Loading the catalogue…
Loading the catalogue…
Proving where your AI runs is the slow part of shipping it. Stav makes jurisdiction a policy you set and a record you can hand to a regulator — so the compliance work is done as you build, not after.
Sovereignty isn’t a checkbox at signup. It’s enforced on each request and recorded for each one.
Set sovereign-only per team or route. The Smart Router will never send a matching request outside EU jurisdiction — it’s blocked, not warned.
Every request logged with model, provider, country, classification and outcome. The evidence your auditor asks for, generated as you build.
Tiered retention for request, audit and routing logs — 7 days to 7 years — matched to your obligations, not ours.
Export a GRC-ready record of any period in one click — for an EU AI Act file, a DORA review or a customer security questionnaire.
Per-team budgets and cost-aware routing keep frontier usage intentional — finance and compliance reading the same dashboard.
Developers keep their SDK and ship faster; compliance gets governance it didn’t have to build. Everyone wins.
The EU AI Act’s core obligations phase in from August 2026. Stav’s architecture is built to the regimes your enterprise already lives under. Stav provides compliance features and evidence — not legal advice; your DPO makes the determination, we give them the controls and the paper trail.
System inventory, provenance and documentation support for deployer obligations.
Special-category data stays in-jurisdiction; lawful basis and retention are explicit.
Sovereign routing keeps reasoning outside US compulsion. Exemption by architecture.
Third-party risk, concentration and resilience evidence for financial entities.
Supply-chain security posture and incident-ready logging across the stack.
The EU’s proposed four-level sovereign-cloud standard, in trilogue now. Stav’s provider mix maps to L3/L4, building on EUCS tiers, with an indicative level per provider.
The Cloud and AI Development Act proposes a four-level sovereign-cloud standard, recognised by a Member-State audit. It’s a proposal — June 2026, now in trilogue — so the levels here are Stav’s indicative reading of the draft, not an official certification. But the audit it foresees runs on exactly the evidence the control plane already produces.
From L1 (data in the EU) to L4 (full control, no third-country interference). A region toggle reaches L1; the top rungs are measured by who controls the stack.
A CADA level is conferred by a Member-State audit — and an audit runs on evidence. The per-request jurisdiction log and one-click export you already get is the paper trail it asks for.
Stav is an EU company that grades every operator it routes to and enforces the floor you set. Raise the floor to L3 or L4 and your policy reaches those providers without a migration — the floor moves, your code does not.
Sovereign by default, frontier when it’s worth it, every request provable. One line to migrate.