Last updated: August 25, 2026
Document-first. Future Stack Reviews did not send a request to Ox Alpha, did not create an Ox Alpha API key, and did not run a benchmark. Every statement below comes from published vendor documents, published platform settings, or named third-party work, and each is labeled with its evidence status. FSR does not place affiliate links in Tier C briefings. This page carries none.
Ox Alpha is an anonymous reasoning model that OpenRouter lists for coding and sustained agentic work, released August 20, 2026 with a 1,048,576 token context window at zero token price. Three services market access to it. The buyer problem is not the missing company name on its own. It is that no route currently supplies one binding answer on who receives your code, how long they keep it, and what they may do with it.
Verdict: approve Ox Alpha for public, synthetic, or fully sanitized evaluation only, unless a route names the processor and offers data terms your organization can sign.
What happened
A capable coding model went live on August 20, 2026 with no company name attached and a price of zero. As of August 25, OpenRouter had not publicly identified the provider, and no route had published an exact end date for free access.
Who this is for
Engineering leads deciding whether an agent may read a repository. Platform owners considering a free tier in a router. Anyone who has to record a processor in a vendor register or a data processing agreement.
Not for
Private repositories, customer data, regulated workloads, export-controlled material, or any production dependency without a tested fallback. Removing confidential data lowers one exposure category. Account terms, endpoint continuity, and output validation remain.
What this page cannot settle
Who built Ox Alpha. Whether any prompt has been used for training. Whether the three routes serve the same checkpoint. Whether any specific use is lawful in any jurisdiction. Each is marked open rather than filled in.
Key facts
| Item | Published information | Evidence status |
|---|---|---|
| OpenRouter model ID | stealth/ox-alpha | Official |
| Release date | August 20, 2026 | Official |
| Provider identity | Anonymous third party. OpenRouter states it will not disclose the name or origin of Stealth Providers. | Official, not disclosed |
| Context window | 1,048,576 tokens | Official |
| Maximum completion | 131,072 tokens | Official |
| Inputs and output | Text, images and video in. Text out. | Official |
| OpenRouter token price | $0 input, $0 output | Official, volatile, checked 25 Aug 2026 |
| Provider policy classification | Stealth: retention period unknown, may train | Official, volatile, checked 25 Aug 2026 |
| Supplemental terms for this model | None listed | Official, volatile, checked 25 Aug 2026 |
| Located full DeepSWE run | 66 of 113, or 58.4% | Independent community run, single attempt |
| Independent leaderboard entry | None located. No Artificial Analysis entry. | Checked 25 Aug 2026, chart data not extractable |
| FSR hands-on testing | None | Untested |
Table note: price, provider classification and supplemental terms are volatile fields read on 25 August 2026 and should be rechecked before any decision.
Jump to a section
Contents
Practice and permission are different layers
OpenRouter’s Ox Alpha page states that prompts and completions are retained by the provider and are not used for training, and that all other use is governed by the Stealth Model Terms. That is a model-specific representation about reported provider practice.
The Stealth Program End User License Agreement, updated July 6, 2026 and incorporated into the Terms of Service by section 5.1, is broader. Section 1 describes the program as offering models anonymously and free of charge for the purpose of collecting user content for use in Stealth Model training and improvement. Section 3 describes free access as consideration for the provision of that content. Section 4 grants a non-exclusive, irrevocable, perpetual, transferable, worldwide, royalty-free license, with the right to sublicense that content to the Stealth Provider for training, evaluation and improvement. The same section states that a user who does not want content provided for Stealth Model training should refrain from using Stealth Models. There is no partial opt-out described.
These statements sit in tension, and the tension does not resolve into proof. A provider can hold a broad contractual permission and not exercise it for a particular model. The open question is narrower and more useful: does the Ox Alpha notice expressly limit or waive sections 1, 3 and 4 for this model?
Section 5.8 of the Terms frames that question rather than answering it. It states that OpenRouter does not modify, waive, or limit any Model Terms unless expressly stated in writing. The Ox Alpha notice is written. The reviewed public documents do not state whether it operates as that written limitation, and OpenRouter’s Stealth Program Supplemental Terms page, which is where a model-specific carve-out would appear, listed no models on August 25, 2026.
