Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Nscale is a UK-incorporated infrastructure operator (jurisdiction: other, GB) marketing a 'Sovereign AI Cloud for Europe' story, and it does operate real EEA/UK data-centre capacity in Norway, Portugal, Iceland and the UK — but that same fleet includes US sites in Texas, North Carolina and West Virginia, and its own privacy policy concedes data may leave the UK/EEA, so residency is selectable rather than fleet-wide guaranteed. Legal exposure is mixed: the operating entity is UK-based with no direct CLOUD Act finding, but heavy US-hyperscaler partnerships (Microsoft, Nvidia, OpenAI) and US-sited capacity mean some workloads plausibly land under US jurisdictional reach. The weakest dimension is serving retention — no explicit prompt/output retention window or no-training commitment at the inference boundary was found — closely followed by security posture, where 'ISO 27001-aligned' is self-declared rather than independently certified and no public uptime/incident history exists to verify operational maturity given the company's May-2024 incorporation. Contractual posture is moderate: sub-processors are named and SCC/UK-IDTA safeguards are cited, but no standalone DPA document is locatable. Given a young operating history, unresolved data-residency ambiguity, and unconfirmed retention practices, Stav's operational verdict is routed-only pending explicit EEA-region pinning and a locatable DPA/retention commitment — sovereign serving is not yet assured by default.
Nscale operates genuine EEA/UK-owned or partner sites (Norway, Portugal, Iceland, UK) but the same fleet includes US facilities (Texas, North Carolina, West Virginia) and its own privacy policy admits data may be processed outside the UK/EEA, so EEA-only serving is region-selectable, not guaranteed by default.
Certifications & legal documents
Nscale is UK-incorporated with no direct CLOUD Act exposure flagged, but its US-sited data centres and deep US-hyperscaler partnerships (Microsoft, Nvidia, OpenAI) mean workloads routed to those facilities or partners carry US jurisdictional exposure.
No page describing prompt/output retention windows or a no-training-on-customer-data commitment at the inference boundary could be located, leaving the serving-side data-handling posture unconfirmed.
Nscale claims only self-declared 'ISO 27001-aligned' controls over sub-processor governance with no independently issued certification located, and no public status/incident history exists to corroborate operational security.
Nscale publishes a named sub-processor list and cites SCCs/UK-IDTA safeguards for out-of-region transfers, but no standalone, customer-facing DPA document was locatable, only references to 'applicable' agreements.
Risk assessment
Nscale markets a 'Sovereign AI Cloud made for Europe' narrative, but its published data-centre map includes US facilities (Texas; partner site North Carolina; newly acquired Monarch Compute Campus, West Virginia) alongside EEA/UK sites (Glomfjord, Narvik, Loughton, Sines, Keflavik). Customers must confirm the specific inference endpoint/region to avoid an implicit US routing. source ↗
DATA_RESIDENCYNscale's own privacy policy states personal data may be transferred to and processed in countries outside the UK and EEA, confirming that cross-border transfer outside the sovereign EU/UK footprint is a live possibility for serving-side data. source ↗
DATA_RESIDENCYNscale operates data centres on US soil (Texas, North Carolina, and the acquired Monarch Compute Campus in West Virginia) and has entered a large-scale supply partnership with Microsoft (200,000 Nvidia chips) and joint 'UK Stargate' infrastructure plans with OpenAI and Nvidia; any customer workload routed to or supported via US-based capacity or these US-linked partners is exposed to US jurisdiction regardless of Nscale's UK incorporation. source ↗
LEGAL_EXPOSUREThe Financial Times has publicly questioned Nscale's 'British' identity, reporting it began as an offshoot of Arkon Energy, an Australian crypto-mining firm, with an Australian founder (Josh Payne), under the headline 'Is the "British firm" at the heart of Britain's AI plans actually British?' and separately published a piece titled 'Nscale's borrowed credibility.' source ↗
GOVERNANCENscale was only incorporated in May 2024 and has scaled extremely rapidly via successive mega-rounds ($155m Series A, $1.1bn Series B, $433m pre-Series C, $2bn Series C), giving it a very short independent operating track record for enterprise-grade serving reliability; an FT piece is titled 'Nscale's credit history (slightly chipped),' suggesting some financial scrutiny. source ↗
RESILIENCENo independently verifiable public status page with historical uptime/incident data was found; Nscale's own documentation describes maintenance-notification practices (minimum one week's notice, emergency maintenance windows) rather than a transparent uptime history. source ↗
RESILIENCENscale describes only 'ISO 27001-aligned controls' over sub-processor selection and monitoring on its own sub-processors page — this is a self-declared alignment statement, not confirmation of an independently issued ISO 27001 certificate for Nscale's own operations. source ↗
SECURITYSafeguards
Nscale publishes a dedicated, named sub-processor list (services provided and processing locations) and commits to reasonable advance notice before adding or replacing a sub-processor. source ↗
For sub-processors located outside the UK/EEA, Nscale states it relies on Chapter V GDPR safeguards — EU Standard Contractual Clauses (2021/914) and/or the UK International Data Transfer Agreement/Addendum. source ↗
Nscale operates its own data centres in Norway (Glomfjord, Narvik) and the UK (Loughton), plus partner-run EEA sites in Portugal (Sines) and Iceland (Keflavik/Blönduós), giving genuine EEA/UK-based compute options for customers who select those regions. source ↗
Nscale states it maintains ISO 27001-aligned controls over sub-processor due diligence and ongoing monitoring. source ↗
Nscale has attracted large strategic investors and partners (Aker, Nvidia, Nokia, Dell, Microsoft) across successive funding rounds, indicating substantial capital backing for infrastructure buildout and continuity. source ↗
Privacy-policy issues
Cross-border transfer beyond UK/EEA acknowledged source ↗
The privacy policy states personal data may be transferred to and processed in countries outside the UK and EEA, which sits in tension with the 'sovereign AI cloud for Europe' positioning unless a customer explicitly pins their workload to an EEA/UK region.
No standalone, independently locatable DPA source ↗
The sub-processors page refers to obligations under 'applicable Data Processing Agreements' but no separately published, customer-facing DPA document (distinct from the Terms and Privacy Policy) could be located during this research.
No explicit serving-boundary retention/no-training statement found source ↗
No page was found stating a specific prompt/output retention window for inference endpoints or an explicit no-training-on-customer-prompts commitment, leaving the serving-boundary data-handling posture unconfirmed.