commercial Region · In-Region · us-east-1; commercial Region · Geographic · eu-central-1; AWS GovCloud (US) · In-Region · us-gov-west-1 Marked “supported” in AWS’s table. Claude Opus 4.8: commercial Region · In-Region · eu-central-1 Not offered. Marked “not-supported” in AWS’s table. Claude Fable 5: AWS GovCloud (US) · In-Region · us-gov-west-1 Not listed. Regional availability by models (opens in a new tab), read 2026-09-24, does not list this combination. |
| Model maker sees prompts? | Every combination AWS’s page: model providers have no access to the Model Deployment Accounts that hold their models inside Amazon Bedrock, and for that reason Amazon Bedrock logs and customers’ prompts and completions are out of their reach too. |
| Who processes the data | Every combination Anthropic’s page: the cloud provider acts as the data processor on Google Cloud’s Agent Platform and on Amazon Bedrock, and for the matching controls it refers readers to the documentation each platform publishes on data retention and compliance. |
| Where prompts are processed | Claude Opus 4.8: commercial Region · In-Region · us-east-1; commercial Region · In-Region · eu-central-1; AWS GovCloud (US) · In-Region · us-gov-west-1 AWS’s page: for In-Region inference, data residency is confined strictly to one Region. Claude Opus 4.8: commercial Region · Geographic · eu-central-1 AWS’s page: for Geographic (Geo) Cross-Region inference, data residency is bounded by a geography, with all EU Regions as its example; inside that geography, but not beyond it, prompts and outputs may travel. Claude Fable 5: commercial Region · In-Region · us-east-1; AWS GovCloud (US) · In-Region · us-gov-west-1 AWS’s page: for In-Region inference, data residency is confined strictly to one Region. Broader, and it also applies Anthropic’s page: on Amazon Bedrock and on Google Cloud’s Agent Platform, any data that is retained remains inside the customer’s cloud provider environment, and it refers readers to the documentation of each platform for enablement steps. Claude Fable 5: commercial Region · Geographic · eu-central-1 AWS’s page: for Geographic (Geo) Cross-Region inference, data residency is bounded by a geography, with all EU Regions as its example; inside that geography, but not beyond it, prompts and outputs may travel. Broader, and it also applies Anthropic’s page: on Amazon Bedrock and on Google Cloud’s Agent Platform, any data that is retained remains inside the customer’s cloud provider environment, and it refers readers to the documentation of each platform for enablement steps. |
| Where data is stored | Claude Opus 4.8: commercial Region · In-Region · us-east-1; commercial Region · Geographic · eu-central-1; commercial Region · In-Region · eu-central-1 Not stated on the pages read. Claude Opus 4.8: AWS GovCloud (US) · In-Region · us-gov-west-1 AWS’s page: for AWS services built inside the AWS GovCloud (US) Regions, it lists the kinds of data that may leave those Regions during normal service operation, says the list can serve as a guide toward customers’ compliance obligations, and says data not on the list stays in the AWS GovCloud (US) Regions. |
| Retention options | Claude Opus 4.8, every option listed AWS’s page, for a project set to aws_review: when a model’s allowed_modes are none, default, aws_review and provider_data_share, with Claude Opus 4.8 as its example, the model allows the none mode, so its data is not retained under any mode setting. Claude Fable 5, every option listed AWS’s page, for a project set to aws_review: when a model’s allowed_modes are aws_review and provider_data_share alone, with Claude Fable 5 as its example, human review is mandatory, so its data is kept inside the AWS boundary, AWS may review it on any request, and it is not passed to the model provider. |
| How long it is kept | Claude Opus 4.8, every option listed AWS’s page, for a project set to aws_review: a model whose allowed_modes are none, default, aws_review and provider_data_share, with Claude Opus 4.8 as its example, allows the none mode, so none of its data is retained, whichever mode is set. Claude Fable 5, every option listed AWS’s page: for models that require aws_review, currently Claude Fable 5.1 and Claude Fable 5, AWS keeps user prompts and completions inside its boundary for as long as 30 days. Broader, and it also applies Anthropic’s page: the requirement to retain data for 30 days holds in every place Covered Models are offered. |
