Final Router

Legal

Safety and Content Policy

What may and may not be sent through Final Router, how it is enforced, and how to challenge a decision.

Effective 20 August 2026

1.Who we are and how Final Router works

Final Router is an API gateway for large language models. A developer sends a request to one endpoint, and we route it to a model from one of several third-party providers, falling back to another if the first fails. We do not build models, and we do not run a consumer product.

That shape matters for everything below. We are infrastructure between a developer and a model provider. We do not host a library of content, we do not publish anything to the public, and we never see the people who eventually use whatever our customers build. Where a duty that applies to a content-hosting platform does not apply to us in the same way, this policy says so rather than borrowing language that sounds reassuring and means nothing.

We apply our own safety measures, described below, and we also rely on the safety controls built into the models we route to. Both layers can refuse a request, and they do not always agree.

2.Our safety commitments

Useful information and reduced harm pull against each other, and any policy claiming otherwise is not being straight with you. These are the commitments we hold to while balancing them:

  • Prevent clearly unlawful or high-risk requests from being sent to a provider at all.
  • Detect problems and act on them quickly, rather than waiting for a complaint.
  • Restrict the service to people aged 18 and over.
  • Be transparent about how enforcement works, including where it is imperfect, and give you a way to tell us we got it wrong.
  • Apply data minimisation: we record that a policy decision happened, not the content it was made about.
  • Comply with applicable law, including the EU AI Act's prohibitions on certain AI practices.

3.Roles and responsibilities

Ours. We screen requests before they reach a provider, act on illegal content when we become aware of it, keep this policy current as capabilities change, and answer appeals.

Yours. You must be 18 or over. You are responsible for what your application sends us, including anything your own end users cause it to send — we have no relationship with them and no way to reach them. Do not attempt to bypass, disable or probe the safeguards described here. If we learn an account belongs to somebody under 18, we may suspend it and delete the associated data.

Providers'. Every model we route to has its own policies and its own safety controls, and those apply to your traffic on top of this policy. Where a provider's rules are stricter, theirs govern that traffic. We may re-route, restrict or stop offering a model where a provider changes its terms or where we identify a risk.

4.Illegal content

Content that is unlawful in the jurisdictions we operate in. This is not a matter of preference, and the categories below are examples rather than an exhaustive list.

When we become aware of illegal content we act on it: the request is refused, the account is restricted where appropriate, and we cooperate with authorities where the law requires. Child sexual abuse material is reported, without exception and without appeal.

5.Child sexual abuse and exploitation

Any content that sexualises a minor. There is no context in which this is permitted, and no appeal.

  • Sexual or suggestive depictions of anyone under 18, real or fictional
  • Grooming, solicitation, or instructions for either
  • Requests to describe, generate, or modify such material

Detection: automatic. Requests matching this are refused before they reach a provider.

6.Violence and violent extremism

Content that incites, plans, praises, or provides operational help for serious violence.

  • Planning an attack, or identifying targets for one
  • Producing recruitment or propaganda material for a violent group
  • Graphic depictions of violence produced for their own sake

Detection: automatic. Requests matching this are refused before they reach a provider.

7.Weapons and mass harm

Instructions that would meaningfully help somebody build a weapon capable of serious injury.

  • Synthesis routes for chemical, biological, radiological or nuclear agents
  • Building explosives, or converting a firearm to automatic fire
  • Circumventing controls on any of the above

Detection: automatic. Requests matching this are refused before they reach a provider.

8.Malicious cyber activity

Building or operating software whose purpose is to compromise systems or people. Security work done with authorisation is fine.

  • Ransomware, credential stealers, botnets, or evasion tooling
  • Exploiting a system you have no permission to test
  • Large-scale credential stuffing or scraping behind authentication

Detection: review. This is prohibited, but the automated signals for it also fire on legitimate work — security research, fiction, clinical writing — so matches are recorded rather than refused, and patterns across an account are reviewed by a person.

9.Fraud and deception

Content whose purpose is to take money or trust from somebody under false pretences.

