Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Phala Cloud is operated by a US-incorporated entity (Hashforest Technology LLC, California, with a Singapore parent) serving inference from a decentralized, globally distributed TEE node network rather than fixed EEA data centers — placing both legal exposure and serving residency firmly outside a sovereign-EU posture regardless of the strength of the underlying confidential-computing technology. The strongest dimension is security posture: hardware-backed TEE attestation, an open-sourced runtime, and current SOC 2 Type I / HIPAA claims are genuine mitigants, though undercut by an unreconciled ISO 27001 status claim and no published SLA or breach history. The weakest dimensions are legal exposure and contractual posture — full CLOUD Act reach, a published DPA (effective 14 June 2025, incorporating SCCs by reference) but no executed enterprise-specific agreement, a liability cap of the greater of $500 or twelve months' fees paid, forced California arbitration, and a debug-mode exception that permits plaintext operator access to the same inference workloads otherwise marketed as 'no-log.' These combine to an overall high-risk read despite Phala's technically differentiated confidentiality architecture. Stav's verdict: no sovereign EEA serving path exists here — this provider is routed-only and would require an enterprise-negotiated derogation (verified production-mode deployment pinning, a countersigned DPA with SCCs, and reciprocal breach terms) before any regulated EU workload could be considered.
Compute runs on a decentralized, globally distributed TEE node network with no fixed EEA-only region, and Phala's own guidance places the burden of regional-compliance configuration on the customer rather than guaranteeing EEA residency.
Certifications & legal documents
The contracting entity, Hashforest Technology LLC, is California-headquartered under a Singapore parent, placing the operator squarely under US CLOUD Act jurisdiction, compounded by a compute layer contributed by 35,000+ third-party machine operators of unclear jurisdiction.
Production-mode TEE inference has a genuine no-log design claim, but a documented debug-mode exception permits operators plaintext access (including remote shell) to the same LLM workloads, and even production traffic may have encrypted inputs/outputs/metadata retained for platform improvement.
Current SOC 2 Type I and HIPAA claims plus hardware TEE attestation and an open-sourced (Linux Foundation-donated) confidentiality stack are real strengths, offset by an unresolved discrepancy over ISO 27001 status (claimed vs. 'in progress') and no published SLA or breach-history disclosure.
No DPA URL is published, liability is capped at three months' fees, disputes are forced into California/JAMS arbitration, there is no reciprocal breach-notification commitment, and subprocessor sharing language names no specific third parties.
Risk assessment
The contracting entity is Hashforest Technology LLC, described in the Terms as operating the Services, headquartered in California, US, with a Singapore parent (Hashforest Technology Pte. Ltd.) — placing the operator squarely under US CLOUD Act and general US lawful-access jurisdiction irrespective of where compute nodes sit. source ↗
LEGAL_EXPOSUREThe privacy policy carves out an explicit exception to its no-access/no-log posture: when a customer deploys in non-production ('dev') mode, 'platform operators may modify the behavior of the software in the TEE and may access data in transmission, use, and storage in plain text,' including via remote shell access, and the policy states this same exception applies to confidential inference/LLM usage. source ↗
SERVING_RETENTIONTotal liability is capped at the amount paid by the customer in the preceding three months, and disputes are resolved via binding arbitration under JAMS/California law with a jury-trial waiver — narrow terms for regulated-sector procurement expecting broader indemnity and audit rights. source ↗
CONTRACTUALPhala's compute layer is a decentralized network of TEE hardware (Intel TDX, NVIDIA H100/H200) with no fixed EEA-only region; Phala's own deployment guidance tells customers they must themselves 'ensure TEE instances comply with regional regulations,' indicating residency is a customer configuration choice rather than a platform guarantee. source ↗
DATA_RESIDENCYThe privacy policy permits broad sharing of personal information with unnamed 'affiliates and other trusted third-party service providers' for processing on Phala's behalf, and separately confirms use of third-party analytics/marketing trackers (Google Analytics 4, PostHog, Customer.io) that collect account and behavioral data outside the TEE boundary. source ↗
SUBPROCESSINGPhala Network's broader compute capacity is contributed by a large, distributed base of third-party machine/GPU operators (Phala cites over 35,000 machines in its network), meaning the identity and jurisdiction of the physical hardware operator behind any given workload is not necessarily Phala itself. source ↗
SUBPROCESSINGPhala's own marketing and comparison pages describe ISO 27001 as 'in progress' rather than completed ('SOC 2 Type I certified and HIPAA compliant, with ISO 27001 certification in progress'), which should be reconciled against any catalogue claim of a completed ISO 27001 certification. source ↗
SECURITYThe policy imposes a strict 24-hour breach-notification obligation on the customer toward Phala but states no reciprocal notification-window commitment from Phala to customers in the event of a security incident. source ↗
CONTRACTUALEven for encrypted TEE traffic, the policy states the platform 'may retain encrypted inputs and outputs and metadata for the purpose of improving its operation and security' — a retention practice beyond pure statelessness, albeit encrypted. source ↗
SERVING_RETENTIONPhala's public status page has recorded live regional networking incidents (e.g., an outage affecting nodes in US-West), and no historical uptime SLA percentage is published alongside it. source ↗
RESILIENCESafeguards
Confidential inference runs inside hardware-backed Trusted Execution Environments (Intel TDX for CPU, NVIDIA H100/H200 Confidential Computing for GPU) with combined CPU+GPU attestation, intended to keep data encrypted even while in use. source ↗
Every application deployed on Phala Cloud automatically receives a public Trust Center verification report providing cryptographic proof of hardware authenticity, code integrity, and OS security, independent of Phala's own attestation. source ↗
For models deployed in TEE production mode, Phala states it does not collect or store users' prompts, inputs, or requests, as these are processed end-to-end encrypted entirely within the secure enclave. source ↗
Phala states it is SOC 2 Type I certified and HIPAA compliant, with privacy-by-design controls aligned to GDPR (ISO 27001 listed as in progress on the same page). source ↗
Core confidential-computing stack (dstack SDK) is open source and has been donated to the Linux Foundation for neutral governance, supporting independent code-level audit of the TEE runtime. source ↗
Privacy-policy issues
Debug-mode plaintext access exception source ↗
When a customer deploys an application in non-production/dev mode, Phala operators may access data in transmission, use, and storage in plain text (including remote shell), and this same exception is stated to apply to LLM/confidential inference workloads.
No provider-side breach notification commitment source ↗
The policy requires customers to notify Phala of a suspected breach within 24 hours but states no equivalent notification timeframe owed by Phala to customers.
Broad/unnamed third-party sharing clause source ↗
Personal information may be shared with unnamed 'affiliates and other trusted third-party service providers' for processing on Phala's behalf, without a fully enumerated subprocessor list in the policy text itself.
Liability cap and forced arbitration source ↗
Total liability is capped at three months of fees paid and disputes must go to California-based JAMS arbitration with a jury-trial waiver, which is restrictive for enterprise risk transfer.
Third-party analytics/marketing trackers source ↗
Phala Cloud uses Google Analytics 4, PostHog, and Customer.io to track user behavior via cookies, with IP addresses and browser user-agents retained for six months for anti-spam purposes.