| Human review | Claude Opus 4.8, every option listed AWS’s page, for a project set to aws_review: for a model whose allowed_modes are none, default, aws_review and provider_data_share, with Claude Opus 4.8 as its example, choosing a more permissive mode at account or project level does not lead to its content being reviewed. Broader, and it also applies AWS’s page: if a model has no human review requirement, AWS does not review the customer’s content. Claude Fable 5, every option listed AWS’s page: for models that require aws_review, currently Claude Fable 5.1 and Claude Fable 5, AWS may review user prompts and completions, because the model provider requires human review before it grants access. Broader, and it also applies AWS’s page: if a model has no human review requirement, AWS does not review the customer’s content. |
| Used for training? | Every combination Not stated on the pages read. |
| Shared with others? | Claude Opus 4.8, every option listed AWS’s page, for a project set to aws_review: for a model whose allowed_modes are none, default, aws_review and provider_data_share, with Claude Opus 4.8 as its example, choosing a more permissive mode at account or project level does not lead to its content being shared. Claude Fable 5, every option listed Not stated on the pages read. |
| Option | What Microsoft’s pages say it means |
|---|---|
| Global | Microsoft’s page: data at rest sits in the Azure geography the customer selects, and processing is limited to the deployment options, Global or DataZone, that apply on Microsoft Foundry. Microsoft’s page: for the Global Standard deployment type, data processing can take place in any Azure region. Microsoft’s page: for Global deployment types, processing of inferencing data may take place in any Azure region. |
| Data Zone | Microsoft’s page: data at rest sits in the Azure geography the customer selects, and processing is limited to the deployment options, Global or DataZone, that apply on Microsoft Foundry. Microsoft’s page: for the Data Zone Standard deployment type, data processing stays inside the data zone. |
| Azure geography | Microsoft’s page: for the Standard deployment type, data processing stays inside the Azure geography. |
Covered on this cloud:
Claude Opus 4.8: Hosted on Azure · commercial · Global; Azure Government; Hosted on Anthropic infrastructure · commercial
Claude Fable 5: Hosted on Azure · commercial · Global; Azure Government; Hosted on Anthropic infrastructure · commercial
GPT-4o: commercial · Azure geography; Azure Government · Data Zone
| Question | What the vendor’s pages say, and where it applies |
|---|---|
| Offered here? | Claude Opus 4.8: Hosted on Azure · commercial · Global; Hosted on Anthropic infrastructure · commercial Not stated on the pages read. GPT-4o: Azure Government · Data Zone Marked “✅” in Microsoft’s table. Also on the same page Marked “✅” in Microsoft’s table. Broader, and it also applies Microsoft’s page: every Azure OpenAI model offered in Azure Government counts among the Models sold by Azure. Claude Opus 4.8: Azure Government Not listed. Foundry Models sold by Azure in Azure Government (opens in a new tab), read 2026-09-24, does not list this combination. |
| Model maker sees prompts? | Claude Opus 4.8: Hosted on Azure · commercial · Global Microsoft’s page: Anthropic staff review customer content only by exception, to investigate possible safety violations, subject to the applicable Anthropic terms. GPT-4o: commercial · Azure geography Microsoft’s page: a customer’s prompts, completions, embeddings and training data are not made available to OpenAI or to any other provider of Models sold by Azure. GPT-4o: Azure Government · Data Zone Not stated on the pages read. Claude Opus 4.8: Hosted on Anthropic infrastructure · commercial Microsoft’s page: if the Hosted on Anthropic Infrastructure option is chosen, infrastructure that Anthropic hosts processes the prompts and outputs. |
| Who processes the data | Claude Opus 4.8: Hosted on Azure · commercial · Global; Hosted on Anthropic infrastructure · commercial Microsoft’s page: under both hosting options, Hosted on Azure and Hosted on Anthropic infrastructure, Anthropic sells and runs the Claude models offered in Microsoft Foundry and is, for their prompts and outputs, an independent data processor; using them is subject to Anthropic’s terms for its Claude models and APIs. GPT-4o: commercial · Azure geography Microsoft’s page: data is stored and processed by Models sold by Azure to deliver the service and to watch for uses that breach the applicable product terms, and it names the Microsoft Products and Services Data Protection Addendum as governing that processing. GPT-4o: Azure Government · Data Zone Not stated on the pages read. |
