Contact
Assess · Infercom

Can you own it?

Ownership levelSubstantialnone·limited·partial·substantial·fullAnalytical input B ยท 74/100

This page is a projection of the one entry record, the Use & modify and Transparency factors that Assess covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.

Which domain expands which factor
  • AssessUse & modify + Transparency
  • ImplementData control + Doesn't fail you
  • UseDoesn't fail you
  • SupportTransparency

Data governance - retention, ZDR & training

Zero data retention, set out in a binding Privacy Policy: the Privacy Policy states in terms that "Infercom does not store, log, or retain the content of your prompts or model outputs" - inference data is processed transiently and the content discarded - that Infercom "does not use inference data for model training, fine-tuning, or service improvement" (both EU-Hosted and Global Catalogue), and that usage logs hold metadata only - timestamps, model identifiers, token counts, response times, error codes, API key identifiers, not prompt/response content - for 90 days. These clauses were read this session, so the posture is contractual rather than marketing. A GDPR Art. 28(3) DPA (v1.3) sits on top - its Art. 28(3) nature, Luxembourg party and 2026-03-04 effective date are confirmed, though the PDF's full clause text is documented but unverified (unreadable behind the proxy this session). The catalogue is open-weight only, so no closed third-party model's data terms attach. One scope caveat separates cleanly from retention: the no-storage/no-training posture is uniform, but residency is not - see the jurisdiction item, where the default Global Model Catalogue routes non-EU-hosted models' prompts to the US. Sub-processors are not individually disclosed.

Data & IP ownership

Your data and the knowledge derived from it stay yours. The Privacy Policy and DPA state that data is not retained after inference, prompts are never used for training or service improvement, and Infercom serves open-weight models only - nothing is captured to improve the service and no closed-model vendor terms attach. Two caveats: the sub-processor list is not disclosed, and while ownership of your data holds across the catalogue, its location does not - non-EU-hosted models route prompt content to the US (see jurisdiction). Sign the DPA and pin EU-hosted models.

Data residency & jurisdiction

Pin EU-hosted models to get EU sovereignty - it is not automatic. EU-hosted models run in Munich (Equinix) under EU jurisdiction, stay in the EEA, and carry no US CLOUD Act / PATRIOT Act exposure. But Infercom's own Privacy Policy is explicit that the default Global Model Catalogue also serves non-EU-hosted models whose API requests, including prompt content, are routed to SambaNova's global infrastructure outside the EEA - primarily the United States - under Standard Contractual Clauses / EU-US Data Privacy Framework. Sovereignty is therefore a per-model choice, not a blanket property: pick EU-hosted models and the extraterritorial switch-off risk is effectively removed; use the Global Catalogue and your prompts can leave the EU under US jurisdiction.

Compliance & attestations

Infercom is ISO 27001 certified and has completed the Cloud Security Alliance's AI security assessment (CSA STAR / AI CAIQ), covering model governance, data handling and security controls. It aligns with GDPR, the German BDSG, and the EU AI Act. This is a genuinely strong, independently attested compliance posture for an EU adopter - the ISO certification is corroborated by third-party partnership announcements. SOC 2, ISO 27701 and HIPAA/BAA status are not confirmed; request those directly if your procurement requires them.

Security controls

Security rests on ISO 27001-certified security management, a completed CSA AI security assessment, and encryption in transit. This is stronger independent assurance than most newly launched providers offer. It is assessed as solid-but-partial only because the platform is newly launched and no independent penetration test beyond the ISO/CSA scope was surfaced this session.

Pricing & cost model

Pricing is pay-as-you-go for OpenAI-compatible inference. Exact per-model rates were not confirmed in the public sources reviewed this session, so treat the cost model as transparent-in-shape but confirm live per-model rates with the provider before committing.

Reliability posture

The underlying SambaNova RDU dataflow architecture is claimed to deliver up to 10x faster inference and 5x better energy efficiency than GPU alternatives. However, the platform is newly launched (first datacenter late 2025) and no public uptime SLA or history was independently verified, so reliability is assessed conservatively pending an observable track record.

How this scores

The ownership factors this domain covers, drawn from the one entry record.

1

Use and modify freelyCan you use it freely and leave without lock-in?

