The benchmark mystery is smaller than the custody mystery
A short evaluation can make an anonymous release look irresistible, but the expanded run weakened the early performance story. The attribution evidence also remains circumstantial: similar infrastructure can host different models, and competing theories about the builder persist.
That uncertainty is acceptable for a public experiment only if users keep sensitive material out. It becomes an enterprise risk when an agent automatically sends repositories, logs, secrets, or customer context to a provider that cannot be named.
Vendor identity belongs in the security boundary
A deployment team should know the legal entity operating the model, the sub-processors involved, the jurisdictions where data travels, the exact retention period, whether inputs support training or evaluation, and who receives an incident notice. Conflicting route descriptions are a reason to stop, not a puzzle for users to solve after exposure.
Model gateways and coding tools should make provider identity and data policy visible at the moment a route is selected. Enterprise controls should block anonymous endpoints by default and require documented approval before code leaves the organization.
Go to the source
Read the evidence behind this analysis. External links open in a new tab.
SiliconANGLE — Nobody knows who built Ox Alpha or where the code goes OpenRouter — Model-routing platform and data-policy controls OpenCode — Coding agent and privacy claims