| Where prompts are processed | Claude Opus 4.8: Hosted on Azure · commercial · Global Microsoft’s page: if the Hosted on Azure option is chosen for Claude, Azure infrastructure processes the prompts and outputs, request intake, GPU inference and the API services included. Broader, and it also applies Microsoft’s page: for the Global Standard deployment type, data processing can take place in any Azure region. Microsoft’s page: for Global deployment types, processing of inferencing data may take place in any Azure region. GPT-4o: commercial · Azure geography Microsoft’s page: processing of prompts and responses happens in the geography the customer specifies unless the deployment type is Global or DataZone, though for operational purposes, performance and capacity management among them, it may move between regions inside that geography. Broader, and it also applies Microsoft’s page: for the Standard deployment type, data processing stays inside the Azure geography. GPT-4o: Azure Government · Data Zone Microsoft’s page, among the two main Azure OpenAI deployment types: Standard offers a USGov data zone option, which routes traffic inside Azure Government for higher throughput. Claude Opus 4.8: Azure Government Not stated on the pages read. Claude Opus 4.8: Hosted on Anthropic infrastructure · commercial Microsoft’s page: if the Hosted on Anthropic Infrastructure option is chosen, infrastructure that Anthropic hosts processes the prompts and outputs, and processing might take place outside Azure, including beyond the Azure region the customer selected. |
| Where data is stored | Claude Opus 4.8: Hosted on Azure · commercial · Global Microsoft’s page: data at rest sits in the Azure geography the customer selects, and processing is limited to the deployment options, Global or DataZone, that apply on Microsoft Foundry. GPT-4o: commercial · Azure geography Microsoft’s page: for the features of Models sold by Azure that keep data in the service, such as uploads through the Files API or vector store, the Responses API, Assistants API threads and Stored completions, that data is held at rest inside the Foundry resource within the customer’s own Azure tenant, in the resource’s own geography. GPT-4o: Azure Government · Data Zone Not stated on the pages read. |
| Retention options | Claude Opus 4.8, every option listed Not stated on the pages read. GPT-4o: commercial · Azure geography Microsoft’s page: if a customer is approved for modified abuse monitoring, the abuse-monitoring storage of prompts and completions, and the human review of them, which the page describes just before, are not carried out. |
| How long it is kept | Every combination Not stated on the pages read. |
| Human review | Claude Opus 4.8: Hosted on Azure · commercial · Global Microsoft’s page: automated safeguards mark content that might go to Anthropic Trust & Safety to be reviewed. GPT-4o: commercial · Azure geography Microsoft’s page: human review is done by authorized Microsoft employees, who reach data through point-wise queries by request ID on Secure Access Workstations with Just-In-Time approval from team managers, and where Models sold by Azure are deployed within the European Economic Area, the reviewers sit in that same area. GPT-4o: Azure Government · Data Zone Not stated on the pages read. |
| Used for training? | Claude Opus 4.8, every option listed Not stated on the pages read. GPT-4o: commercial · Azure geography Microsoft’s page: a customer’s prompts, completions, embeddings and training data do not go into training any generative AI foundation model unless the customer permits or instructs it. |
| Shared with others? | Claude Opus 4.8, every option listed Not stated on the pages read. GPT-4o: commercial · Azure geography Microsoft’s page: a customer’s prompts, completions, embeddings and training data are not made available to other customers. Also on the same page Microsoft’s page: Foundry is one of Azure’s services, Microsoft hosts Models sold by Azure within its own Azure environment, and those models have no interaction with any service that their providers run, OpenAI for instance, whether the OpenAI API or ChatGPT. |