Two further provisions keep a buyer from closing the question on the notice alone. Section 6.1 states that while OpenRouter strives to represent logging and training status accurately for each model, it is not liable for errors or misrepresentations in any Model Terms. Section 16 states that OpenRouter makes no representation or warranty regarding any model provider’s data handling, retention, training, security, availability, or intellectual property practices.
A third document adds a fourth published position. OpenRouter’s provider logging documentation classifies the Stealth provider as retaining prompts for an unknown period and as a provider that may train. Of the 83 providers listed there, five carry that classification. This is a dated platform classification rather than evidence about any specific request; it was read on August 25, 2026.
The defensible conclusion is a procurement conclusion, not a legal one. OpenRouter’s public materials do not give a buyer one unambiguous, route-specific statement covering both current practice and contractual permission, and the platform has disclaimed liability for the accuracy of the statement a buyer would most want to rely on. That is enough to fail a vendor review. It is not enough to say the notice is wrong.
One provision runs the other way and belongs in the record. Section 4 states that content provided to Stealth Providers carries a hashed identifier so that individual users are not identifiable to the provider, and that OpenRouter contractually prohibits providers from attempting to re-identify users. That is a stated control over user identity, and it says nothing about the content itself. The contract stack is also wider than the Stealth documents: sections 10.1 and 10.2 incorporate OpenRouter’s Privacy Policy and its Data Processing Agreement by reference, and a complete review reads those too.
Sources: OpenRouter model page, read 25 August 2026 · Stealth Program EULA, updated 6 July 2026, read 25 August 2026 · OpenRouter Terms of Service, updated 29 July 2026, read 25 August 2026 · Stealth Program Supplemental Terms, read 25 August 2026 · OpenRouter provider logging documentation, read 25 August 2026
The route is the procurement unit
Three services publish route-specific data terms for a model marketed as Ox Alpha. The public materials do not establish that they serve the same checkpoint, the same wrapper, or the same upstream deployment, so they should be audited as separate services carrying the same marketed name. A fourth route, Nous Portal, has been reported to offer the model; FSR did not locate published route-specific data terms for it and therefore does not list it below.
Card note: cards 01 and 02 were read directly by FSR on 25 August 2026. Card 03 and the $10 subscription figure come from an external research pass and have not been read at source. Every value shown is a vendor representation, not an independent verification of the data path.
OpenCode’s own terms add the limitation its marketing does not: content sent to third party models is subject to the retention policies of the providers of those models. Its published operational representations for Ox Alpha are materially better than the anonymous OpenRouter route, and they are still statements about a provider OpenCode has not named either. The same documentation says Zen models are hosted in the United States, without explaining how the hosting location of an unnamed provider is established.
The practical consequence is that data terms attach to the access route rather than to the marketed model name. Two engineers using “Ox Alpha” on the same afternoon can be operating under different published retention promises, different hosting statements, and different governing contracts. A vendor register entry that records the model name records almost nothing.
Third-party websites add a further path. At least one, oxalpha.org, offers browser chat under the Ox Alpha name with no signup, no account, and no card, and states in its footer that prompts and completions are handled by a third-party provider via OpenRouter. It is not operated by OpenRouter, and FSR did not locate a data processing agreement, a named operator, or a stated retention period for it. Anyone routing work through a site like that is adding an unidentified intermediary in front of an already unidentified provider.
Sources: OpenRouter, read 25 August 2026 · OpenCode Zen documentation, read 25 August 2026 · OpenCode Zen, read 25 August 2026 · oxalpha.org, read 25 August 2026 · OpenCode Go documentation and OpenCode terms of service.
The 58.4% run and its failure modes
Three DeepSWE figures circulate for Ox Alpha. They are three different sample sizes, and the most repeated one is the smallest.
| Run | Scope | Result | Evidence status |
|---|---|---|---|
| First subset, Ben Davis (@davis7) | 10 tasks | 8 of 10 | Community signal. Disclosed as a subset by its author in the original post. |
| Larger subset, @winkey_h | Subset, size not exposed in the inspected material | approximately 63% | Community signal. Davis later cited this figure and identified the runner as someone else. |
| Full set, Henry Zhang (@henryzhangumich) | 113 tasks | 66 of 113, 58.4% | Community run, single attempt. Not an FSR test and not an official leaderboard result. |
Table note: only the third row is described by its runner as covering the complete 113-task set. FSR has not opened the underlying run log and marks that verification as outstanding.
