Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Crusoe is a US-incorporated (Denver, DE) neocloud operator, meaning its serving stack is fully reachable under the CLOUD Act and FISA irrespective of the physical region — including its Iceland (EU) capacity — a decisive weakness that anchors the composite. Its strongest showing is security posture: current, third-party-sourced ISO 27001, ISO 42001 and SOC 2 Type II attestations plus a published DPA and subprocessor page, tempered by a documented 45-hour outage and an NDA-gated Statement of Applicability. Serving residency is weak in practice: EU capacity exists, but genuine sovereign/EU-only inference is only available via the newly announced (March 2026) contract-negotiated 'Edge Zones' product — with first hardware units expected Q3 2026 — not the standard default for managed or serverless endpoints. Retention and training practices at the serving boundary are not clearly documented beyond general DPA language, and contractual terms (SCCs, audit rights, breach-notification windows) are only partially confirmed publicly. Given the combination of unresolved US legal exposure and non-default EU residency, Stav treats Crusoe as routed-only for sovereignty-sensitive workloads pending a signed Edge Zones or equivalent residency-guaranteeing contract, which would constitute the required derogation.
Crusoe operates an EU (Iceland) region, but a genuinely sovereign/EU-only inference path is only offered via the newly-announced 2026 'Edge Zones' opt-in product rather than the default serving posture.
Certifications & legal documents
Crusoe is a US-incorporated entity (Denver, DE) and therefore remains fully subject to CLOUD Act/FISA reach over data it controls regardless of whether the underlying GPUs sit in the EU.
Crusoe publishes a GDPR-aligned DPA imposing subprocessor obligations, but no explicit prompt/output retention window or no-training-by-default commitment at the inference boundary was found.
Current, sourced ISO 27001, ISO 42001 and SOC 2 Type II certifications demonstrate a real security program, though a documented 45-hour regional outage and an NDA-gated Statement of Applicability limit pre-contract verifiability.
A standalone DPA with GDPR Article 28(3)-equivalent subprocessor terms and a public subprocessor-disclosure page exist, but SCC coverage, audit rights, and breach-notification SLAs are not independently confirmed.
Risk assessment
Crusoe is a US-incorporated company (Denver-based, founded 2018); as a US legal entity it is subject to CLOUD Act / US lawful-access requests over data it controls, independent of whether the underlying GPUs/data centers are located in the EU or elsewhere (e.g. its Iceland region). source ↗
LEGAL_EXPOSURETrue 'sovereign' or strictly jurisdiction-bound deployments are offered via a newly-launched 'Crusoe Edge Zones' product for customers with 'strict data residency requirements' — this is a bespoke, contract-negotiated option rather than a default guarantee across Crusoe's standard managed-inference / serverless endpoints. source ↗
DATA_RESIDENCYA Crusoe data center experienced a 45-hour outage that forced at least one GPU-cloud customer to fail over to another provider, with the customer describing the service as 'not as reliable.' source ↗
RESILIENCECrusoe paused development of a major 1.8GW Wyoming data-center campus at a customer's request after failing to secure certain hyperscaler tenants, illustrating execution/organizational volatility typical of a fast-scaling 'neocloud' still building out its infrastructure base. source ↗
GOVERNANCECrusoe's status page shows recurring planned network-maintenance windows causing intermittent regional hypervisor unavailability, including in its EU (Iceland) region, with customers advised to pause workloads during the window. source ↗
RESILIENCECrusoe relies heavily on debt and equity financing (e.g. $200M and $225M Nvidia-collateralized credit lines, a $750M Brookfield credit line, and a $15B JV for its Abilene campus) to fund its infrastructure build-out, indicating a leveraged, capital-intensive growth model typical of the 'neocloud' sector. source ↗
RESILIENCESafeguards
Crusoe has achieved ISO 27001 (information security management) and ISO 42001 (AI management system / responsible AI governance) certifications following independent third-party audits. source ↗
Crusoe Cloud has completed a SOC 2 Type II attestation, with reports available to customers/prospects via its Trust Center. source ↗
Crusoe publishes a standalone 'Data Processing and Security Terms' (DPA) that imposes GDPR Article 28(3)-equivalent obligations on any subprocessor when Customer Personal Data is subject to European Data Protection Law, and commits to using subprocessors only to the extent required to perform subcontracted obligations. source ↗
Crusoe maintains a public Subprocessors disclosure page referenced directly from its DPA, intended to be kept current as subprocessors are added. source ↗
Crusoe offers 'Edge Zones' / dedicated sovereign infrastructure deployments explicitly targeted at government entities and regulated industries with strict data-residency requirements. source ↗
A named enterprise customer (Windsurf) reports cluster uptime of 99.98% on Crusoe Cloud's NVIDIA H100 infrastructure. source ↗
Privacy-policy issues
No public breach-notification SLA window found source ↗
Neither the publicly-fetchable portions of the DPA nor the Trust Center content surfaced a specific stated breach-notification time window (e.g. '72 hours'), so customers cannot verify this commitment without requesting the full document under NDA.
Subprocessor list not independently verifiable source ↗
The public Subprocessors page is rendered client-side via Vanta and could not be read to confirm the actual current sub-processor entities, their locations, or whether any process data outside the EEA.
ISO Statement of Applicability gated behind NDA source ↗
The detailed scope of Crusoe's ISO 27001 Statement of Applicability is only available to prospects on request through a standard NDA process, limiting pre-contract due diligence.