  • Phishing pages, scam scripts, or fake invoices
  • Forged identity documents, receipts, or credentials
  • Impersonating a real person or organisation without their consent
  • Bulk fake reviews, ratings, or engagement

Detection: review. This is prohibited, but the automated signals for it also fire on legitimate work — security research, fiction, clinical writing — so matches are recorded rather than refused, and patterns across an account are reviewed by a person.

10.Privacy and surveillance

Using the API to compile, expose, or track information about people without a lawful basis.

  • Assembling a dossier on a private individual
  • Facial recognition or biometric identification without consent
  • Publishing somebody's home address, phone number, or documents to expose them

Detection: review. This is prohibited, but the automated signals for it also fire on legitimate work — security research, fiction, clinical writing — so matches are recorded rather than refused, and patterns across an account are reviewed by a person.

11.Intellectual property infringement

Using the API to reproduce protected work at scale, or to strip the marks that identify it.

  • Bulk reproduction of copyrighted text, code or media
  • Removing watermarks, attribution, or licence notices
  • Passing somebody else's protected work off as your own product

Detection: review. This is prohibited, but the automated signals for it also fire on legitimate work — security research, fiction, clinical writing — so matches are recorded rather than refused, and patterns across an account are reviewed by a person.

12.Harmful content

Lawful in many places, and still not something we will pass on. This is our decision rather than a legal requirement, and we would rather say that than dress a choice up as an obligation.

Requests in these categories are refused, or recorded and reviewed, depending on how reliably they can be detected. Repeated violations restrict the account.

13.Self-harm

Encouraging suicide, self-injury or disordered eating, or explaining how.

  • Methods, dosages, or comparisons of lethality
  • Encouragement, or discouragement from seeking help
  • Pro-suicide or pro-eating-disorder material
  • Encouraging drug misuse, or dangerous challenges likely to cause injury
  • Body shaming, or content designed to deepen somebody's depression

Detection: automatic. Requests matching this are refused before they reach a provider.

14.Harassment and hate

Content that attacks, degrades, or threatens people, particularly on the basis of who they are.

  • Threats of violence against a person or group
  • Dehumanising content targeting a protected characteristic
  • Coordinated abuse aimed at an individual

Detection: automatic. Requests matching this are refused before they reach a provider.

15.Adult sexual content

Explicit sexual material is not served through the shared gateway. Adult platforms should hold their own provider accounts and connect them.

  • Sexually explicit generation for entertainment
  • Non-consensual sexual content or intimate imagery of real people

Detection: review. This is prohibited, but the automated signals for it also fire on legitimate work — security research, fiction, clinical writing — so matches are recorded rather than refused, and patterns across an account are reviewed by a person.

16.Regulated advice presented as professional

Medical, legal and financial applications are welcome. Passing model output off as a licensed professional's judgement is not.

  • Presenting output as a diagnosis, prescription, or legal opinion
  • Removing disclaimers a regulator requires

Detection: review. This is prohibited, but the automated signals for it also fire on legitimate work — security research, fiction, clinical writing — so matches are recorded rather than refused, and patterns across an account are reviewed by a person.

17.Political manipulation

Campaigning and civic tools are fine. Manufacturing the appearance of public opinion is not.

  • Astroturfing, sock puppets, or bulk persona generation
  • Content designed to suppress or misdirect voters

Detection: review. This is prohibited, but the automated signals for it also fire on legitimate work — security research, fiction, clinical writing — so matches are recorded rather than refused, and patterns across an account are reviewed by a person.

18.Product-level safeguards

Screening happens on the way in. Requests are classified before a provider is called, because a request we would refuse is not one we should be paying to answer.

Model output carries the provider's own safety controls. We do not re-screen what a model returns: it has already been through that provider's safety layer, and running our own over the top would refuse people for a reply they did not ask for.

You are responsible for telling your users they are talking to an AI. We are not in front of them, so we cannot. If you build something where that matters — and in the EU, for many uses, it is a legal requirement — that disclosure is yours to make.

Connecting your own provider keys does not exempt you. Requests routed on your own credentials are screened exactly the same way. The bill changes; the policy does not.

