Provider catalog¶
The catalog sharpens attribution. It is not a prerequisite for detection — that distinction is the whole reason the tool survives a vendor launching next week.
Print the live catalog at any time — this documentation can drift, the binary cannot:
Category weights¶
Reaching a frontier API is a different fact from reaching a model hub, and the weight for shadow_ai_egress says so.
Withheld from the public documentation
Exact weights, thresholds, and defaults are kept out of the published site: together they are enough to tune activity to sit below the reporting floor. They are in the repository, beside the code that applies them, for operators who need to reason about a score.
Hosted providers¶
Weight 50. Direct first-party model APIs.
| Provider | Domains |
|---|---|
| AI21 Labs | api.ai21.com |
| Alibaba Qwen / DashScope | dashscope.aliyuncs.com, dashscope-intl.aliyuncs.com |
| Anthropic | api.anthropic.com, anthropic.com |
| AssemblyAI | api.assemblyai.com |
| ByteDance Doubao / Volcengine | ark.cn-beijing.volces.com, open.volcengineapi.com |
| Cohere | api.cohere.ai, api.cohere.com |
| DeepSeek | api.deepseek.com |
| ElevenLabs | api.elevenlabs.io |
| Google Gemini / Vertex AI | generativelanguage.googleapis.com, aiplatform.googleapis.com |
| Jina AI | api.jina.ai |
| MiniMax | api.minimax.chat, api.minimaxi.com |
| Mistral AI | api.mistral.ai, mistral.ai |
| Moonshot Kimi | api.moonshot.cn, api.moonshot.ai |
| OpenAI | api.openai.com, openai.com |
| Reka AI | api.reka.ai |
| Stability AI | api.stability.ai |
| Voyage AI | api.voyageai.com |
| Zhipu GLM | open.bigmodel.cn, api.z.ai |
| xAI Grok | api.x.ai |
Weight 50. Multi-model routers and on-demand inference hosts.
| Provider | Domains |
|---|---|
| Anyscale Endpoints | api.endpoints.anyscale.com |
| Baseten | api.baseten.co, baseten.co |
| Cerebras Inference | api.cerebras.ai |
| DeepInfra | api.deepinfra.com |
| Fireworks AI | api.fireworks.ai |
| Groq | api.groq.com |
| Hyperbolic | api.hyperbolic.xyz |
| Lambda Labs | api.lambdalabs.com |
| Modal | modal.run |
| NVIDIA NIM | integrate.api.nvidia.com, api.nvcf.nvidia.com |
| Novita AI | api.novita.ai |
| OpenRouter | openrouter.ai |
| Perplexity | api.perplexity.ai |
| Replicate | api.replicate.com, replicate.com |
| RunPod | api.runpod.ai, runpod.io |
| SambaNova Cloud | api.sambanova.ai |
| Together AI | api.together.xyz, api.together.ai, together.ai |
Weight 35. Hyperscaler-mediated model access, often already governed.
| Provider | Domains |
|---|---|
| AWS Bedrock | bedrock.amazonaws.com, bedrock-runtime.amazonaws.com |
| Azure OpenAI | openai.azure.com, cognitiveservices.azure.com, inference.ai.azure.com, services.ai.azure.com |
| Databricks Model Serving | serving.cloud.databricks.com |
| IBM watsonx | ml.cloud.ibm.com |
Weight 30. Weight downloads, which is how a local runtime gets a model.
| Provider | Domains |
|---|---|
| Civitai | civitai.com |
| Hugging Face | huggingface.co, hf.co, cdn-lfs.huggingface.co, cdn-lfs-us-1.hf.co, hf-mirror.com |
| ModelScope | modelscope.cn |
| Ollama model registry | registry.ollama.ai, ollama.com |
Weight 25. Often sanctioned, and still worth an inventory entry.
| Provider | Domains |
|---|---|
| Codeium / Windsurf | codeium.com, server.codeium.com, codeiumdata.com |
| Cursor | api2.cursor.sh, cursor.sh |
| GitHub Copilot | githubcopilot.com, copilot-proxy.githubusercontent.com, api.githubcopilot.com |
| Sourcegraph Cody | sourcegraph.com |
| Tabnine | tabnine.com |
Weight 25. Their presence implies an agent framework is running somewhere.
| Provider | Domains |
|---|---|
| Braintrust | api.braintrust.dev |
| Helicone | api.helicone.ai, oai.helicone.ai |
| Langfuse | cloud.langfuse.com |
| LangSmith | api.smith.langchain.com, smith.langchain.com |
| Pinecone | pinecone.io |
| Weights & Biases | api.wandb.ai |
Weight 30. Browser-mediated, so see the caveat below.
| Provider | Domains |
|---|---|
| ChatGPT web | chatgpt.com, chat.openai.com |
| Claude web | claude.ai |
| Gemini web | gemini.google.com |
| Microsoft Copilot web | copilot.microsoft.com |
Consumer chat is attributed to the browser, not the user's intent
A hit on chatgpt.com names the browser process that opened the socket. TLS terminates inside the browser, so the sensor cannot see which tab, which profile, or what was pasted. Browser telemetry architecture covers why that is structural rather than a gap to be patched.
Local model runtimes¶
Twelve runtimes, matched by case-insensitive process pattern and by owned port.
| Runtime | Ports | Port is conclusive |
|---|---|---|
| Ollama | 11434 | yes |
| LM Studio | 1234 | yes |
| GPT4All | 4891 | yes |
| Jan | 1337 | yes |
| llama.cpp server | 8080, 8081 | no |
| vLLM | 8000 | no |
| HF text-generation-inference | 8080 | no |
| Apple MLX LM server | 8080 | no |
| LocalAI | 8080 | no |
| Open WebUI | 3000, 8080 | no |
| KoboldCpp | 5001 | no |
| LiteLLM proxy | 4000 | no |
Exclusive ports — 11434, 1234, 4891, 1337 — count on their own.
Ambiguous ports — 8000, 8080, 8081, 3000, 4000, 5001 — belong to every web framework in existence, so a listener there only counts when the process name also names a model runtime. Otherwise your development server would be reported as a model endpoint.
Heuristics for everything else¶
Inference-shaped hostnames¶
Four patterns raise unknown_provider_egress for a host in no catalog. The
realised weight is graded by how many independent hostname-shape reasons
matched rather than treating a bare vanity .ai TLD like a strong inference
API shape:
| Pattern | Catches |
|---|---|
| Inference-shaped API subdomain | api./inference./serving./predict. combined with ai/ml/llm/gpt/model |
| Inference-shaped hostname label | llm., gpt., genai., inference., embeddings. |
| Model family name in the hostname | chatgpt, gpt-4, llama, mistral, qwen, deepseek, claude, gemini, phi-3, grok |
The .ai TLD |
any *.ai host |
OpenAI-compatible request paths¶
Seven paths identify an inference-shaped request regardless of who is serving it:
/v1/chat/completions /v1/completions /v1/embeddings
/v1/responses /v1/messages
/api/generate /api/chat
What the catalog does not do¶
It does not gate detection, and it cannot be used to silence anything.
- A provider being absent does not make its traffic invisible — the heuristics and Plane A signals still fire.
- A provider being present does not make its traffic exempt. There is no allowlist.
sanctioned_endpointslabels approved paths, and that label is what makesgateway_bypasspossible.