5. Data Sensitivity and Provider Choice
Choose the right provider and model when working with confidential or regulated data, and understand how administrators can restrict model access.
When you handle confidential or regulated data — contracts, medical records, financial reports — the provider behind the model matters as much as the model itself. OUPI connects multiple providers, but they are not all hosted in the same jurisdiction. Mistral, for example, is a French company hosted in Europe, making it a natural fit when data must stay within EU borders. Your organization may have approved only certain providers; your administrator can restrict which models your team is allowed to use, so you may not even see models that fall outside the policy. Regardless of which provider you pick, OUPI never uses your content to train any model — a guarantee that applies across every provider on the platform.
Data sensitivity is one of the five criteria for choosing a model, alongside task difficulty, context length, modality, and budget. It is the one criterion that can override all others: even if a frontier model from a non-European provider would give a better answer, compliance requirements may force you toward a different choice. In practice, start by checking which providers your admin has approved, then apply the other four criteria within that approved set. A balanced Mistral model, for instance, covers most professional tasks well while keeping data in a European environment.
Administrators play a key role in data governance on OUPI. They can restrict the list of available models for their organization or team, ensuring that no one accidentally sends sensitive material to an unapproved provider. If you open the model selector and notice that some models are missing, it is likely because your admin has limited the selection. This is by design — it removes the burden of checking compliance from every individual user and centralizes the decision. If you believe you need access to a restricted model, contact your administrator to discuss the use case.
For confidential documents, prefer uploading them into a knowledge base rather than pasting their content directly into a prompt. A knowledge base keeps your files inside OUPI and lets the model read only the relevant excerpts, reducing exposure and improving answer quality on long material.
Model names change frequently as providers release new generations, but the four families — frontier, balanced, fast, specialist — stay stable. When an approved model you relied on disappears, look for its replacement in the same family rather than switching providers, so you stay within your organization's compliance rules.
Go to the Knowledge Bases section in OUPI. Create a test knowledge base and upload a sample document. Then open a chat, select a Mistral model (or whichever European provider your admin has approved), attach the knowledge base, and ask a question about the document. Notice how the file stays in OUPI instead of being pasted into the prompt.
When data is sensitive or regulated: (1) check which providers and models your administrator has approved — Mistral is French and EU-hosted; (2) remember that OUPI never trains on your content, regardless of provider; (3) use knowledge bases instead of pasting confidential text into prompts; (4) apply the remaining criteria (difficulty, length, modality, budget) within the approved set. Compliance first, then performance.