Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Exoscale Managed Inference is operated by Akenes SA, a Swiss entity (Lausanne) that reports no CLOUD Act exposure and maintains a mature GDPR/FADP-aligned compliance program across its broader cloud platform, including an exceptionally deep certification stack (ISO 27001/27017/27018, SOC 2 Type II, BSI C5 Type 2, HDS, TISAX, CSA STAR). However, the specific Managed Inference product under review is pre-GA — marketed as 'Coming soon' with a waitlist and unpublished pricing — and its EU/Switzerland residency is described only as 'planned,' not contractually committed, which drags down serving_residency and serving_retention since no inference-specific retention or no-training guarantee exists yet. The composite lands in elevated_risk territory: security_posture is the clear strength (multiple current, sourced certifications on the underlying platform), while serving_residency and serving_retention are the weakest links because the product itself cannot yet be independently verified in production. Contractual posture and legal exposure are moderately solid, resting on Exoscale's general DPA and Swiss/GDPR framework, but the undisclosed AI-specific sub-processor chain adds residual uncertainty. Stav's operational verdict: this service is not yet suitable for sovereign-serving certification — treat it as routed-only pending GA launch, and re-score against Exoscale's live 'Dedicated Inference' product, which already offers a verifiable EU-only hosting guarantee, if an interim sovereign path is required.
Managed Inference is pre-GA ('Coming soon', waitlist) and its EU/Switzerland deployment locations are described only as 'planned,' so there is no live, verifiable EEA-only serving path today.
Certifications & legal documents
Operator Akenes SA is Swiss (non-EU but GDPR/FADP-aligned, CNIL as lead supervisory authority) with no declared CLOUD Act exposure, though the AI-specific sub-processor chain is not yet disclosed, leaving some downstream uncertainty.
No inference-specific prompt/output retention or no-training commitment has been published for Managed Inference, unlike the platform-wide DPA's generic 'Company Data' clauses.
Exoscale holds an unusually deep, sourced certification stack (ISO 27001/27017/27018, SOC 2 Type II, BSI C5 Type 2, HDS, TISAX, CSA STAR) covering the underlying cloud platform, though these are not yet independently confirmed against the specific Managed Inference product.
A standing DPA commits Akenes SA to GDPR/FADP compliance with sub-processor change notice and objection rights, but no inference-specific contractual terms exist yet since the product hasn't launched.
Risk assessment
Managed Inference is not yet generally available: the product page is headed 'Coming soon' with a 'Join the Waitlist' call to action, and states pricing tiers 'will be published upon launch,' meaning there is no live SLA, uptime track record, or production usage history for this specific service to evaluate. source ↗
RESILIENCERegional deployment for Managed Inference is described in future/planned tense — 'All models are planned to be deployed in both the EU and Switzerland locations' — rather than as a current, contractually committed residency guarantee, so customers cannot yet confirm actual physical execution location for a live workload. source ↗
DATA_RESIDENCYExoscale's disclosed sub-processor table for Compute/Storage/SKS currently lists no third-party processor and only Aiven Oy (Finland) for DBaaS; no AI/inference-specific sub-processor entry yet exists, so the downstream chain for the still-unlaunched Managed Inference product (e.g. any model-hosting or GPU-orchestration vendor) is not yet disclosed. source ↗
SUBPROCESSINGExoscale's corporate third-party provider list includes US-domiciled vendors (PayPal for payments, Twilio for authentication, and Amazon Web Services for data archival), representing some corporate/account data flow to US entities even though the privacy policy states client workload data is never transferred to these providers. source ↗
SUBPROCESSINGIndependent third-party uptime monitoring of Exoscale's general platform (not inference-specific) recorded 17 incidents in a recent 90-day window (2 major, 15 minor) with a median resolution time of about 65 minutes, and a longer-run average of over 6 incidents/maintenance events per month — indicating a non-trivial baseline of short operational disruptions on the shared platform Managed Inference will run on. source ↗
RESILIENCESafeguards
Exoscale's DPA (governing Akenes SA) commits to GDPR and Swiss FADP compliance, requires 30 days' advance notice before adding or replacing sub-processors, and grants the customer a right to object and terminate within 30 days if they disagree with a sub-processor change. source ↗
Exoscale states it protects data at rest and in transit across compute, local and block storage, snapshots, templates, APIs, and network communication, with centralized key lifecycle management via Exoscale KMS. source ↗
Exoscale's sibling live product, Dedicated Inference, explicitly commits that 'your data never leaves Europe,' hosted entirely in European, GDPR-compliant data centers, giving a verifiable sovereignty baseline for the AI-inference product line even though Managed Inference itself is pre-GA. source ↗
Exoscale publishes a dedicated compliance center mapping its security referential to the 32 Control Domains of the Secure Control Framework (SCF) and provides direct access to ISO certificates and audit reports. source ↗
Privacy-policy issues
No inference-specific retention/no-training commitment published source ↗
Because Managed Inference has not launched, there is no published statement (yet) on prompt/output retention windows or a no-training-on-customer-data guarantee specific to this service, unlike the general DPA's platform-wide 'Company Data' deletion-on-termination clause.
Website-scoped 'no encryption at rest' statement source ↗
The general Privacy Policy states 'Our data isn't encrypted at-rest' for website/account data, which appears to refer to marketing-site data rather than customer cloud workloads (which the Compliance page says are encrypted at rest), but the inconsistency in phrasing could confuse procurement reviewers.
AI/inference sub-processor chain not yet disclosed source ↗
The published sub-processor tables (privacy policy and DPA) cover Compute/Storage/SKS and DBaaS but do not yet list any processor specific to Managed or Dedicated Inference, so the downstream GPU/orchestration vendor chain for AI workloads is not independently verifiable from these documents.