TRUST CENTER

Enterprise Security for Sovereign AI Inference

ISO 27001 certified. No persistent storage of prompts or outputs. On EU sovereign models, your data stays in the EU.

Resources

ISO 27001:2022 Certified

Our information security management system is independently certified to the ISO 27001 international standard.

View Certificate: ISO 27001:2022 Certified

CSA STAR Level 1

We published our security self-assessment for AI services (CAIQ for AI v1.1.0) in the Cloud Security Alliance STAR Registry: model governance, data handling and security controls.

View Registry Entry: CSA STAR Level 1

How Your Data Flows

Your data is encrypted in transit and never written to disk.

  1. 01

    Your API Request

    Encrypted with TLS in transit

  2. 02

    Gateway in Munich

    Authentication and routing

  3. 03

    SambaRack Compute in Munich

    Inference - no persistent storage

  4. 04

    Response

    Returned encrypted - nothing written to disk

Infercom Infrastructure - Equinix MU4, Munich

Data Security

Technical safeguards for your data

Encryption in Transit

  • Every API request and response is encrypted with TLS in transit
  • TLS 1.3 supported, TLS 1.2 for older clients

No Persistent Storage

  • Prompts and responses are never written to disk
  • On MiniMax M2.7, repeated context is held briefly in the chips' memory for prompt caching, never on disk
  • Usage logs retain metadata only (timestamps, token counts, model used), not content. Retained for 90 days.

Our Own Hardware

  • Our own racks in Munich, not rented GPU cloud capacity
  • 8 SambaRack SN40L-16 racks with 128 RDUs, operated with SambaNova

Equinix Munich 4 (MU4)

  • ISO 27001, ISO 22301, SOC 1 and SOC 2 Type II certified facility
  • 24/7 on-site security staff with CCTV surveillance
  • Physical access control: mantrap entry, card readers, biometric verification

View Equinix MU4

EU Data Residency

Infercom SCS
Luxembourg legal entity
Equinix MU4, Munich
German data center
EU Sovereign Models
Inference runs in Munich
Data Jurisdiction
EU law governs, no US parent company

Compliance

ISO 27001 Certified
Information security management
DPA Available
GDPR Article 28 compliant
Subprocessors Listed
Listed in the DPA
ISO 27001 Audits
Surveillance audits per certification requirements

What We Don't Do

We don't train on your data

Infercom is inference-only. We run models, we don't train them. Your prompts are never used for training.

We don't store your prompts or responses

No persistent storage. Nothing from your request is written to disk.

We don't route EU sovereign model data outside the EU

EU sovereign models run in our data center in Munich.*

* Global catalog requests are processed on SambaNova Cloud outside the EU, in a region we do not control. Each model in the catalog is marked, so you choose where your data goes.

Frequently Asked Questions

Are you SOC 2 certified?

Not yet. We are ISO 27001 certified, which covers comparable information security controls.

Who operates the infrastructure?

Our compute infrastructure is operated by SambaNova under a managed services agreement. SambaNova is a US company with operational access to the Munich facility. This is disclosed in our DPA.

Can I get a custom DPA?

Enterprise customers can negotiate custom terms. Contact dpo@infercom.ai.

Do you train on my data?

No. We do not use your data to train, fine-tune, or improve AI models. Your prompts and outputs are processed transiently and discarded.

How long do you retain my data?

Inference data (prompts/outputs): Not stored persistently - processed in memory only. API metadata (timestamps, token counts): 90 days. Authentication logs: 12 months. See our Privacy Statement for full details.

Do you store prompts for caching?

Not on disk. On MiniMax M2.7, repeated context is held briefly in the chips' memory so long prompts start faster. It is evicted as new requests arrive and never written to disk.

What happens if there's a data breach?

We notify the supervisory authority (CNPD) within 72 hours and notify affected customers without undue delay where there is high risk to your rights and freedoms.

What are my data rights?

Under GDPR you have the right to access, rectify, erase, restrict, or port your data. You can also object to processing. Contact dpo@infercom.ai to exercise these rights.

Do you support private connectivity?

Not today: the API is reached over HTTPS on the public internet. For isolation, Dedicated Capacity gives you your own rack, and On-Premises puts the racks in your own datacenter.

How do I report a security vulnerability?

Email dpo@infercom.ai. We take all reports seriously and will respond promptly.

What's the difference between dedicated and on-premises?

Dedicated gives you your own rack in our data center in Munich (Equinix MU4) - full compute isolation while we handle facility operations. On-premises deploys hardware in your own facility, giving you complete physical control with an optional air-gapped configuration.

What models are available on dedicated or on-premises?

You're not limited to our standard model catalog. Custom model selection, specific checkpoints, and fine-tuned versions can be deployed based on your requirements.

Questions?

dpo@infercom.ai