Strong

OpenAI-compatible API over portable open-weight models served in native BF16 - the SambaNova RDU is a provider-side dependency, but the same checkpoints run on GPU providers or self-hosted, so customer exit cost is low.

How this scores (AOI sub-dimensions)
Transparency & lock-in4/5how portable it is and how easily you can leaveOpenAI-compatible API over portable open-weight models keeps customer lock-in low.
Cost3/5how the pricing model compares and how predictable it isPay-as-you-go OpenAI-compatible pricing, but exact per-model rates were not confirmed in public sources and no independent cost benchmark was captured this session.
2

TransparencyAre the binding terms published, legible and independently checkable?

Moderate

The no-storage/no-training posture is legible in the binding Privacy Policy whose clauses were read this session, and the DPA is a confirmed Art. 28(3) agreement; the served catalogue is open-weight and inspectable. Held to moderate because the sub-processor list is not disclosed and the DPA PDF's full clause text was unreadable behind the proxy (documented but unverified).

How this scores
Not a scored AOI dimension. For a hosted provider, transparency is whether the binding terms are published, legible and were actually read - the read/unverified evidence below, not a certification. A strong rating here must trace to a retrieved binding document.
What this means for adoptionYou substantially own EU-sensitive workloads here: zero retention, prompts never trained on, metadata-only logs and a portable open-weight exit keep your data yours, and the posture is read from a binding Privacy Policy and an Art. 28(3) DPA rather than a marketing page. It stops short of full because sovereignty is conditional - Infercom's own Privacy Policy routes the default Global Model Catalogue's non-EU-hosted prompts to the US under SCCs - the platform is newly launched with no verified uptime SLA, and the sub-processor list is undisclosed. Pin EU-hosted models and sign the DPA to keep data in EU jurisdiction.

Sources

The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.

Vendor announcementunverified2026-07-25
Luxembourg-headquartered sovereign inference platform serving open-weight models on SambaNova RDU hardware with OpenAI-compatible APIs, EU sovereignty by default.
Vendor announcementread2026-07-25
Trust Centre (marketing surface): zero data retention, prompts never used for training, usage logs metadata only (timestamps/token counts/model, no content) with 90-day retention, ISO 27001 certified, CSA AI security assessment (CSA STAR Level 1 / AI CAIQ v1.1.0) completed, GDPR and EU AI Act alignment, encryption in transit.
Third-party analysisunverified2026-07-25
SambaNova partnership announcement - Infercom as a sovereign AI provider, Luxembourg HQ, EU jurisdiction, Munich deployment, ISO 27001, GDPR-safe/EU-compliant.
Third-party analysisunverified2026-07-25
SambaNova & Infercom Q&A - EU-hosted models on dedicated SambaNova RDU (SN40L) hardware at Equinix Munich; native BF16; three-tier memory; up to 10x faster / 5x more energy-efficient than GPU alternatives; first datacenter late 2025.
Third-party analysisunverified2026-07-25
Independent gateway partnership - open-weight models on SambaNova RDU dataflow hardware across EU, US and JP regions, OpenAI-compatible, no vendor lock-in.
Vendor announcementread2026-07-25
Zero Data Retention glossary - after inference completes the data is gone; prompts are never used for training.
Vendor announcementunverified2026-07-25
EU Sovereign AI page - EU-hosted models keep data in the EU; data never leaves the European Union.
Privacy Policyread2026-07-25
Privacy Policy (binding, clauses read this session): "Infercom does not store, log, or retain the content of your prompts or model outputs" - inference data is processed transiently, passed to the inference engine and the content discarded - and Infercom "does not use inference data for model training, fine-tuning, or service improvement" for both EU-Hosted Models and the Global Model Catalogue.
Data Processing Addendumunverified2026-07-25
Data Processing Agreement v1.3 - an Article 28(3) GDPR controller-processor agreement with Infercom SCS (Luxembourg-incorporated), effective 2026-03-04, imposing Articles 28-33 processor obligations.
Privacy Policyread2026-07-25
Privacy Policy (binding, clause read this session): for Global Model Catalogue models not hosted on EU infrastructure, "your API requests (including prompt content) are routed to SambaNova's global infrastructure outside the EEA, primarily in the United States"; Infercom uses EC Standard Contractual Clauses (Decision 2021/914) as the primary transfer mechanism, with EU-US Data Privacy Framework certification as an additional basis.