Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Infomaniak AI Tools is operated by a Switzerland-incorporated entity serving inference exclusively from its own Swiss data centres, with no reliance on US hyperscalers and no CLOUD Act exposure — a strong sovereignty story overall, but Switzerland itself sits outside the EU/EEA, which caps the serving_residency score despite the absence of any non-EEA fallback path. Legal exposure is the standout strength: a Swiss operator, a GDPR/FADP-aligned DPA, and no documented US-parent or hyperscaler dependency in the serving path keep third-country lawful-access risk low. Retention and security posture are solid — no training on customer prompts and a current, sourced ISO/IEC 27001:2022 certification with a public bug-bounty programme — though the strongest no-logging claim lives in marketing copy rather than the formal legal text, and no SOC 2 or equivalent audit attestation was located. Contractual posture is adequate but incomplete: the published DPA is a general hosting agreement rather than an AI-Tools-specific addendum, and it lacks an enumerated sub-processor list and an explicit breach-notification timeframe. On balance this is a low-risk, well-governed provider whose principal gap is EEA-strict residency rather than legal or security weakness; Stav's verdict is conditional — this is a routed (non-EEA-resident) option today, best paired with sub-processor disclosure and an AI-Tools-specific DPA addendum before treating it as sovereign EEA serving.
Inference runs exclusively on Infomaniak's own Swiss data centres with no non-EEA fallback, but Switzerland is outside the EU/EEA, so the strict physical-EEA-presence bar is not met despite a strong sovereignty design.
Certifications & legal documents
Infomaniak is Swiss-incorporated with no CLOUD Act exposure and a DPA grounded in GDPR Art.28 and the Swiss FADP, though the full sub-processor chain is not publicly enumerated.
Infomaniak states customer queries are neither logged nor used to train models, but this claim appears mainly in marketing material rather than being restated with the same precision in the formal Privacy Policy or DPA.
A current, sourced ISO/IEC 27001:2022 certification plus a public bug-bounty and vulnerability-disclosure programme evidence credible controls, though no SOC 2 or equivalent independent audit was found.
A public DPA anchored in GDPR Article 28 and the Swiss FADP exists, but it is a general hosting agreement rather than AI-Tools-specific and omits an enumerated sub-processor list or explicit breach-notification SLA.
Risk assessment
Third-party outage monitoring reports a high volume of incidents across Infomaniak's service portfolio (74+ tracked over six months, 200+ notifications sent), including a recent 'AI Tools Instability' incident, indicating non-trivial operational disruption frequency across the platform that customers should weigh against SLA commitments. source ↗
RESILIENCEMarketing and FAQ pages state prompts are 'neither recorded nor used to train models,' but this commitment is stated in product marketing/FAQ copy rather than in a dedicated AI-specific clause of the published DPA, leaving the precise contractual retention window for logs (e.g. abuse/billing metadata) unspecified. source ↗
SERVING_RETENTIONOwnership structure has recently changed: as of 2026 the majority of Infomaniak's shares was transferred into a public-interest foundation and the company signed an agreement to list on the SIX Swiss Exchange, a governance transition that customers with strict vendor-stability diligence should track. source ↗
GOVERNANCEAI image generation/interpretation is described by Infomaniak itself as 'currently being analysed' and not yet fully operational, meaning the data-handling and residency guarantees for that specific future feature are not yet contractually confirmed. source ↗
DATA_RESIDENCYSafeguards
Inference for AI Tools/Euria runs end-to-end on Infomaniak-owned and operated data centres physically located in Switzerland (Geneva D4 site, with GPUs including NVIDIA L4/A100/H100), with no dependency on foreign hyperscaler regions. source ↗
Infomaniak states that AI Tools queries are used exclusively to meet immediate user needs 'without any storage or logging of requests,' and that data only transits within its own independent cloud infrastructure. source ↗
Infomaniak explicitly states it does not currently offer the ability to train its AI Services on customer data, and separately pledges customer queries are 'neither recorded nor used to train models or improve our services.' source ↗
Infomaniak operates its own infrastructure end-to-end (no outsourcing/foreign intermediaries in data-centre design, operation or staffing), reducing sub-processor chain complexity for the AI serving path. source ↗
Infomaniak runs a public bug bounty / coordinated vulnerability disclosure programme via YesWeHack with a documented security.txt policy and dedicated security@infomaniak.com contact. source ↗
Data centres hosting AI workloads are ISO 27001 certified and use n+1 redundancy for power, cooling and UPS; Infomaniak also holds Swiss Made Software and Swiss Hosting labels confirming Swiss physical hosting. source ↗
Switzerland's EU adequacy status (Art. 45 GDPR) means EU↔Switzerland data transfers for this service do not require separate SCCs, simplifying the contractual cross-border transfer position versus non-adequate third countries. source ↗
Privacy-policy issues
AI-specific retention pledge lives mainly in marketing/FAQ copy, not a dedicated AI annex source ↗
The 'no storage, no training' commitment for AI Tools/Euria is repeated across product and news pages but is not clearly codified as an AI-specific clause distinct from the general DPA, which is product-agnostic.