TRUST CENTER
Enterprise Security for Sovereign AI Inference
ISO 27001 certified. No persistent storage of prompts or outputs. On EU sovereign models, your data stays in the EU.
Resources
ISO 27001:2022 Certified
Our information security management system is independently certified to the ISO 27001 international standard.
View Certificate: ISO 27001:2022 CertifiedCSA STAR Level 1
We published our security self-assessment for AI services (CAIQ for AI v1.1.0) in the Cloud Security Alliance STAR Registry: model governance, data handling and security controls.
View Registry Entry: CSA STAR Level 1How Your Data Flows
Your data is encrypted in transit and never written to disk.
- 01
Your API Request
Encrypted with TLS in transit
- 02
Gateway in Munich
Authentication and routing
- 03
SambaRack Compute in Munich
Inference - no persistent storage
- 04
Response
Returned encrypted - nothing written to disk
Infercom Infrastructure - Equinix MU4, Munich
Data Security
Technical safeguards for your data
Encryption in Transit
- Every API request and response is encrypted with TLS in transit
- TLS 1.3 supported, TLS 1.2 for older clients
No Persistent Storage
- Prompts and responses are never written to disk
- On MiniMax M2.7, repeated context is held briefly in the chips' memory for prompt caching, never on disk
- Usage logs retain metadata only (timestamps, token counts, model used), not content. Retained for 90 days.
Our Own Hardware
- Our own racks in Munich, not rented GPU cloud capacity
- 8 SambaRack SN40L-16 racks with 128 RDUs, operated with SambaNova
Equinix Munich 4 (MU4)
- ISO 27001, ISO 22301, SOC 1 and SOC 2 Type II certified facility
- 24/7 on-site security staff with CCTV surveillance
- Physical access control: mantrap entry, card readers, biometric verification
EU Data Residency
- Infercom SCS
- Luxembourg legal entity
- Equinix MU4, Munich
- German data center
- EU Sovereign Models
- Inference runs in Munich
- Data Jurisdiction
- EU law governs, no US parent company
Compliance
- ISO 27001 Certified
- Information security management
- DPA Available
- GDPR Article 28 compliant
- Subprocessors Listed
- Listed in the DPA
- ISO 27001 Audits
- Surveillance audits per certification requirements
What We Don't Do
We don't train on your data
Infercom is inference-only. We run models, we don't train them. Your prompts are never used for training.
We don't store your prompts or responses
No persistent storage. Nothing from your request is written to disk.
We don't route EU sovereign model data outside the EU
EU sovereign models run in our data center in Munich.*
* Global catalog requests are processed on SambaNova Cloud outside the EU, in a region we do not control. Each model in the catalog is marked, so you choose where your data goes.
Enterprise Security Options
Additional capabilities for organizations with stricter security requirements.
- Dedicated Rack Dedicated infrastructure with full compute isolation - no shared resources. Custom model selection and checkpoints supported.
- On-Premises Deployment Hardware deployed in your own datacenter. Complete physical and network control, with air-gapped option for highly regulated environments.
Frequently Asked Questions
Are you SOC 2 certified?
Not yet. We are ISO 27001 certified, which covers comparable information security controls.
Who operates the infrastructure?
Our compute infrastructure is operated by SambaNova under a managed services agreement. SambaNova is a US company with operational access to the Munich facility. This is disclosed in our DPA.
Can I get a custom DPA?
Enterprise customers can negotiate custom terms. Contact dpo@infercom.ai.
Do you train on my data?
No. We do not use your data to train, fine-tune, or improve AI models. Your prompts and outputs are processed transiently and discarded.
How long do you retain my data?
Inference data (prompts/outputs): Not stored persistently - processed in memory only. API metadata (timestamps, token counts): 90 days. Authentication logs: 12 months. See our Privacy Statement for full details.
Do you store prompts for caching?
Not on disk. On MiniMax M2.7, repeated context is held briefly in the chips' memory so long prompts start faster. It is evicted as new requests arrive and never written to disk.
What happens if there's a data breach?
We notify the supervisory authority (CNPD) within 72 hours and notify affected customers without undue delay where there is high risk to your rights and freedoms.
What are my data rights?
Under GDPR you have the right to access, rectify, erase, restrict, or port your data. You can also object to processing. Contact dpo@infercom.ai to exercise these rights.
Do you support private connectivity?
Not today: the API is reached over HTTPS on the public internet. For isolation, Dedicated Capacity gives you your own rack, and On-Premises puts the racks in your own datacenter.
How do I report a security vulnerability?
Email dpo@infercom.ai. We take all reports seriously and will respond promptly.
What's the difference between dedicated and on-premises?
Dedicated gives you your own rack in our data center in Munich (Equinix MU4) - full compute isolation while we handle facility operations. On-premises deploys hardware in your own facility, giving you complete physical control with an optional air-gapped configuration.
What models are available on dedicated or on-premises?
You're not limited to our standard model catalog. Custom model selection, specific checkpoints, and fine-tuned versions can be deployed based on your requirements.
Questions?
dpo@infercom.ai