Loading the catalogue…
Loading the catalogue…
Compliance posture
About the Stav Sovereignty Ladder →
Stav's assessment · serving-side
Baseten is a US-incorporated (Delaware-governed) managed inference platform that layers optimized serving atop rented multi-cloud GPU capacity, with EU/UK 'regional environments' available only as an opt-in, support-configured deployment rather than a default. The composite lands in elevated-risk territory primarily because the two sovereignty-weighted dimensions — serving residency and legal exposure — are weak: EU residency is not guaranteed absent manual setup and has already shown dependence on third-party cloud outages, and the US-domiciled operating entity remains fully subject to CLOUD Act reach irrespective of where workloads are pinned. This is offset by genuinely strong serving-side hygiene: no default retention of prompts, outputs, or weights, current and sourced SOC 2 Type II and SOC 3 attestations plus a Drata-driven HIPAA self-certification, and a contractually defined audit-rights process, though the scope of SCC coverage in the embedded European Annex has not been independently confirmed and an EU-only processing commitment is not yet documented. Security posture and retention practices are the strongest dimensions; legal exposure is the clear weakest, with residency close behind due to its non-default, request-based nature. Given US incorporation and unconfirmed default EEA residency, Stav treats Baseten as routed-only for sovereignty-sensitive workloads — sovereign serving would require a customer-specific regional-environment configuration plus contractual EU-only processing commitments before it could be upgraded.
EU/UK regional environments exist but require a manual support request to configure rather than being default, and the documented EU cluster outage confirms EU-labelled clusters ride on underlying third-party cloud capacity rather than fixed sovereign infrastructure.
The contracting entity, Baseten Labs, Inc., is US-incorporated and Delaware-governed, placing it squarely under CLOUD Act reach regardless of EU-region hosting, and its subprocessor list is expanding to include additional non-hyperscaler GPU cloud vendors that widen the exposure chain.
Baseten documents that it does not store model inputs, outputs, or weights by default at the serving boundary.
Baseten holds current, sourced SOC 2 Type II (clean opinion), SOC 3, and HIPAA attestations along with a published vulnerability-disclosure channel, though no ISO 27001/27018 certification is on record.
Risk assessment
The contracting entity, Baseten Labs, Inc., is US-incorporated, gives a San Francisco address, and its agreement is governed by Delaware law — meaning the operator is subject to US CLOUD Act / lawful-access jurisdiction irrespective of any EU-region hosting configuration. source ↗
LEGAL_EXPOSUREEU/regional data residency is not the default: Baseten's regional environments (which guarantee traffic stays within a designated region such as EU, UK, US, or Australia) 'require initial configuration by Baseten' via a support request rather than being a self-serve or default setting, so an unconfigured account may run on globally distributed workload planes. source ↗
DATA_RESIDENCYBaseten's own status page recorded an incident of 'Elevated inference 500s for models in an EU cluster due to provider outage,' confirming EU-labelled clusters are themselves dependent on an underlying third-party cloud provider, not sovereign fixed infrastructure. source ↗
DATA_RESIDENCYBaseten's disclosed subprocessor list is actively changing to include smaller, less-established GPU cloud vendors (ScitiX, Hyperstack, Latitude) for cloud infrastructure, widening the downstream vendor chain beyond major hyperscalers and increasing due-diligence burden for regulated customers.
Safeguards
Baseten does not store model inputs, outputs, or weights by default at the serving boundary. source ↗
Baseten holds SOC 2 Type II certification with a clean (no exceptions) audit opinion, plus SOC 3 public report and HIPAA compliance. source ↗
Baseten supports region-locked 'regional environments' (US, EU, UK, Australia) that constrain replicas and route inference exclusively within the designated region for compliance needs such as GDPR. source ↗
Baseten's standard terms grant customers audit rights, with a defined process (proposed audit plan, 14-day notice) and allow acceptance of existing SOC 2 Type 2/ISO/NIST reports in lieu of a full audit when controls are already covered. source ↗
Baseten operates a published vulnerability disclosure channel (security@baseten.co) via its Trust Center. source ↗
Privacy-policy issues
EU residency requires manual setup, not default source ↗
Regional data-residency guarantees are only available after Baseten support configures a restricted regional environment for the account, so an EU enterprise using default settings may not get residency assurances automatically.
No published EU-only processing commitment source ↗
As of a recent third-party review, Baseten had not published an EU-only data processing commitment on its public pages, leaving European buyers to perform their own transfer-impact assessment.
Certifications & legal documents
A DPA is available with defined audit rights (proposed plan, 14-day notice, acceptance of existing SOC 2 reports), but no explicit SCC coverage or EU-only processing commitment is published for European buyers.
Baseten's public status page shows a recurring cadence of minor incidents (elevated errors/500s for specific models, metrics degradation) through August 2026, indicating operational noise, though Dedicated Inference was repeatedly noted as unaffected. source ↗
RESILIENCEBaseten publishes and updates a subprocessor list (with changelog entries for additions/removals) on its SafeBase-hosted Trust Center, and notifies customers of changes via privacy@baseten.co. source ↗
Baseten publishes a public real-time status page with incident and uptime history via Atlassian Statuspage. source ↗