| Option | What Google’s pages say it means |
|---|---|
| Locational endpoints | Google’s page: with Locational endpoints such as us-central1 or europe-west1, ML processing (tuning, training and inference) stays wholly inside the wider multi-regional or national jurisdiction that region belongs to; its example is that us-central1 requests are processed in the United States. |
| Jurisdictional multi-region endpoints | Google’s page: with Jurisdictional multi-region endpoints, ML processing, which it defines as tuning, training and inference, is kept inside the geography that endpoint covers, for example the European Union or the United States. |
| Global endpoints | Google’s page: requests sent to the global endpoint can be served and processed by Google from any region the model in use supports, which in some cases might mean higher latency. |
Covered on this cloud:
Claude Opus 4.8: Jurisdictional multi-region endpoints · US multi-region; Jurisdictional multi-region endpoints · EU multi-region; Locational endpoints · Belgium (europe-west1)
Claude Fable 5: Jurisdictional multi-region endpoints · US multi-region; Jurisdictional multi-region endpoints · EU multi-region; Locational endpoints · Belgium (europe-west1)
| Question | What the vendor’s pages say, and where it applies |
|---|---|
| Offered here? | Claude Opus 4.8: Jurisdictional multi-region endpoints · US multi-region; Jurisdictional multi-region endpoints · EU multi-region Google’s page: multi-region endpoints support every Claude model at version 4.7 or later, with claude-fable-5, claude-opus-4-7 and claude-opus-4-8 as its examples. Broader, and it also applies Google’s page: it gives Claude, from Anthropic, and Mistral’s models as examples of managed models from third parties that are offered on Gemini Enterprise Agent Platform. Claude Opus 4.8: Locational endpoints · Belgium (europe-west1) Not stated on the pages read. Broader, for context only: it does not name this option or region Google’s page: it gives Claude, from Anthropic, and Mistral’s models as examples of managed models from third parties that are offered on Gemini Enterprise Agent Platform. |
| Model maker sees prompts? Retention options Human review | Every combination Not stated on the pages read. |
| Who processes the data | Every combination Google’s page: Google processes Customer Data only on the customer’s instructions, and it points to its Cloud Data Processing Addendum for the detail. Broader, and it also applies Anthropic’s page: the cloud provider acts as the data processor on Google Cloud’s Agent Platform and on Amazon Bedrock, and for the matching controls it refers readers to the documentation each platform publishes on data retention and compliance. |
| Where prompts are processed | Claude Opus 4.8: Jurisdictional multi-region endpoints · US multi-region Marked “Supported” in Google’s table. Broader, and it also applies Google’s page: with Jurisdictional multi-region endpoints, ML processing, which it defines as tuning, training and inference, is kept inside the geography that endpoint covers, for example the European Union or the United States. Claude Opus 4.8: Jurisdictional multi-region endpoints · EU multi-region Marked “Supported” in Google’s table. Broader, and it also applies Google’s page: for ML processing, the multi-region endpoint for the European Union (eu) holds data residency strictly to EU member states, and places outside the European Union’s political boundary, the United Kingdom and Switzerland among them, fall outside that endpoint. Google’s page: with Jurisdictional multi-region endpoints, ML processing, which it defines as tuning, training and inference, is kept inside the geography that endpoint covers, for example the European Union or the United States. Claude Opus 4.8: Locational endpoints · Belgium (europe-west1) Left blank in Google’s table. Broader, for context only: it does not name this option or region Google’s page: with Locational endpoints such as us-central1 or europe-west1, ML processing (tuning, training and inference) stays wholly inside the wider multi-regional or national jurisdiction that region belongs to; its example is that us-central1 requests are processed in the United States. Google’s page: with regional endpoints, the region the customer specifies is where requests are served from. Claude