kontinent / trust center
Security & Compliance
Kontinent is built as an EU-sovereign AI gateway: your data stays in the EU, content is never stored, and every connected provider goes through a legal review before any traffic flows to it. This page summarizes our security and privacy commitments transparently.
17
Providers reviewed
14
Publicly rated
16
Review criteria per provider
0
Stored prompts, by design
What happens to a request
Client
Kontinent Gateway
Frankfurt · eu-central-1
EU provider
Never stored
- Prompt content
- Response content
Stored (metadata)
- Token counts
- Latency
- Status code
- Model/provider
Zero retention, tested
Our end-to-end suite sends marked test prompts (a sentinel value) through the full stack and then greps every gateway and worker log for it. If the sentinel shows up anywhere, the test fails. The zero-retention promise is verified on every run, not just asserted.
Compliance
Controls
Data minimization
No prompt logging
Prompt and response content is never stored or logged anywhere: not in usage records, not in the audit log, not in server logs.
Usage data is metadata only
usage_records holds only token counts, latency, status, and model/provider, never content.
Prunable raw records
Usage records are prunable; aggregates and the ledger carry the durable truth, not the individual rows.
Traceability
Append-only audit log
Every control-plane change (sign-ins, org creation, key create/revoke, top-ups, suspensions) lands in the append-only audit_log.
Append-only credit ledger
All balance movements flow through ledger_entries with a unique idempotency_key, so double-booking is structurally impossible.
Per-org audit view
Every organization sees its own audit trail at /audit in the dashboard.
Tenancy separation & access
Strict organization separation
Every request is isolated by organization and API key; other organizations' data is never reachable.
API key auth with rate limits
Every key carries its own RPM limit; authentication runs on hashed keys (SHA-256), never stored in plaintext.
Audited key handling
API key creation and revocation are logged and traceable in the audit log.
EU infrastructure
Hosted in Frankfurt
All infrastructure runs in AWS eu-central-1 (Frankfurt).
EU providers only
Requests are routed exclusively to inference providers hosted in the EU.
Legal review before going live
Every provider goes through a legal review before any traffic flows to it.
How we vet providers
- 01
Collect documents
Terms of service, DPAs, and certificates are gathered systematically.
- 02
Full-text review & clarifying questions
Every document is read in full; open points go back to the provider as clarifying questions.
- 03
Contractual evidence, not website claims
Only what's backed by contract clauses or written commitments is scored, not marketing copy.
- 04
Ongoing review with dated snapshots
Every rating carries a review date and is re-checked whenever something changes.
Provider Compliance Ranking
Every provider in the Kontinent catalog, rated on publicly verifiable compliance facts: six dimensions, tiers A–E, an open methodology, and a source citation for every rating.
View full rankingFAQ
Where is my data processed?+
The Kontinent gateway runs in AWS eu-central-1 (Frankfurt); requests are routed exclusively to providers hosted in the EU.
Are my prompts stored?+
No. Prompt and response content is never persisted or logged. Only metadata such as token counts, latency, status code, and the model used is stored (see "What happens to a request" above).
Is my data used for training?+
Kontinent itself never stores content, so it cannot use it for training. Whether an individual provider contractually commits to a training exclusion varies by provider; see the compliance ranking for the per-provider rating.
How are providers vetted?+
Every provider goes through a legal review of its terms, DPA, and certificates before any traffic flows to it; details in "How we vet providers" above and in the full compliance ranking.
What certifications does Kontinent hold?+
ISO/IEC 27001 certification is in preparation, and SOC 2 Type II is on the roadmap. GDPR-compliant processing and an Art. 28 DPA are already available.
How do I report a security issue?+
Email security@kontinent.ai or follow the details at /.well-known/security.txt.
Subprocessors
All service providers who may process data as part of delivering the service. Inference providers are only added after a completed legal review.
| Subprocessor | Purpose | Location / ZDR |
|---|---|---|
| Amazon Web Services (AWS) | Hosting & infrastructure | EU (eu-central-1, Frankfurt) |
| Stripe | Payment processing | EU / USA (SCCs) |
| Metronome | Usage-based billing (metering, credits; no customer content) | USA (SCCs) |
| PostHog | Product analytics (consent-based only) | EU (Frankfurt) |
| AWS Bedrock (EU Irland) | AI model inference (EU) | EU · ZDR (partial) |
| Mistral La Plateforme | AI model inference (EU) | EU · ZDR (partial) |
| Scaleway Generative APIs | AI model inference (EU) | EU · ZDR (partial) |
| OVHcloud AI Endpoints | AI model inference (EU) | EU · Zero Data Retention |
| IONOS AI Model Hub | AI model inference (EU) | EU · Zero Data Retention |
| Inceptron | AI model inference (EU) | EU · Zero Data Retention |
| Regolo AI | AI model inference (EU) | EU · Zero Data Retention |
| Nebul | AI model inference (EU) | EU · Zero Data Retention |
| Nebius Token Factory | AI model inference (EU) | EU · ZDR (partial) |
| AKI.IO | AI model inference (EU) | EU · Zero Data Retention |
| Google Vertex AI (EU) | AI model inference (EU) | EU · Zero Data Retention |
| TensorX | AI model inference (EU) | EU · Zero Data Retention |
| Infercom | AI model inference (EU) | EU · Zero Data Retention |
| Azure OpenAI (EU Data Zone) | AI model inference (EU) | EU |
| AWS Bedrock (EU Frankfurt) | AI model inference (EU) | EU · ZDR (partial) |
Documents
We provide further evidence (e.g. TOM annex, provider DPAs, certification confirmations) on request: security@kontinent.ai.
Report a security issue: security@kontinent.ai or /.well-known/security.txt.