Enterprise software, security and engineering notes

Connecting the EVREN API to Enterprise Software: Middleware, Model Routing and KVKK

AI and Agents ·

EVREN API integration — close-up of server hardware in a data center | Aksiyon Soft

Connecting the EVREN API to enterprise software: a technical guide

The EVREN API gives programmatic access to the large language model inference service of EVREN, Türkiye’s national AI platform, which opened for wide use at the end of September 2026. According to Anadolu Agency, the platform was developed within the Presidency of Defence Industries (SSB), and prompts, responses and usage data are processed on GPU infrastructure in Türkiye. According to the newspaper Dünya, 11 models are offered behind a single OpenAI-compatible API. For businesses that want to keep data in the country, that is a new way to add language models to ERP, CRM and document systems.

This article is a technical guide and commentary: Aksiyon Soft has no partnership or official cooperation with the Presidency of Defence Industries or EVREN. We only use information we could verify in public sources, and we explain how an enterprise application can connect to EVREN safely and without lock-in: architecture, environment variables, client code, model routing and fallback, the KVKK (Turkish data protection law) assessment, credit planning after 1 November and document use cases.

In short

  • EVREN’s inference service is OpenAI-compatible; as a rule, existing clients only need a new address and key.
  • Do not guess the API address: keep the address shown in the platform dashboard in EVREN_BASE_URL and the key in EVREN_API_KEY.
  • Connect applications to a middleware layer that classifies data and manages fallback, not directly to a model.
  • Processing in Türkiye is a strong plus under KVKK, but it does not remove notice, legal basis and data minimisation duties.
  • According to AA, API calls are not deducted from credit until 1 November 2026; use this window to measure usage.
Diagram: EVREN API integration — apps, middleware / LLM router, EVREN and a fallback provider
Suggested flow: applications call the middleware, which routes to EVREN or a fallback provider based on data class (Aksiyon Soft diagram).

What do we know for certain about EVREN?

Before deciding on an integration, separate what is confirmed from what is still unclear. These are the main points we could verify in public sources:

  • Access and audience: according to AA, the platform is open to defence companies, technology firms, academics, startups and students; access is through e-Devlet (Türkiye’s e-government gateway) and it uses a contribution-based credit system.
  • Inference layer: AA reports 11 open-weight language models in the inference layer, streaming support and automatic model routing, with 7,500 active users.
  • Infrastructure: according to the SSB announcement shared on LinkedIn, the model fleet runs on a domestic bare-metal H200 cluster and offers a context window of up to 1 million tokens.
  • Easy switching: the same announcement says existing applications only need to change the address and key, with no separate contract, application or invoicing process.
  • Credit: AA and the announcement both state that API calls made before 1 November 2026 are not deducted from credit.

The platform has other components too. The Apache-2.0 licensed evren-sdk package on PyPI offers computer vision functions such as object detection, classification, segmentation and edge inference, plus an LLM gateway client. A letter from the IT Department of YÖK (the Council of Higher Education) dated 17 June 2026 presents EVREN as an end-to-end MLOps platform built on a credit model and e-Devlet login. For more on these developments, see our news coverage: EVREN’s launch, the 11-model OpenAI-compatible inference service, the EVREN SDK and computer vision and the MLOps platform opening to universities.

The open questions should be noted as well: how credit is consumed after 1 November, quotas and rate limits, service level commitments and how the model list will change over time are not clear from public sources. So the integration should be designed on the assumption that these values can change.

Architecture: how should the flow between apps, middleware and EVREN work?

The most common mistake is letting every application connect to the model provider on its own. Five teams write five clients, keys spread across repositories and nobody can tell which personal data went where. In the setup we recommend, applications such as ERP, CRM, the customer portal, the e-document archive and internal search talk only to an in-house middleware layer (an LLM router or AI gateway). This layer:

  1. Tags each request by data class: personal, internal or public.
  2. Masks personal data or rejects the request when needed.
  3. Picks a model and quota based on task type.
  4. Logs cost, latency and error rate.
  5. On failure, switches to a fallback provider only for permitted data classes.

We cover this approach in detail in the AI Ops layer, LLM router and KVKK and taking AI agents to production. The middleware’s connections to ERP and CRM are classic API and integration work; authentication, retries, idempotency and monitoring need the same discipline. An API and data integration platform is a natural home for this layer when several systems must be managed from one place.

Why move the address and key into environment variables?

Do not hard-code the EVREN API address from a blog post, a forum or a guess. The correct address is the one shown in the platform dashboard you sign into through e-Devlet; the dashboard address and the API address are not the same thing. Moving the address and key into environment variables brings three benefits: you can use different keys for development, test and production; you can rotate a leaked key without changing code; and switching providers becomes a configuration change.

