Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Telenor AI Factory is a Norwegian, EEA-jurisdiction operator running inference on security-cleared domestic infrastructure under Norway's Security Act, with no declared CLOUD Act exposure — a genuinely strong sovereignty starting point reflected in its residency score. The composite lands at elevated risk, however, because that strong physical/legal posture is not backed by service-specific documentation: there is no dedicated DPA, sub-processor register, or independent security certification scoped to the AI Factory unit itself, only general corporate privacy language and certifications held by unrelated sibling Telenor entities. The privacy notice's unreconciled caveat about third-country data transfers further muddies an otherwise clean residency claim, and the parent group's unrelated but live lawful-access controversy adds reputational uncertainty around the group's data-disclosure history. Strongest dimension is serving_residency (physical Norway hosting, legally mandated clearance); weakest is contractual_posture, given the total absence of a published DPA or audit-rights framework for this specific service. Given the gap between sovereignty marketing and thin procurement documentation, Stav's operational verdict is routed-only pending publication of a dedicated DPA, sub-processor list, and AI-Factory-scoped security certification.
Inference runs physically in security-cleared Norwegian data centres under the Security Act, but the provider's own privacy notice concedes personal data 'will in some situations transfer to third countries outside the EU/EEA' without clarifying whether that caveat can touch AI-workload data.
Certifications & legal documents
The AI Factory entity is Norwegian/EEA with no CLOUD Act exposure declared, but the tech stack depends on US vendors (Red Hat, NVIDIA) with no published sub-processor register, and the parent Telenor Group carries an unresolved lawful-access controversy that colors confidence in group-level data-handling practices.
The provider states customer data is 'never used for other purposes than your own,' implying a no-training default, but this commitment is informal marketing language rather than a documented retention schedule, and the general privacy notice does not explicitly cover prompt/output data.
Operational controls (personnel security clearance, VPN-gated access) are credible but no ISO 27001/SOC 2 or other certification scoped specifically to the AI Factory service was found; certifications located belong to sibling Telenor entities, not this unit.
No dedicated DPA, SCC annex, or audit-rights document for the AI Factory inference service is published — only a general corporate privacy notice referencing SCC use for transfers, leaving enterprise contractual terms undocumented.
Risk assessment
No itemized, dedicated sub-processor list for the AI Factory serving stack is published; only high-level technology-partner disclosures (Red Hat OpenShift AI, NVIDIA) and a possible data-centre partnership (Skygard) are visible via press coverage rather than a formal sub-processor register. source ↗
SUBPROCESSINGNo ISO 27001, SOC 2, or other independent security certification specifically scoped to Telenor AI Factory was found; certifications located are held by sibling Telenor Group entities (e.g. Telenor Connexion, Telenor Linx, Telenor Sweden) rather than the AI Factory unit itself. source ↗
SECURITYTelenor Group (the parent company) faces an active 2026 class-action lawsuit in Norway alleging its Myanmar subsidiary disclosed customer personal data to the military junta, which was allegedly used to persecute activists — a governance data point about how the parent group has handled authority data requests historically, even though unconnected to the Norwegian AI Factory's EEA operations. source ↗
GOVERNANCENo dedicated Data Processing Agreement, SCC annex, or audit-rights document for the AI Factory inference service was found published on the provider's site; only a general corporate/website privacy notice is available. source ↗
CONTRACTUALThe published privacy notice states personal data 'will in some situations transfer to third countries outside the EU/EAA', which sits in tension with the platform's core marketing claim that data is processed and stored only in Norway — the notice does not clarify whether this caveat can ever apply to AI-workload data versus only website/CRM data. source ↗
DATA_RESIDENCYNo published SLA, uptime track record, or incident-history disclosure specific to the AI Factory service was located; the facility is operationally young, having opened in November 2024 and only recently begun external-customer scaling and capacity expansion. source ↗
RESILIENCESafeguards
Inference infrastructure runs physically in Norway, in a data centre requiring security clearance for access, because the underlying systems are subject to Norway's Security Act. source ↗
The provider states customer data is 'stored and processed in Norway and it is never used for other purposes than your own,' indicating a no-repurposing / no-training-on-customer-data commitment, though not elaborated into a formal retention schedule. source ↗
Customer environments connect via a secure VPN, and the underlying GPU infrastructure sits behind personnel security clearance requirements mandated by Norway's Security Act. source ↗
The general privacy notice commits to using EU Standard Contractual Clauses (or relying on adequacy decisions / EU-US Data Privacy Framework certification) for any data transferred outside the EU/EEA, including Transfer Impact Assessments where needed. source ↗
The provider publicly names its core technology partners (Red Hat OpenShift AI, NVIDIA) and discloses named external customers (Hive Autonomy, Capgemini, Bineric), giving some visibility into its supply chain and multi-tenant customer base. source ↗
Privacy-policy issues
Privacy notice scope excludes AI workload data source ↗
The published privacy notice explicitly covers website visitor data, customer-relationship data (contact, billing, security logs) and contact-form messages, but does not clearly address retention or handling of prompts/outputs processed through the AI inference platform itself.
No published sub-processor register source ↗
No dedicated, itemized list of downstream cloud/logging/network sub-processors for the AI Factory service is published on the provider's own site.
Third-country transfer caveat undermines sovereignty claim source ↗
The privacy notice states personal data 'will in some situations transfer to third countries outside the EU/EAA,' which is not reconciled with the marketing claim that customer data stays in Norway.