Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Nebius Token Factory is operated by Nebius B.V., an EEA-incorporated entity under Dutch law and Dutch DPA supervision, with a genuinely EU-anchored contractual and certification stack. The composite lands in 'conditional' territory because the two sovereignty-weighted dimensions — serving residency and legal exposure — are the weakest links: shared/public model endpoints can process data in Israel or the US depending on model choice, and disclosed sub-processors include a US Nebius Group affiliate with out-of-EEA administrative access plus a third-party US inference vendor (Eigen AI, Inc.), undercutting the 'eu_hosted' label for default-tier traffic. Security posture is the strongest dimension, backed by current, sourced ISO 27001/27701 and SOC 2 Type II/SOC 3 certifications, and contractual posture is solid with an auto-incorporated DPA, SCCs, and annual audit rights, though the liability cap is thin. Retention is reasonably handled via an available, configurable Zero Data Retention mode, though the default is opt-out training for speculative decoding. Stav's verdict: sovereign serving is available only via a dedicated EU-region endpoint with Zero Data Retention actively enabled — the default/shared tier requires a derogation or explicit reconfiguration before it can be treated as EEA-sovereign.
Dedicated EU-region endpoints carry a contractual no-failover region commitment, but the default shared/public endpoints can process data in Israel or the US depending on the model selected, so EU-only serving is not guaranteed absent active configuration.
Certifications & legal documents
Although the controller/processor is Nebius B.V. (Netherlands), disclosed sub-processors include a US-incorporated Nebius Group affiliate with administrative/maintenance access from outside the EEA and an external US company (Eigen AI, Inc.) actually performing AI inference in the US, with transfers relying partly on the legally-contested EU-US DPF.
Retention/training on prompts is opt-out by default for speculative-decoding purposes, but an organization-wide Zero Data Retention mode is available and configurable with written confirmation, matching a documented opt-out posture.
Current, sourced ISO 27001, ISO 27701, SOC 2 Type II (with HIPAA mapping) and SOC 3 certifications plus documented encryption, access-control and audit-logging measures in the DPA demonstrate a strong, verifiable security program.
A GDPR-native DPA auto-incorporated into the ToS includes SCCs (Modules 2–4), UK/Swiss addenda, annual audit rights, and Dutch governing law/supervisory authority, though the standard liability cap (12-month fees or $500) is low for regulated enterprise use.
Risk assessment
Nebius Inc. (United States) is disclosed as an internal group sub-processor performing cloud infrastructure, service maintenance and support for Token Factory, and Nebius explicitly confirms this covers 'administrative, maintenance and support access to data from outside the EEA — for example, by Nebius group entities in the United States, Israel or Serbia.' This gives a US-incorporated affiliate operational access to customer data despite the EU controller/processor entity being Nebius B.V. source ↗
LEGAL_EXPOSUREExternal sub-processor Eigen AI, Inc. is a US-incorporated company providing 'AI inference services' hosted in the United States — a third-party inference vendor entirely outside Nebius's own EU-owned data centers, which is material to any customer relying on 'EU-hosted' sovereignty for inference workloads. source ↗
SUBPROCESSINGFor non-dedicated (shared/public) model endpoints, real-time inference processing location depends on the specific model and can occur in the EU, Israel, or the United States; the customer must check a per-model country flag to confirm EU-only processing rather than it being guaranteed by default. source ↗
DATA_RESIDENCYCross-border transfers to the US rely partly on the EU-US Data Privacy Framework (DPF), a mechanism with a history of legal challenge (predecessor frameworks Safe Harbor and Privacy Shield were both invalidated by the CJEU), and Nebius's US DPF-certified entities remain subject to FTC enforcement jurisdiction and to disclosure obligations to US public authorities for national security or law enforcement purposes. source ↗
LEGAL_EXPOSUREMultiple other external cloud-infrastructure sub-processors (RunPod Inc., BoostRun LLC, Shadeform Inc., Argentum AI Inc., Data Section Inc.) are US-incorporated entities hosting in the United States, Iceland, or Canada — none disclosed as EU/EEA-hosted — and were added to the list as recently as May and August 2026. source ↗
SUBPROCESSINGUnless a customer proactively enables Zero Data Retention, inputs and outputs are stored by default and used to train a smaller 'speculative decoding' draft model — an opt-out (not opt-in) data-reuse default for a production inference service. source ↗
SERVING_RETENTIONStandard Terms of Service cap total liability at the greater of fees paid in the preceding 12 months or US$500, a low ceiling for an enterprise regulated-sector deployment, and generally accepted risk transfer beyond this is left to negotiated Order Forms. source ↗
CONTRACTUALA published August 19, 2026 post-mortem describes a storm-related cooling/building-management failure causing a full regional outage (including Token Factory) in us-central1, with a detection gap because neither the facility operator nor Nebius received a facility-level alert. source ↗
RESILIENCESafeguards
Dedicated endpoints carry a contractual region commitment (DPA Section 6.1): no multi-region routing, load balancing, or automatic failover — inference for an EU-configured dedicated endpoint stays in that region. source ↗
Fine-tuning datasets, artifacts and model outputs are stored exclusively in EU data centers regardless of customer origin, and speculative-decoding retention data (when not opted out) is stored in Finland (EU) regardless of where real-time processing occurred. source ↗
Organization-wide Zero Data Retention mode is available: with ZDR enabled, no inputs/outputs are stored beyond ephemeral processing and none are used for speculative decoding or model training; written confirmation of ZDR status can be requested for compliance reviews. source ↗
A public, dated sub-processor list is maintained (internal Nebius Group entities and external vendors, with roles and locations), with at least 15 days' prior notice and a customer objection/termination right before any addition or replacement. source ↗
The DPA is automatically incorporated into the Terms of Service (no separate signature needed), includes EU Standard Contractual Clauses (Modules 2–4) plus UK Addendum and Swiss FADP adaptations, and grants customers a right to commission an independent audit with 30 days' notice, once per calendar year. source ↗
Governing law for the DPA/SCCs is the Netherlands with exclusive Dutch court jurisdiction, and the competent supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). source ↗
DPA Annex 3 documents concrete technical and organizational measures: encryption at rest and in transit, need-to-know/least-privilege access control, audit logging, physical data-center security, personnel confidentiality training, and annual vulnerability assessments. source ↗
Public real-time status board (status.nebius.com) with per-region incident views and publicly published incident post-mortems, including root-cause and corrective-action detail. source ↗
Dedicated endpoints are marketed with a 99.9% uptime SLA and guaranteed isolation/reserved compute capacity. source ↗
Contracting entity, data-flow roles (controller vs. processor), and sub-processor access are explained in a dedicated plain-language 'Legal Quick Guide' aimed at procurement/compliance teams. source ↗
Privacy-policy issues
Third-country AI-inference sub-processor source ↗
A US-incorporated sub-processor (Eigen AI, Inc.) is disclosed as providing 'AI inference services' hosted in the United States, outside Nebius's own EU-owned infrastructure.
Opt-out (not opt-in) training/reuse default source ↗
Absent an explicit Zero Data Retention election, customer inputs and outputs are stored and used to train a smaller draft model for speculative decoding.
Shared endpoint region not EU-guaranteed by default source ↗
Public/shared model endpoints may process data in Israel or the United States depending on the model selected; EU-only processing requires either checking per-model flags or contracting a dedicated EU endpoint.
Inconsistent 'no training' language source ↗
The Legal Quick Guide FAQ states content is never used to train any model, while the Terms of Service describe the same default retention as 'training smaller Models... for Speculative Decoding,' creating ambiguity for compliance reviewers.