Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Scaleway Generative APIs is operated by a French, Iliad Group-owned entity serving exclusively from its Paris (fr-par) region, giving it a strong EU-residency posture with no non-EEA fallback path. The composite lands in the 'conditional' band because the operator's headline sovereignty claim — CLOUD Act immunity via ANSSI SecNumCloud qualification — is still undergoing assessment rather than granted, which caps legal_exposure below the top tier despite an otherwise clean EU-only footprint. Security posture is a strength, anchored by current, sourced ISO/IEC 27001:2022 and HDS certifications and documented encryption/IAM controls, though a recurring pattern of infrastructure incidents on Scaleway's own status page tempers confidence. Serving retention is solid, with a default Zero Data Retention policy and no training on prompts, subject only to a narrow, disclosed exception covering service errors and suspected misuse — for example, when a request triggers an unexpected HTTP 500 error or may represent malicious activity. Contractual posture is adequate — a public DPA and sub-processor list exist — but SCC and audit-rights documentation is thinner than ideal and the sub-processor list's contents could not be independently verified. Stav's verdict: sovereign serving is available today on a conditional basis, pending confirmation of the SecNumCloud grant to fully substantiate the extraterritorial-immunity claim.
Generative APIs serve exclusively from the Paris (fr-par) region with no non-EEA fallback, though this creates single-region concentration risk.
Certifications & legal documents
Scaleway is a French, Iliad-owned operator with no CLOUD Act exposure per operational data, but its ANSSI SecNumCloud qualification — the formal attestation of extraterritorial-law immunity central to its 'CLOUD Act-free' claim — is still in progress, not granted.
A default Zero Data Retention policy with no training on prompts is confirmed, tempered only by a narrow, disclosed exception allowing temporary logging of full request content during suspected abuse or error investigation.
Current, sourced ISO/IEC 27001:2022 and HDS certifications plus documented encryption-at-rest/in-transit and IAM controls are offset somewhat by a non-trivial cadence of infrastructure incidents on the status page.
A public DPA and sub-processor list exist with a clear French/Iliad Group counterparty, but SCC coverage and audit-rights terms are not explicitly documented, and the sub-processor list's actual vendors could not be verified.
Risk assessment
Scaleway markets itself as 'the most sovereign cloud provider in Europe' and 'free from the US CLOUD Act', but its flagship ANSSI SecNumCloud qualification — the qualification that formally attests immunity from extraterritorial law — is still undergoing assessment and has not yet been granted. source ↗
GOVERNANCEScaleway's own status page shows a recurring pattern of operational incidents affecting Generative APIs and related infrastructure (e.g. a Cockpit/Loki logging outage causing lost logs across FR-PAR, NL-AMS and PL-WAW, and a network-device-caused traffic loss on FR-PAR-2 instances) within recent weeks. source ↗
RESILIENCEGenerative APIs (serverless) is currently available only in a single region, the Paris (fr-par) datacentre, creating geographic/operational concentration risk for customers relying on it, even though this also keeps data unambiguously in France. source ↗
DATA_RESIDENCYDespite a default Zero Data Retention policy, Scaleway reserves the right to temporarily store and access full HTTP request content (including prompts) when traffic is judged to cause errors or represent possible misuse, creating a conditional exception to the no-logging posture. source ↗
SERVING_RETENTIONSafeguards
Scaleway states it does not collect, read, reuse or analyse prompt/output content by default, applies a Zero Data Retention policy, and confirms customer data is not accessible to other customers, to the underlying model creators, or used for model training/retraining. source ↗
Data is encrypted at rest when stored and encrypted in transit via HTTPS; access to servers hosting Generative APIs is authenticated/authorized via Scaleway IAM. source ↗
Scaleway describes its Generative APIs as 'All hosted in Europe' and states its infrastructure is 100% European, operated 24/7 with a dedicated CSIRT and native DDoS protection, positioning it as free from the US CLOUD Act. source ↗
Scaleway holds ISO/IEC 27001:2022 and HDS (health-data hosting) certifications and has formally entered ANSSI's SecNumCloud qualification process (J0 milestone passed). source ↗
Scaleway publishes a dedicated sub-processor list (last reviewed July 2025) with a change-history page, and operates a SafeBase-powered Trust Center including a completed CAIQ questionnaire and security advisories (e.g. CVE-2026-46333 note). source ↗
Scaleway was selected by Airbus as a sovereign cloud provider and by the European Commission as one of four providers in a €180M tender, and was recognized as SEAL-3 under the EU Cloud Sovereignty Framework, indicating institutional confidence in its operational maturity. source ↗
Privacy-policy issues
SecNumCloud qualification not yet granted source ↗
Scaleway's sovereignty and CLOUD Act-immunity messaging leans heavily on SecNumCloud, but the qualification is still 'currently undergoing assessment' and not yet awarded, which regulated buyers should not treat as already achieved.
Conditional logging exception to Zero Data Retention source ↗
In cases of abnormal errors or suspected malicious activity, Scaleway may temporarily store and access the full HTTP request content (including prompt data) to investigate, which is an exception to the stated zero-retention default.