# .env.example — real values live in a secret store (vault / secret manager)
EVREN_BASE_URL=<address shown in the platform dashboard>
EVREN_API_KEY=<read from the secret store>
EVREN_CHAT_MODEL=<chat model listed in the dashboard>
EVREN_EMBED_MODEL=<embedding model listed in the dashboard>

Because the service is OpenAI-compatible, the official openai Python client can be used by changing only the address and key. The example below is a generic template; take model names from the dashboard list.

import os
from openai import OpenAI

# The address and key are never hard-coded; they come from the environment
client = OpenAI(
    base_url=os.environ["EVREN_BASE_URL"],
    api_key=os.environ["EVREN_API_KEY"],
    timeout=30,
    max_retries=2,
)

response = client.chat.completions.create(
    model=os.environ["EVREN_CHAT_MODEL"],
    messages=[
        {"role": "system", "content": "Answer only from the document provided."},
        {"role": "user", "content": "Extract the due date and total amount from this invoice: ..."},
    ],
    temperature=0.2,
)
print(response.choices[0].message.content)
Python code on screen — calling the EVREN API with an OpenAI-compatible client
When an OpenAI-compatible client reads its address and key from the environment, switching providers becomes a configuration task. Image: Unsplash.

How should model routing and fallback work?

The SSB announcement lists the 11 models in four categories. In an enterprise application, sending every task to the largest model is wasteful; choosing the category that fits the task lowers both cost and latency. The table below maps the categories to typical enterprise use cases. The model list may change, so always confirm current names in the dashboard.

Model category Models named in the announcement Enterprise use case
Reasoning · code · agent glm-5.3, deepseek-v4-flash, qwen3.8-flash-next, gemma-4-31b Internal assistant, report summaries, coding help, tool-calling agent workflows
Vision and video qwen3-vl-30b Interpreting fault or product photos, reading screenshots, visual quality checks
Retrieval · embedding · safety qwen3-embedding-8b, qwen3-reranker-8b, qwen3guard-4b Document search (RAG), re-ranking results, input and output safety filtering
Document and speech dots-ocr, deepseek-ocr-2, qwen3-asr-1.7b OCR for e-documents and scanned archives, transcribing call recordings

The fallback rule should be simple: requests with personal or sensitive data stay on EVREN; on failure the user gets a clear message and the request is queued. Non-sensitive requests can be routed to a second provider. The TypeScript example below applies that rule in the middleware:

import OpenAI from "openai";

type Sensitivity = "personal" | "internal" | "public";

const evren = new OpenAI({
  baseURL: process.env.EVREN_BASE_URL,
  apiKey: process.env.EVREN_API_KEY,
});

const fallback = new OpenAI({
  baseURL: process.env.FALLBACK_BASE_URL,
  apiKey: process.env.FALLBACK_API_KEY,
});

export async function complete(prompt: string, sensitivity: Sensitivity) {
  const messages = [{ role: "user" as const, content: prompt }];
  try {
    return await evren.chat.completions.create({
      model: process.env.EVREN_CHAT_MODEL!,
      messages,
    });
  } catch (err) {
    // Requests containing personal data are never sent to the fallback provider
    if (sensitivity === "personal") throw err;
    return fallback.chat.completions.create({
      model: process.env.FALLBACK_CHAT_MODEL!,
      messages,
    });
  }
}

According to AA, EVREN also has automatic model routing on its side. Even so, keep routing in your own middleware: data class, budget and fallback decisions are your policy, and the record of them should stay with you.

How should the EVREN API be assessed under KVKK?

Processing prompts, responses and usage data on infrastructure in Türkiye largely removes the question of transferring data abroad, which is a significant advantage in a KVKK assessment. But processing in the country does not equal compliance on its own. The assessment should answer these questions:

  • Are the legal basis and privacy notice for the personal data being processed up to date?
  • Is only the data the request really needs being sent, or the whole record? (data minimisation)
  • What do the platform’s terms of use say about retention, logging and data use?
  • Do middleware logs contain personal data, how long are they kept and who can access them?
  • Should special categories of personal data (health, biometrics and so on) be in the flow at all?

Work through these questions with your legal adviser; this article is not legal advice. On the technical side, applying masking, field-level filtering and a log retention policy in the middleware makes life easier whatever the decision.

Server room render — processing data inside Türkiye and the KVKK assessment
Processing data in Türkiye simplifies the KVKK assessment but does not remove notice and minimisation duties. Image: Unsplash.

How should you plan credit after 1 November?

According to AA, API calls on EVREN are not deducted from credit until 1 November 2026, and the platform uses a contribution-based credit system overall. The consumption rules after that date are not publicly detailed. The best way to handle the uncertainty is to treat the free period as a measurement period:

  • Log the application, department, model and token count of every request in the middleware.
  • Work out average token usage per task and identify the ten most expensive flows.
  • Use caching and short system prompts for frequently repeated questions.
  • Route simple classification and extraction tasks to smaller models.
  • Set monthly budgets and threshold alerts per department.

