Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
NEAR AI Cloud is operated by Jasnah, Inc. d/b/a NEAR AI, a Delaware corporation, with no EEA serving option or region-specific residency commitment disclosed, placing the operator fully within US CLOUD Act and FISA reach irrespective of where its Phala Network TEE nodes physically run. The strongest dimension is security posture: hardware-enforced Intel TDX + NVIDIA confidential-GPU TEEs with per-request, customer-verifiable attestation are a genuinely differentiated technical control, though undermined by the absence of any independent SOC 2/ISO certification and the service's beta status. The weakest dimensions are legal exposure and serving residency — both structurally low given the US incorporation and undocumented, decentralized TEE node jurisdiction — compounded by a critical gap in serving retention, since 'premium' closed-source models bypass the TEE entirely and are proxied to undisclosed third parties without attestation. Contractual posture is similarly thin: while a DPA is publicly accessible (last updated Aug 17, 2026) and includes a Schedule B subprocessor list, no standalone sub-processor list is separately published, leaving GDPR Article 28 obligations and named-subprocessor detail harder to pre-vet without reviewing the full DPA. Given the compounding of US jurisdictional exposure, an unverified decentralized sub-processing chain, and a documented non-TEE data path for premium models, Stav's verdict is high risk: this provider is routed-only at best, and any regulated or EEA-sensitive workload would require a specific derogation and exclusive use of the TEE-protected open-weight model path with independent contractual assurances obtained directly from NEAR AI before use.
Certifications & legal documents
No EEA serving path is documented; inference runs on Phala Network's decentralized TEE nodes with no published jurisdictional breakdown, and the operator itself is US-incorporated.
The contracting entity, Jasnah, Inc. d/b/a NEAR AI, is a Delaware corporation fully subject to US CLOUD Act/FISA reach regardless of where TEE compute physically sits.
Open-weight model traffic benefits from strong TEE-based no-training/no-access guarantees with attestation, but 'premium' closed-source models are proxied to unnamed third parties without any TEE protection or attestation, undermining the platform's default privacy posture.
Hardware-enforced Intel TDX + NVIDIA confidential-GPU TEEs with an independently verifiable open attestation verifier are a genuine technical strength, but no SOC 2, ISO 27001, or other independent security certification could be located, and the service is still labeled beta.
No DPA URL or published sub-processor list exists separate from the general Terms/Privacy Policy, leaving GDPR Article 28 obligations and SCC specifics unverifiable pre-sale despite a clear legal counterparty (Jasnah, Inc.).
Risk assessment
NEAR AI Cloud's own Terms define the 'NEAR AI Cloud API' as supporting 'premium closed-source models (proxied to third-party providers via a shared NEAR AI API key, without TEE-based privacy or attestation)' — meaning the flagship confidentiality/attestation guarantee does not apply to a subset of models routed to undisclosed third parties. source ↗
SERVING_RETENTIONThe contracting entity is Jasnah, Inc., d/b/a NEAR AI, a Delaware corporation, meaning the operator is squarely subject to US CLOUD Act and other US lawful-access regimes irrespective of where TEE compute nodes are physically hosted. source ↗
LEGAL_EXPOSURENEAR AI's TEE infrastructure was built in collaboration with, and continues to run on, Phala Network's decentralized confidential-compute cloud, a Web3 DePIN network of independently operated TEE nodes; no NEAR AI-published subprocessor list or jurisdictional breakdown of these nodes was found. source ↗
SUBPROCESSINGNEAR AI Cloud is explicitly labeled as being 'currently in beta' with capabilities shipping weekly, indicating an immature, rapidly-changing production service rather than a hardened enterprise offering. source ↗
RESILIENCENo SOC 2, ISO 27001, or other independent security-audit certification for NEAR AI Cloud could be located on the company's own domain or via public registries during this research. source ↗
SECURITYNo region-specific data residency commitments (e.g., an EEA-only deployment option) are published; the Privacy Policy only states that 'infrastructure providers may process limited network metadata (e.g., IP addresses)' without naming regions or entities. source ↗
DATA_RESIDENCYNo standalone, publicly linked DPA or sub-processor list was found separate from the general Privacy Policy and Terms of Service, making it harder for prospective enterprise customers to pre-vet GDPR Article 28 obligations before a sales conversation. source ↗
CONTRACTUALSafeguards
Open-weight model inference (e.g., GLM, Qwen, GPT-OSS) executes inside hardware-enforced Intel TDX + NVIDIA confidential-GPU TEEs, with memory sealed from the host OS and cloud infrastructure providers, and per-request cryptographic attestation that customers can independently verify. source ↗
NEAR AI publishes an open verifier so customers can independently check the TEE attestation quote binding the exact model/code that processed their request, rather than relying purely on vendor assertions. source ↗
For TEE-hosted models, NEAR AI's documentation states that model providers, cloud infrastructure providers, and NEAR itself 'cannot see, access, mine, or use your data to train models.' source ↗
Published, dated Privacy Policy (last updated Aug 10, 2026) and Terms of Service (last updated Jul 27, 2026) define legal bases for processing, data retention section, and international transfer provisions applicable to EEA/UK users. source ↗
Payment card data is handled entirely by a named third-party processor (Stripe) and is not received or stored by NEAR AI directly, limiting PCI-scope exposure at the serving boundary. source ↗
Privacy-policy issues
Non-TEE model path lacks privacy guarantees source ↗
Closed-source 'premium' models on the NEAR AI Cloud API are proxied to unnamed third-party providers via a shared API key without TEE-based privacy or attestation, contradicting the platform's 'private by default' positioning for that traffic.
No published subprocessor list source ↗
Neither the Privacy Policy nor Terms of Service link to a maintained, named sub-processor list (cloud, CDN, logging, or model-proxy vendors), despite referencing 'infrastructure providers' and 'third-party providers' generically.
No stated breach-notification window source ↗
The Privacy Policy and Terms of Service excerpts reviewed do not specify a concrete breach-notification timeframe (e.g., 72-hour GDPR-aligned commitment) to customers.
Advertising/analytics trackers on marketing site source ↗
www.near.ai deploys PostHog analytics plus LinkedIn Insight Tag and Twitter/X Ads Pixel for advertising measurement, which is unrelated to inference traffic but should be disclosed to enterprise security reviewers auditing the domain.