Davis posted the lower figure himself, writing that the run ended at roughly 63% rather than the 80% his first subset produced, and that this made more sense. He posted again to clarify that the larger run was not his. Both statements are on the record. Neither invalidates the original subset, which was correctly labeled as a subset when it was published. What went wrong happened downstream, where the caveat fell away and a ten-task figure was repeated as a benchmark score.
The aggregate number also conceals the finding an engineering team would act on first. An external research pass reviewing the published run log reports that 11 of the 113 tasks, 9.7% of the set, ended after Ox Alpha returned three consecutive responses containing no tool call, and that five more exceeded the task time budget. The same pass records the harness as mini-swe-agent on a Docker backend. FSR has not opened that log.
If those figures hold, the distinction matters more than the rank. A reasoning failure argues for a better model or a better prompt. A recurring tool-format failure argues for retry policy, wrapper validation, or a different agent harness, and it is the kind of defect that produces silent cost in an autonomous loop rather than a visible wrong answer.
The supportable claim is narrow. One public full run shows Ox Alpha completing a material share of difficult software engineering tasks, with a measurable agent-loop failure mode alongside it. That does not establish run-to-run consistency, production reliability, or superiority over named alternatives.
No independent leaderboard has published a score
Artificial Analysis, the tracker most often cited for cross-model intelligence scores, has no Ox Alpha entry. Its Intelligence Index v4.1.1 combines nine evaluations and covers 605 models, and the model-creator legend on its release-date chart lists eighteen labs, none of them an anonymous or stealth provider. FSR read that page on August 25, 2026. The chart data itself is rendered client side and could not be extracted, so this is a check against the visible page rather than a query against the underlying dataset. Independent reporting on the same dates describes the same absence.
That absence has been filled by someone else. The third-party site oxalpha.org publishes a comparison table with an Intelligence column, listing Ox Alpha at 59 with an asterisk beside models priced per million output tokens. Its footnote attributes the column to the Artificial Analysis Intelligence Index and SWE-bench, and states that Ox Alpha is in preview and that its starred score is a community-reported estimate.

The mechanism is worth naming because it will repeat. Two of the comparison values on that page, Claude Opus 5 at 63 and Claude Fable 5 at 62, match what Artificial Analysis publishes; FSR checked both on the same day. The Ox Alpha figure does not come from there, and the footnote says so. Placed in the same column, a number nobody measured travels alongside numbers somebody did, carrying an index name that lends it weight the disclaimer cannot take back.
Anyone quoting an intelligence score for Ox Alpha should establish where it came from. As of August 25, 2026 the answer was not Artificial Analysis, and the word frontier attached to this model is the operator’s own.
Sources: Ben Davis on X, 21 and 22 August 2026 · Henry Zhang on X and GitHub, 22 August 2026 Artificial Analysis Intelligence Index v4.1.1, read 25 August 2026 · oxalpha.org, read 25 August 2026 · SiliconANGLE, 23 August 2026
What is documented about the model
OpenRouter describes Ox Alpha as a reasoning model designed for coding, sustained agentic work and production workloads, suited to long-horizon software engineering and to workflows combining text with visual context. The listing also states that OpenRouter routes requests to it and is not its developer, owner, or provider.
Beyond the specification in the table above, the listing documents tools and tool_choice for function calling and response_format for JSON output without schema enforcement. One provider serves it, labeled Stealth, so there is no routing fallback if that provider stops responding.
What is not documented anywhere is the part a review normally starts with. There is no parameter count, no architecture description, no training data description, no model card, no version or checkpoint identifier, and no named legal entity. The listing carries a marketing name and an alias. Nothing in the public record pins the alias to a specific build, which means the behavior behind the slug can change without any published signal.
Serving telemetry on the model page moves continuously and is not reproduced here. Record the timestamp with any figure taken from it.
Sources: OpenRouter model page and FAQ, read 25 August 2026 · OpenRouter Stealth provider page, read 25 August 2026
One new account’s privacy defaults
OpenRouter lets an account holder control whether requests may be routed to endpoints with particular data policies. The settings page states that enabling a toggle allows routing to endpoints with that policy and disabling it excludes them.
