Loading the catalogue…
Loading the catalogue…
Compliance posture
About the Stav Sovereignty Ladder →
Stav's assessment · serving-side
Berget AI is a Swedish-incorporated operator (Berget AI AB, Stockholm) running inference exclusively on its own GPU infrastructure across Swedish data centers, with no third-country data transfer by design and no CLOUD Act exposure — a strong sovereignty and residency posture that anchors the score. Retention practice is similarly favorable: prompts and outputs are reportedly never stored, only service metadata, though this commitment sits in Terms rather than an audited technical control. The composite is held back by security and contractual weaknesses: ISO 27001 is still 'in progress' rather than certified, the service is offered on an as-is basis with service-credit-only SLA remedies, and no public sub-processor list confirms the absence of third-country data flows. As an early-stage company (founded 2024, small team), organizational continuity and independent verification remain open questions. Given strong residency and legal-exposure fundamentals offset by unaudited security claims and thin contractual protections, Stav's verdict is conditional: sovereign serving is plausible but should be treated as routed-only pending ISO 27001 completion, DPA review, and sub-processor disclosure.
Berget operates its own GPU infrastructure across multiple Swedish data centers with inference, storage, and processing confined to that network and no reliance on non-EU hyperscalers.
Berget AI AB is a Stockholm-incorporated entity with no US parent and no hyperscaler sub-processor in the compute path, though the absence of a published sub-processor list leaves some third-country dependency unverified.
Terms of Service commit to never storing prompt or output content by default (only billing/operations metadata), a strong zero-retention posture that is not yet independently audited.
ISO 27001 is explicitly 'in progress' rather than achieved, so technical/organisational controls and a public disclosure program exist but lack an independently audited certificate.
Risk assessment
Berget has not yet achieved ISO 27001 certification; its own Terms of Service state the company is 'actively working toward' it, meaning no independently audited ISMS certificate currently exists to verify security claims. source ↗
SECURITYThe Service is provided on an 'as-is'/'as-available' basis with no warranty of merchantability, fitness for purpose, or non-infringement; SLA compensation for outages is paid only in non-cash service credits, not liability damages. source ↗
CONTRACTUALBerget explicitly disclaims uninterrupted/error-free service and states it does not guarantee fail-safe performance; disaster-recovery backups apply to core systems but explicitly exclude Customer Data unless separately agreed in writing. source ↗
RESILIENCEBerget AI is a very early-stage company (founded 2024, seed-stage funding of roughly €2.1M, reported team size of 1-10), which raises organisational and financial-continuity questions for enterprises evaluating long-term vendor stability.
Safeguards
Berget states all inference, storage and processing happens on its own European (Swedish) infrastructure, with data never leaving that infrastructure and inference running entirely within its own network rather than traversing the public internet. source ↗
Berget's Terms of Service state it will never store actual prompt input content or LLM output content, collecting only service/API metadata (logs, token counts, timestamps) for billing and operations. source ↗
A Data Processing Agreement (DPA), Service Level Agreement (SLA) and Acceptable Use Policy (AUP) are formal supplements to the Terms of Service, with the DPA taking first precedence in case of conflict. source ↗
Berget operates a public responsible-disclosure / vulnerability-reporting program with GitHub private advisories, a published PGP key, a Signal contact channel, and a stated 48-hour initial response commitment plus safe-harbor terms for good-faith researchers. source ↗
Berget applies industry-standard technical/organisational measures including encryption in transit, network isolation, access controls and system monitoring, and is actively pursuing ISO 27001 certification.
Privacy-policy issues
No named public sub-processor list found source ↗
No publicly accessible, named sub-processor list (cloud/CDN/logging vendors) was found on Berget's own domain during this review, despite Berget's own-infrastructure claims.
Website privacy policy scope mismatch source ↗
The published Privacy Policy addresses website/marketing personal data processing (GDPR rights, cookies, analytics) rather than the API/inference serving relationship, so enterprise customers must rely on the separate DPA for service-level data handling terms.
Certifications & legal documents
A DPA/SLA/AUP framework exists and takes precedence over the ToS, but the service is offered 'as-is' with service-credit-only remedies, no liability warranty, and no named sub-processor list.
The published website Privacy Policy covers website/marketing personal data (identity, contact, technical, usage data) rather than the API-serving data-processing relationship; the substantive processing terms sit in a separately referenced Data Processing Agreement (DPA) that was not independently reviewed in this run. source ↗
GOVERNANCEBerget operates its own GPU-based infrastructure across multiple data centers rather than relying on a third-party hyperscaler, reducing dependency on non-EU cloud sub-processors for the core compute layer. source ↗