Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
IONOS AI Model Hub is a German-jurisdiction, EU-hosted serving stack: inference and RAG vector storage run exclusively in IONOS's own Berlin data centers, with cloud_act_exposure marked false and no documented non-EU fallback path. The strongest dimension is serving residency, backed by an explicit no-fallback EU-only architecture and a stateless, non-training default for prompts and outputs described in both product documentation and the DPA. The weakest dimension is security posture: while IONOS holds current BSI C5 and IT-Grundschutz certifications, the C5 attestation is a Type 1 (design-only) rather than Type 2 attestation and its scope to the AI Model Hub product specifically is unconfirmed, and there is no paid bug-bounty program. Contractual posture is solid but incomplete — a DPA and enterprise terms exist with a clear EU counterparty, but no AI-Model-Hub-specific sub-processor list or explicit SCC/audit-rights language was found. Given the exclusively EU-based serving path, default non-retention, and a German legal entity with no US-parent exposure, Stav's operational verdict is that sovereign serving is available for most use cases, though highly regulated customers (e.g., healthcare under §393 SGB V) should independently confirm C5 Type 2 coverage before relying on this posture without a derogation.
Inference and managed vector DB run exclusively in IONOS's own Berlin, Germany data centers with no stated non-EU fallback.
Certifications & legal documents
IONOS is a German-incorporated operator with cloud_act_exposure marked False, though the absence of a published sub-processor list leaves minor residual uncertainty about downstream vendors.
AI Model Hub is documented as stateless by default, discarding prompts/outputs post-session and excluding customer data from training, per both product docs and the DPA.
IONOS holds current, sourced BSI C5 (Type 1) and IT-Grundschutz certifications, but the C5 attestation is design-only (not operating-effectiveness), its scope to AI Model Hub specifically is unconfirmed, and there is no paid bug-bounty program.
A DPA and enterprise terms are published with a clear German legal counterparty, but no dedicated sub-processor list or explicit SCC/audit-rights detail was located for the AI Model Hub product.
Risk assessment
IONOS's BSI C5 attestation is a Type 1 (design/point-in-time) attestation covering Compute Engine, Cloud Cubes and S3 Object Storage — not a Type 2 (operating-effectiveness) attestation, and not explicitly scoped to the AI Model Hub product itself. Germany's healthcare-sector rules (§393 SGB V) require Type 2 as of July 2025, so healthcare customers relying on C5 for AI Model Hub should independently confirm current scope/type. source ↗
SECURITYIONOS has a responsible-disclosure/vulnerability-reporting policy but explicitly states it has no official (paid) bug bounty program, relying instead on a non-monetary 'Hall of Fame' for researchers. source ↗
SECURITYIONOS Cloud's public status page has recorded GPU server provisioning incidents ('exceptionally high demand for GPU servers... temporarily limited our available capacity'), indicating GPU capacity constraints can affect AI workload availability. source ↗
RESILIENCENo dedicated, publicly indexed sub-processor list specific to the AI Model Hub (downstream logging, CDN, or support tooling vendors) was located during this research; data-handling documentation describes internal practices but not a named third-party sub-processor chain. source ↗
SUBPROCESSINGFor certain modified models (e.g., FP8-quantized variants such as Llama 3.1 405B-FP8), IONOS's own documentation states it takes on the AI Act 'Provider' role with additional transparency obligations, rather than the lighter 'Distributor' role that applies to most unmodified open-source models — customers must track which role applies per model. source ↗
GOVERNANCESafeguards
All AI Model Hub inference endpoints and managed vector databases are hosted exclusively in IONOS Cloud's data centers in Germany (Berlin), with no stated fallback to non-EU regions. source ↗
AI Model Hub is documented as a stateless service that discards user prompts and outputs at the end of each session, with no logging, recording, or reuse for model training. source ↗
Per the IONOS DPA, customer data including API-sent prompts, inputs, and RAG-uploaded documents is processed exclusively for service provision and is not used for training, fine-tuning, or otherwise improving any AI models. source ↗
Underlying IONOS Cloud infrastructure holds BSI C5 (Type 1) attestation and BSI IT-Grundschutz ISMS certification, making IONOS the first cloud provider to hold both certificate types. source ↗
IONOS publishes a dedicated EU AI Act compliance page describing its role (Distributor vs. Provider) per model type and its data-governance obligations to customers. source ↗
IONOS operates a documented, security.txt-registered responsible vulnerability disclosure process with a dedicated security contact and PGP key. source ↗
IONOS Cloud operates a public, component-level status page with incident history and subscription/webhook notifications for AI Model Hub-relevant services (e.g., GPU server provisioning). source ↗
Privacy-policy issues
C5 attestation type/scope ambiguity for AI Model Hub source ↗
The BSI C5 attestation IONOS holds is Type 1 and was announced for Compute Engine, Cloud Cubes and S3 Object Storage; its explicit extension to the AI Model Hub product was not confirmed in available sources, which matters for healthcare customers now requiring Type 2 under §393 SGB V.
Sub-processor chain not disclosed for AI Model Hub specifically source ↗
IONOS's data-handling documentation describes internal stateless processing but does not name or list downstream sub-processors (e.g., logging, monitoring, support tooling vendors) used in serving the AI Model Hub.