FSR created an OpenRouter account on August 25, 2026 at 10:08 JST and read the privacy settings page at 10:10 JST. This is what that page displayed.
| Setting | State displayed |
|---|---|
| Zero Data Retention, non-frontier | Off |
| Zero Data Retention, Anthropic, OpenAI, Google, SpaceXAI | Off |
| Allow paid endpoints that train on request data | Off |
| Allow free endpoints that train on request data | On |
| Allow free endpoints that publish prompts | Off |
| Allow 1% data discount in workspaces | Off |
Table note: single account, created in Japan, personal account type, read 25 August 2026 at 10:10 JST. FSR treats this as the delivered default rather than a configured state, and a reader can check that in under a minute by creating an account and opening the same page. Whether the same defaults apply to organizational accounts or to accounts created in other jurisdictions was not tested.
The switch that is on reads: enable providers serving free models that may retain and/or train on prompts and completions. The equivalent switch for paid endpoints is off.
FSR did not test whether this setting controls routing to Ox Alpha specifically, and does not claim that it does. The observation is that a free-endpoint training permission arrived enabled while its paid counterpart arrived disabled, on one account, on one day. Anyone can check it in a minute by creating an account and opening the same page. The eligibility preview on that page, which reports how many models the current configuration permits, displayed 536 available and 3 unavailable; toggling the free-training switch and rereading that count would establish whether it gates this model. That test is outstanding.
Sources: OpenRouter privacy settings, read 25 August 2026, sign-in required · OpenRouter provider logging documentation, read 25 August 2026
Three hypotheses, none confirmed
As of August 25, 2026 OpenRouter had not publicly identified the provider. Three hypotheses circulate, and none is authenticated.
Z.ai, formerly Zhipu AI, serving a GLM-family model. An independent fingerprinting tool reports that GLM-5.3 matched on all four normalized tokenizer counts while no other candidate cleared more than two, and separate reports describe error codes and an API path structure consistent with Z.ai’s published reference. Against it: the publicly documented GLM-5.3 is text only, while Ox Alpha accepts images and video.
Microsoft, in the Phi or MAI lineage. One analyst published a three-probe token count table reporting an exact match to the cl100k_base encoding. Against it: the table contains no GLM row, a direct reply asserted the same fingerprint also matches GLM-5.3, and no reproduction package has been published.
A different model sharing GLM tokenization or serving infrastructure. Serving-layer signals identify a stack rather than a checkpoint, which is what the tool’s own author says. This absorbs the modality mismatch and covers unreleased variants and other labs, including Xiaomi’s MiMo family, which some observers have named. It is also the least falsifiable of the three.
Underneath all three sits a measurement problem. None of the analyses FSR reviewed cites a published tokenizer vocabulary specification or a published video token accounting formula for the model being compared against. The comparisons are made against measured behavior rather than against documentation.
The cl100k reading carries a second caveat. That encoding is still in general use as a counting standard rather than only as a model’s native vocabulary: Artificial Analysis defines the document lengths in its long-context evaluation in cl100k_base tokens. A reported token count matching cl100k therefore establishes what some counting layer produced, and it becomes evidence about the model’s own vocabulary only once the count is shown to come from the model rather than from a router or wrapper. The fingerprinting tool’s own documentation flags routing as exactly that kind of confound.
Treat all of this as infrastructure evidence, not authenticated model identity.
Sources: modelprint README, GitHub, read 25 August 2026 · Artificial Analysis long context reasoning evaluation, read 25 August 2026 · TechCrunch, 23 August 2026 · SiliconANGLE, 23 August 2026 · Robert Lukoszko on X, 21 August 2026 .
Export control, conditionally
Conditional analysis, not a determination
Because one hypothesis names a company on a United States restricted list, this question gets raised often and answered badly in both directions.
On January 16, 2025 the Bureau of Industry and Security added eleven entities to the Entity List under the destination of China. Ten are Zhipu entities. The primary listing is Beijing Zhipu Huazhang Technology Co., Ltd., recorded with the aliases Zhipu AI and Beijing Knowledge Atlas Technology Co., Ltd. The license requirement reads all items subject to the EAR, and the license review policy reads presumption of denial.