19.Proactive technology and human review

Automated screening. Every request is classified against the same list published above, before it reaches a provider. A match in a category we can detect reliably is refused with HTTP 403 and an error type of policy_violation, and nothing is charged for it.

Two tiers, and the reason is worth stating. Some categories can be detected precisely enough to refuse a request on. Others cannot, because every automated signal for them also fires on ordinary work: asking how SQL injection works in order to defend against it reads to a classifier exactly like planning an attack, and a novelist's ambulance scene reads as violence. Refusing on those signals would break the service for security engineers, writers and clinicians, who are customers. Those categories are recorded and reviewed by a person instead.

The consequence, stated plainly: some prohibited use gets past the automated layer. It is caught by review, not by the classifier. We prefer telling you that to claiming a machine catches everything.

Human review. Patterns across an account are reviewed by a person before the account is restricted — automated screening is imperfect in both directions, and a single match is not evidence of anything. The exception is child sexual abuse material, where we act immediately.

Safety logging, minimised. We record the category, the outcome and the time, against your account and the key used. Enforcement never stores the text of the request. Keeping a copy of everything the policy ever touched would build exactly the archive of other people's private data that this policy says we do not build.

Prompt storage is a separate thing, and a choice. An account can switch it on for itself so its own requests and replies can be read back in its own log — useful when the question is why a model answered the way it did. It is off unless somebody turns it on. The text is kept for 30 days and then deleted; turning the setting off deletes what was already stored, immediately; and nobody outside that account can read it. If your prompts carry other people's personal data, the decision to store them is yours to make and yours to tell them about.

When screening is unavailable, requests are allowed through and recorded as unscreened. Refusing everyone during an outage would take the service down to prevent abuse that may not be happening.

20.What happens if you break this policy

Proportionate to what happened and whether it keeps happening:

  • A single refused request needs nothing from you beyond changing the request.
  • A repeated pattern gets an email asking what you are building.
  • Continued abuse suspends the API keys involved, then the account.
  • Child sexual abuse material results in immediate termination and a report to the relevant authorities. There is no appeal.

Credits on a suspended account are not forfeit. If we end an account for policy reasons, unspent credits are refunded except where the law requires otherwise.

21.Reporting concerns

If you believe somebody is using Final Router in a way this policy prohibits, write to abuse@finalrouter.com. Include what was requested, what appeared, and timestamps where you have them — that is usually enough for us to find it.

Reports concerning the safety of a child are escalated immediately.

To report a security vulnerability rather than an abuse of the service, use security@finalrouter.com instead.

22.Appeals

Automated screening produces false positives, and security research, medical work, harm reduction and fiction all sit close to category lines. If a legitimate request was refused, or an account action was wrong, write to support@finalrouter.com with the time of the request and the key prefix it used. We can find it from that, and we do not need you to send us the prompt.

We answer appeals within two working days. If your work routinely sits near one of these categories and is legitimate, tell us before you launch rather than after — arrangements can be made, and it is a much easier conversation in advance.

23.Regional notes

Age. Final Router is offered only to people aged 18 and over. If we obtain knowledge that an account holder is under 18, we terminate the account and delete the associated data on the schedule set out in the Privacy Policy.

United Kingdom. Complaints about illegal content may be submitted using the contact details in Reporting concerns above, and we will respond in line with the Online Safety Act's requirements as they apply to a service of this kind.

European Union. We comply with the requirements of the Digital Services Act applicable to services offered to users in the EU, and with the EU AI Act, including its prohibitions on certain AI practices. Note that Final Router is business-to-business infrastructure: where an obligation attaches to a provider of an online platform that hosts and displays content publicly, it does not apply to us in the same way, and we do not claim otherwise.

Providers. Model providers apply their own regional restrictions, which can differ from ours. A request that this policy permits may still be refused by the model that receives it.

24.Effective date and updates

This policy takes effect on the date shown above. New capabilities create new ways to misuse them, and providers and laws change, so it will be updated. Material changes are announced by email to account holders at least 14 days before they take effect, except where a change is needed immediately to address serious harm.