Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Tinfoil is a US-incorporated operator (Tinfoil, Inc., San Francisco) serving inference exclusively from US-hosted infrastructure (AWS, Cloudflare, Vercel) with no EU/EEA region option, so the serving-residency signal is weak by Stav's standard. Legal exposure is nominally high given US jurisdiction and US-hyperscaler subprocessors, but Tinfoil's core differentiator — hardware-isolated secure enclaves with client-verifiable attestation designed so neither Tinfoil nor its cloud providers nor government requesters can access plaintext prompts/outputs — is a genuine mitigant that Stav credits, without treating it as equivalent to EEA jurisdiction. The strongest dimensions are serving retention (no post-response retention, no training on API content) and security posture (current SOC 2 Type II plus enclave attestation), while the weakest is serving residency, compounded by a contractual posture that leaves enterprise-grade liability, DPA/SCC execution, and regulated-data handling to a separately negotiated agreement rather than standard terms. On balance this composite lands in elevated-risk territory: the confidential-computing architecture is a meaningful technical safeguard, but the absence of EEA infrastructure and the US legal seat mean Stav should treat Tinfoil as routed-only pending a signed DPA/SCC and, for regulated workloads, an explicit derogation rather than default sovereign serving.
All disclosed hosting/CDN subprocessors (AWS, Cloudflare, Vercel) are US-based with no documented EU/EEA inference region, so serving runs outside the EEA by default.
Certifications & legal documents
Tinfoil, Inc. is a US-incorporated operator using US hyperscaler subprocessors and is explicitly CLOUD Act-exposed, though hardware-enclave confidential computing is designed to keep plaintext content unreadable even under compelled legal process, materially mitigating (but not eliminating) that exposure.
Tinfoil states it does not retain Inference API prompt/response content after the response is returned and does not use API content for training, enforced in part by enclave architecture rather than policy alone.
A current, sourced SOC 2 Type II certification plus hardware-isolated enclaves (AMD SEV-SNP/Intel TDX, confidential-computing GPUs) with client-verifiable attestation form a strong technical baseline, tempered by the provider's own disclosure that side-channel and firmware risks are not fully eliminated.
DPAs with SCCs and BAAs are available on request for business/enterprise customers, but standard Terms cap liability at the greater of $100 or 12 months' fees, mandate arbitration, and push regulated-data handling and enterprise-grade audit terms into a separately negotiated agreement.
Risk assessment
Standard Terms cap Tinfoil's total liability at the greater of $100 or 12 months' fees paid, exclude consequential damages, and mandate individual arbitration with a class-action waiver for most disputes — enterprise-grade liability/audit terms require a separate signed agreement. source ↗
CONTRACTUALTinfoil is headquartered in the US and its disclosed hosting/CDN subprocessors (AWS, Cloudflare, Vercel) are US hyperscalers; no EU/EEA-specific inference region is documented, meaning enclave workloads by default run on US-controlled infrastructure even though content is encrypted from the host. source ↗
DATA_RESIDENCYTinfoil, Inc. is a US company subject to US law; personal data 'may be processed in the United States and other locations where our providers operate,' exposing the operator (though not necessarily plaintext AI content) to CLOUD Act / US legal process. source ↗
LEGAL_EXPOSURETinfoil is not a HIPAA business associate and will not process PHI, payment-card data, or other regulated data unless a separate written agreement (BAA/DPA) is signed — regulated-sector customers must proactively negotiate this rather than relying on standard terms. source ↗
CONTRACTUALStandard terms target 99.9% uptime but only guarantee a 95% floor, with reimbursement of usage costs as the sole remedy; enterprise SLAs/service credits apply only under a separately signed order form. source ↗
RESILIENCETinfoil's own privacy policy discloses that confidential computing 'reduces access risk, but does not eliminate all security risk,' citing hardware vulnerabilities, firmware issues, side channels, and misconfiguration as residual risks not eliminated by enclave architecture. source ↗
SECURITYSafeguards
Inference API, Chat, and Containers all run inside hardware-isolated secure enclaves (AMD SEV-SNP/Intel TDX + NVIDIA confidential-computing GPUs) designed so prompt/response content is inaccessible to Tinfoil and its cloud providers during normal operation, with client-verifiable cryptographic attestation of the exact code, weights, and GPU running each request. source ↗
Tinfoil states it does not retain Inference API prompt/response content after the response is returned and does not use API content to train models. source ↗
Tinfoil publishes a detailed, dated subprocessor list (AWS, Cloudflare, Vercel, Clerk, Stripe, RevenueCat, GitHub, Resend, Plausible, Sentry, Tigerdata, Exa, Probo, etc.) covering hosting, auth, billing, analytics and audit-evidence vendors. source ↗
Business/enterprise customers can obtain a Data Processing Addendum including Standard Contractual Clauses for third-country transfers, and Business Associate Agreements or region-specific DPAs on request. source ↗
Tinfoil has completed a SOC 2 Type II examination covering security, availability, and confidentiality, evidenced via its Trust Center. source ↗
Tinfoil reports it has received zero government requests for personal data as of the policy's effective date, and states it will notify affected users before complying with legal process where lawful, committing to GDPR-aligned 72-hour breach notification. source ↗
Tinfoil maintains a public status page (status.tinfoil.sh) with real-time operational status, historical uptime data, and incident subscription notifications. source ↗
Privacy-policy issues
Very low standard liability cap source ↗
Default Terms cap total liability at the greater of $100 or 12 months' fees, which is unlikely to satisfy regulated-sector procurement/audit-liability requirements absent a negotiated enterprise agreement.
No dedicated EU/EEA data residency option source ↗
Privacy policy states data 'may be processed in the United States and other locations where our providers operate,' with no documented EU-only region for regulated European customers.
Regulated-data processing requires separate agreement source ↗
PHI, payment-card data, and other regulated data may not be processed under standard Terms unless Tinfoil signs an express written agreement (e.g., BAA) covering the applicable Service.