The Entity List is item-based and transaction-based, imposing license requirements on exports, reexports and in-country transfers of items subject to the EAR when a listed entity is a party. It is not a blanket prohibition on every dealing with a listed company. It is also not irrelevant here, because the regulatory definition of an item covers commodities, software and technology, and sending source code or technical data to an endpoint can involve transferring something in one of those categories depending on the facts.
Two conditions have to hold before this becomes concrete for Ox Alpha: the provider has to be identified, and the specific data crossing the specific border has to be classified. Neither has been done publicly. Any organization handling controlled technical data should route this to counsel as a transaction question.
Sources: Federal Register, 90 FR 4617, 16 January 2025, read 25 August 2026 · OpenRouter, read 25 August 2026
Three gates before approval
A team can decide this without waiting for a reveal.
Gate one, data class. Public, synthetic, or fully sanitized material containing no secrets, personal data, customer content, private source code, or controlled technical data can proceed to a limited evaluation. Internal non-confidential material needs a security or legal decision. Confidential, customer, regulated, or export-controlled material should not proceed until the receiving legal entity is named and binding data terms exist.
Gate two, continuity. The Stealth EULA permits removal at any time, with or without notice, and the terms of service allow a provider to modify Model Terms with continued use counting as acceptance. A one-off evaluation tolerates that. An internal tool needs a tested fallback. A production dependency needs a provider pin, a version identifier, a notice period, and a migration path, none of which is currently available.
Gate three, capability. No independent leaderboard has scored this model, so a single screenshot or aggregate figure is not a basis for approval. Run representative tasks repeatedly, record tool-call failures separately from reasoning failures, measure human correction time, and compare the same commits and acceptance tests against a named fallback model.
One more clause belongs in a procurement file. Section 5.5 states that OpenRouter may suspend or terminate access at a model provider’s request, that each provider retains sole control over access to its model, and that if access is suspended it is the user’s responsibility to contact the provider to resolve it. The Stealth EULA states that OpenRouter will not disclose the name or origin of Stealth Providers. The public documents do not explain how a user reaches a provider whose name is withheld.
Sources: OpenRouter Terms of Service, updated 29 July 2026, read 25 August 2026 · Stealth Program EULA, updated 6 July 2026, read 25 August 2026
FAQ
What is Ox Alpha?
An anonymous reasoning model listed on OpenRouter as stealth/ox-alpha, released August 20, 2026, marketed for coding and sustained agentic work. It has a 1,048,576 token context window, accepts text, images and video, and carried a zero token price when checked on August 25, 2026.
Who made Ox Alpha?
As of August 25, 2026 OpenRouter had not publicly identified the provider, and states it will not disclose the name or origin of Stealth Providers. Community fingerprinting reports GLM-family serving signals, with a competing analysis pointing at Microsoft’s Phi or MAI lineage. These identify infrastructure, not an authenticated model identity.
Does the provider train on my code?
The model page says prompts and completions are retained but not used for training. The incorporated Stealth EULA describes training as the program’s purpose, describes free access as consideration for that content, and grants a training license. OpenRouter’s provider table classifies the Stealth provider as one that may train. The public documents do not resolve which governs.
Is it safe for a private repository?
FSR does not make safety determinations. From the reviewed public documents, no route names the legal entity that receives the request or its subprocessors. An organization that requires a named processor and a signed data processing agreement cannot establish either from what is currently published.
What was its full DeepSWE score?
The located full run covered 113 tasks and scored 66 solves, or 58.4%, as a single-attempt community run. The widely repeated 80% came from an eight-of-ten subset that its author labeled as a subset. A larger subset produced approximately 63%.
Is there an Artificial Analysis score for Ox Alpha?
No. FSR checked the Artificial Analysis Intelligence Index on August 25, 2026 and found no Ox Alpha entry, and no intelligence, coding or agentic score. A third-party site publishes a 59 figure in a column labeled with the index name, but its own footnote calls that a community-reported estimate.
What happens when the preview ends?
The Stealth EULA permits removal from the program at any time at the provider’s request or at OpenRouter’s discretion, with or without notice. No route has published an exact end date or a post-preview price. Anything built against the slug should assume the endpoint can disappear and should carry a tested fallback.
