Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Nextbit (NEXTBIT 256, S.L.) is a Spain-incorporated, EEA-jurisdiction operator running its own EU data center in Valencia, but its serving footprint is mixed: non-EU-resident endpoints may run on third-party cloud infrastructure outside the EEA, and Nextbit's own documentation warns these can fall under US CLOUD Act and FISA 702 reach, relying on SCCs and the EU-US DPF rather than EU-only processing. Retention at the serving boundary is not zero by default — up to 90 days of operational logs are kept under legitimate-interest processing — though a strong no-training commitment spans all tiers and true zero-retention is contractable only on dedicated endpoints. The strongest dimension is serving retention's no-training guarantee and the explicit EU-resident endpoint option; the weakest are security posture, given the absence of any located third-party certification, and contractual posture, given an opaque, non-committal subprocessor-disclosure regime and one-sided customer indemnification for regulatory fines. Governance signals (early-stage, accelerator-backed, no public uptime history) further temper confidence in operational maturity. Given this mixed picture, Stav treats Nextbit as elevated risk: sovereign serving is achievable only if a customer explicitly contracts a dedicated, EU-resident, zero-retention endpoint — routed-only status applies to the default shared-tier offering.
Nextbit operates its own EU data center in Spain and offers explicitly EU-resident endpoints, but also provisions compute via third-party cloud infrastructure with nodes outside the EEA for non-designated endpoints.
Certifications & legal documents
Nextbit itself discloses that non-EU-resident endpoints run on US-linked infrastructure providers subject to the CLOUD Act and FISA 702, mitigated only by SCCs and DPF self-certification rather than EU-only processing.
Standard tier retains prompts/outputs up to 90 days under legitimate-interest processing rather than zero-retention by default, though a strong contractual no-training commitment applies across tiers and true zero-retention is available only via dedicated endpoints.
No ISO 27001, SOC 2, or other third-party security certifications could be located, and while a 48-hour breach notification commitment exists in the DPA, controls remain largely unverified given the company's early-stage scale.
A published DPA and SCC-based transfer mechanism exist, but the subprocessor regime is opaque with no published list or committed disclosure timeframe, and the Terms impose broad one-sided indemnification on customers for regulatory fines.
Risk assessment
Nextbit itself discloses that infrastructure providers operating in the United States (used for non-EU-resident endpoints) may be subject to the US CLOUD Act (2018) and FISA Section 702, permitting US authorities to compel data access, and relies on SCCs plus the EU-US Data Privacy Framework for such transfers. source ↗
LEGAL_EXPOSUREThe DPA grants Nextbit blanket, unrestricted authorization to engage subprocessors of any identity, number, or location; Nextbit is under no obligation to publish or maintain a public subprocessor list and will respond to information requests 'at its sole discretion and without any committed timeframe.' source ↗
SUBPROCESSINGThe Terms of Service impose broad indemnification on the customer for any regulatory investigation, fine, or sanction from a data protection or AI supervisory authority (e.g. AEPD, AESIA) arising from the customer's own processing, shifting significant regulatory risk onto the enterprise customer rather than the processor. source ↗
CONTRACTUALNextbit's own data center is in Spain, but compute capacity is also provisioned through third-party cloud infrastructure providers with nodes both inside and outside the EEA; endpoints not explicitly marked EU-resident should be assumed to potentially run outside the EU. source ↗
DATA_RESIDENCYStandard offering is explicitly not zero-retention: API request data (prompts/outputs) may be retained for an operational period of up to 90 days on the basis of Nextbit's legitimate interest (Art. 6(1)(f) GDPR), with only dedicated-endpoint customers able to negotiate true zero-retention. source ↗
SERVING_RETENTIONCustomers objecting to a subprocessor change must notify Nextbit within 30 days and then must cease using the Services; Nextbit is not obligated to remove the objected-to subprocessor or continue service to an objecting customer. source ↗
SUBPROCESSINGNo public status page, historical uptime data, or incident-history disclosure could be located for Nextbit/Nextbit256, limiting independent verification of serving reliability. source ↗
RESILIENCENextbit reserves broad unilateral rights to change service scope, pricing, or discontinue any Service at any time without notice, and disclaims any guarantee that errors or issues will be resolved. source ↗
CONTRACTUALNextbit is an early-stage startup incubated in the Lanzadera accelerator (Juan Roig's Marina de Empresas ecosystem in Valencia) with a small founding team, indicating limited organizational scale/maturity relative to hyperscale providers. source ↗
GOVERNANCESafeguards
Nextbit operates its own physical data center located in Spain (EU) and offers EU-resident endpoints that customers can explicitly select for data residency requirements. source ↗
Contractually binding commitment that customer data (prompts, inputs, outputs, or derivatives) is never used to train, fine-tune, retrain, or otherwise adapt any AI model, across all service tiers. source ↗
Dedicated inference endpoint customers can contractually specify their own retention policy, including a true zero-retention commitment. source ↗
A published Data Processing Agreement (DPA) is available covering GDPR/LOPDGDD roles, breach notification (48 hours to controller), and international transfer safeguards via SCCs. source ↗
Nextbit publishes a dedicated 'Zero Data Retention' attestation document explicitly distinguishing model-training use (never) from operational log retention (up to 90 days), giving customers clear language for procurement review. source ↗
Post-termination, all customer personal data is deleted within 60 calendar days, including any data still within the 90-day operational window. source ↗
Nextbit is a verified AWS Partner Network member listed on AWS Marketplace and a partner of OpenRouter, giving some third-party ecosystem visibility into its operations. source ↗
Privacy-policy issues
Opaque subprocessor disclosure source ↗
Nextbit is not obligated to publish a subprocessor list and responds to subprocessor information requests at its sole discretion with no committed timeframe, undermining a customer's ability to verify the downstream processing chain.
Third-country transfer risk on non-EU endpoints source ↗
Endpoints not explicitly designated EU-resident may run on US or other non-EEA infrastructure subject to CLOUD Act/FISA 702, mitigated only by SCCs/DPF self-certification rather than EU-only processing.
No zero-retention by default source ↗
Standard API service retains request/response data for up to 90 days for operational purposes rather than offering zero retention by default; only dedicated endpoints get true zero retention.
No independent instruction acceptance channel source ↗
Controller instructions submitted via email, support ticket, or platform message do not bind Nextbit unless captured in a separately signed agreement, which can create friction in fast-moving compliance requests.