That way, when the credit rules become clear after 1 November, you can plan usage from real data rather than estimates. Any decision to move certain flows to a fallback provider or your own infrastructure rests on the same data.

Which OCR and embedding use cases fit e-documents and document search?

The OCR models in the document and speech category, combined with the embedding and re-ranking models, are the combination that adds the most value in enterprise document management. A typical flow works like this: a scanned contract, delivery note or letter is converted to text with an OCR model; the text is split into meaningful chunks; each chunk is turned into a vector with an embedding model and stored in an in-house vector database. When a user asks a question, the most relevant chunks are found, filtered with the re-ranking model, and the chat model answers only from those chunks while citing them. The safety model can also check inputs and outputs for policy violations.

If the embedding models are exposed through the OpenAI-compatible embeddings endpoint, the call is as simple as the one below; confirm endpoint support in the dashboard documentation.

chunks = ["Contract clause 7: delivery period ...", "Delivery note no ... line items ..."]

emb = client.embeddings.create(
    model=os.environ["EVREN_EMBED_MODEL"],
    input=chunks,
)
vectors = [item.embedding for item in emb.data]
# vectors are written to an in-house vector database together with document ID and access rights

The most important point in this scenario is authorisation: a user should only see chunks from documents they are allowed to see. So every vector is stored with the access information of its source document, and search is filtered on it.

Stacks of paper documents and file folders — document search with OCR and embedding models
Used together, OCR, embeddings and re-ranking turn a scanned archive into a searchable knowledge source. Image: Unsplash.
Nutanix: what an AI gateway is and why LLM workloads need one — a short explainer of the middleware approach.

EVREN API integration checklist

  • The API address was taken from the platform dashboard; no guessed address is used anywhere.
  • EVREN_BASE_URL and EVREN_API_KEY live in a secret store, with a separate key per environment.
  • All applications reach EVREN only through the middleware layer.
  • Requests are tagged by data class; personal data never goes to the fallback provider.
  • A KVKK assessment was done with a legal adviser and privacy notices were updated.
  • Tokens, cost, latency and error rate are measured per department.
  • Model names live in configuration and can be updated without code changes when the dashboard changes.
  • In document search, vectors are stored and filtered together with access rights.

How can Aksiyon Soft help?

Aksiyon Soft is a software company headquartered in Samsun that works remotely with organisations across Türkiye, with planned on-site visits for discovery or go-live when needed. When connecting EVREN or any other model provider to enterprise systems, we follow this rhythm:

  • Discovery: mapping use cases, data classes, a KVKK question list and existing ERP/CRM connections.
  • MVP: putting the middleware live with a single use case (for example document search) and setting up measurement.
  • Sprint demos: working integration, cost and latency reports shared every two weeks.
  • Hypercare and SLA: close monitoring after go-live, then maintenance and model updates under a written service level.

For SMEs that want to start within a ninety-day frame, our 90-day AI roadmap based on TurkStat 2026 data is a good starting point.

Frequently asked questions

Do we need a separate contract to use the EVREN API?

According to the SSB announcement, no separate contract, application or invoicing process is needed; access is through the platform you sign into with e-Devlet. For enterprise use we recommend reading the platform’s terms of use with your legal team.

What is the EVREN API address?

Take it from the platform dashboard. We deliberately do not give an address here; the dashboard address and the API address differ, and a guessed address may not work and can be a security risk. Keep the address in the EVREN_BASE_URL environment variable.

Do we have to change our existing OpenAI-based code?

Because the service is OpenAI-compatible, changing the address, key and model name is usually enough. Still, test features such as tool calling, structured output and the embeddings endpoint against your own use case.

Is sending requests with personal data to EVREN compliant with KVKK?

Processing data in Türkiye largely removes the cross-border transfer question, but the legal basis, notice and data minimisation obligations remain. The final assessment should be made with your legal adviser.

What happens if EVREN is unavailable?

The fallback rule in the middleware kicks in: non-sensitive requests go to a second provider, requests with personal data are queued and the user sees a clear message.

What will it cost after 1 November 2026?

According to AA, API calls are not deducted from credit until that date; details beyond it are not clear in public sources. Measuring token usage now and setting budgets per department is the soundest approach.

Sources

Let’s talk about your project

If you want to connect your ERP, CRM or document systems to the EVREN API or another model provider through a secure middleware layer, get in touch. In the first conversation we can clarify your data classes and pilot use case together.

Subscribe to blog and news

Get an email when we publish. Unsubscribe any time.

Related posts