Sources: OpenRouter, read 25 August 2026 · Stealth Program EULA, read 25 August 2026 · OpenRouter provider logging documentation, read 25 August 2026
Methodology and source status
This is a document-first briefing. FSR did not send a request to Ox Alpha, did not create an Ox Alpha API key, and did not run a benchmark. No performance figure on this page is an FSR measurement.
Read directly in a browser on August 25, 2026 and captured: the Ox Alpha model page and its FAQ answers, the Stealth provider page, the Stealth Program End User License Agreement, the Stealth Program Supplemental Terms page, the OpenRouter Terms of Service, the OpenRouter provider logging documentation, the OpenRouter account privacy settings page, the OpenCode Zen documentation and product page, the Artificial Analysis Intelligence Index and long context reasoning evaluation pages, the third-party site oxalpha.org, and the Federal Register entry of January 16, 2025.
Recorded but not read at source, and labeled as such in the body: the OpenCode Go documentation and OpenCode terms of service, the $10 Go subscription figure, the 113-task run log and its failure decomposition, and Z.ai developer documentation referenced in the identity section.
Five verification tasks remain outstanding: the eligibility preview differential test in section 05, direct reading of the OpenCode Go and OpenCode terms documents, direct inspection of the 113-task run log, a query against the Artificial Analysis model list rather than the visible chart, and a check of whether Ox Alpha appears on LMArena.
One dating note. The model page header displayed a release date of August 21, 2026 when read from a browser set to Japan Standard Time, while the FAQ on the same page states August 20, 2026. The header most likely renders in the reader’s local timezone from a timestamp late on August 20 UTC. This briefing uses August 20, 2026.
Volatile fields, meaning price, provider classification, supplemental terms listings, availability and serving telemetry, are dated wherever they appear and require rechecking before use.
Corrections policy: FSR retracts errors publicly with the original wording quoted, numbered and logged, rather than editing them away.
Affiliate disclosure: this is a Tier C briefing. FSR does not place affiliate links in Tier C briefings. This page carries none, and FSR receives nothing from OpenRouter, OpenCode, Nous Research, or any Ox Alpha access route.
Verdict
Third-party users and one public full run indicate material coding capability. No independent leaderboard has published a score, and FSR did not test the model, so this briefing takes no position on how good it is.
The procurement position is separate and it does not close. No route names the legal entity that receives a request. OpenRouter’s model page, its provider classification table, and the incorporated Stealth EULA describe the treatment of user content differently, and the terms of service disclaim liability for errors in exactly that kind of statement. The endpoint can be withdrawn without notice, and there is no published version identifier to pin.
Approve sanitized, non-sensitive evaluation. Do not approve confidential, customer, regulated, or export-controlled workloads, and do not build a production dependency, until a named processor, binding data terms, and endpoint continuity are established. The unresolved conditions are themselves the disqualifier, not a reason to wait and see.
Contact us
FSR reads the contract stack, separates vendor claims from what the agreement permits, and writes down what a buyer cannot verify. If you are running an entitlement or data-terms audit and want a second pass, get in touch.
Email the editorRelated briefings
Tier B means FSR tested the product hands-on inside a paid account. Tier C means the briefing is document-first, with no hands-on testing.
Three routes into one vendor, tested inside paid accounts, and the data controls each route actually hands the buyer.
What a buyer outside China can and cannot establish about access, payment and output rights from a vendor’s published terms.
The agent at the top of Ox Alpha’s public app list, and the terms its open license leaves to the portal.
A named vendor whose privacy and training documents contradict each other, and what a buyer can still rely on.
The same document-first method applied to a vendor that publishes more, and where the public record still stops.
What the transparency obligations say, what the code of practice adds, and which parts a buyer can check without counsel.
Future Stack Reviews is an independent publication and is not affiliated with OpenRouter, Inc., OpenCode, Nous Research, or any party discussed here. Nothing on this page is legal, tax, or export control advice. Pricing, availability and contract terms for preview models change without notice and should be verified at source before any decision. This page carries no affiliate links.
Last updated: 25 August 2026. Volatile fields rechecked: 25 August 2026, 00:46 and 10:08 JST.