Fable 5: Jurisdictional multi-region endpoints · US multi-region Marked “Supported” in Google’s table. Broader, and it also applies Google’s page: with Jurisdictional multi-region endpoints, ML processing, which it defines as tuning, training and inference, is kept inside the geography that endpoint covers, for example the European Union or the United States. Anthropic’s page: on Amazon Bedrock and on Google Cloud’s Agent Platform, any data that is retained remains inside the customer’s cloud provider environment, and it refers readers to the documentation of each platform for enablement steps. Claude Fable 5: Jurisdictional multi-region endpoints · EU multi-region Marked “Supported” in Google’s table. Broader, and it also applies Google’s page: for ML processing, the multi-region endpoint for the European Union (eu) holds data residency strictly to EU member states, and places outside the European Union’s political boundary, the United Kingdom and Switzerland among them, fall outside that endpoint. Google’s page: with Jurisdictional multi-region endpoints, ML processing, which it defines as tuning, training and inference, is kept inside the geography that endpoint covers, for example the European Union or the United States. Anthropic’s page: on Amazon Bedrock and on Google Cloud’s Agent Platform, any data that is retained remains inside the customer’s cloud provider environment, and it refers readers to the documentation of each platform for enablement steps. Claude Fable 5: Locational endpoints · Belgium (europe-west1) Left blank in Google’s table. Broader, for context only: it does not name this option or region Google’s page: with Locational endpoints such as us-central1 or europe-west1, ML processing (tuning, training and inference) stays wholly inside the wider multi-regional or national jurisdiction that region belongs to; its example is that us-central1 requests are processed in the United States. Google’s page: with regional endpoints, the region the customer specifies is where requests are served from. Anthropic’s page: on Amazon Bedrock and on Google Cloud’s Agent Platform, any data that is retained remains inside the customer’s cloud provider environment, and it refers readers to the documentation of each platform for enablement steps. |
| Where data is stored | Every combination Google’s page: on Gemini Enterprise Agent Platform, for partner models, data at rest stays within the region or multi-region the customer selects; it adds that where processing happens may vary. Broader, and it also applies Google’s page: data at rest in the location a customer selects stays there, whichever Agent Platform endpoint the customer’s request calls. |
| How long it is kept | Claude Opus 4.8, every option listed Not stated on the pages read. Claude Fable 5, every option listed Anthropic’s page: the requirement to retain data for 30 days holds in every place Covered Models are offered. |
| Used for training? | Every combination Google’s page: citing the Training Restriction in its Service Specific Terms, Google does not fine-tune or train any AI/ML model on customer data without the customer’s prior permission or instruction, and this covers every managed model on Gemini Enterprise Agent Platform, GA and pre-GA alike. |
| Shared with others? | Every combination Google’s page: when the Gemini Enterprise API is used, partner models included, the prompts customers send and the responses models return are not passed to third parties. |
Every line summarizes its publisher’s page in words that are not the publisher’s; the linked page is the authority on what it says. Lines attributed to Google summarize work created and shared by Google and used according to terms described in the Creative Commons 4.0 Attribution License (opens in a new tab). Lines attributed to Microsoft summarize Microsoft Learn documentation, © Microsoft, whose source is published in MicrosoftDocs/azure-ai-docs (opens in a new tab) under the Creative Commons Attribution 4.0 International License. Lines attributed to AWS summarize AWS documentation hosted on docs.aws.amazon.com, which the AWS Site Terms (opens in a new tab) state is licensed under the Creative Commons Attribution-ShareAlike 4.0 International License (opens in a new tab); a line drawn from it is offered here under the same license. Lines attributed to Anthropic summarize its pages, with attribution, and no license to them is claimed.