kontinent / trust center

Security & Compliance

Kontinent is built as an EU-sovereign AI gateway: your data stays in the EU, content is never stored, and every connected provider goes through a legal review before any traffic flows to it. This page summarizes our security and privacy commitments transparently.

17

Providers reviewed

14

Publicly rated

16

Review criteria per provider

0

Stored prompts, by design

What happens to a request

Client

Kontinent Gateway

Frankfurt · eu-central-1

EU provider

Never stored

  • Prompt content
  • Response content

Stored (metadata)

  • Token counts
  • Latency
  • Status code
  • Model/provider

Zero retention, tested

Our end-to-end suite sends marked test prompts (a sentinel value) through the full stack and then greps every gateway and worker log for it. If the sentinel shows up anywhere, the test fails. The zero-retention promise is verified on every run, not just asserted.

Compliance

GDPR

Met

Processing in line with GDPR; a DPA under Art. 28 is available.

EU data residency

Met

Routing exclusively to EU-hosted providers; hosting in Frankfurt.

ISO/IEC 27001

In progress

Certification in preparation.

SOC 2 Type II

Planned

On the roadmap.

Controls

Data minimization

No prompt logging

Prompt and response content is never stored or logged anywhere: not in usage records, not in the audit log, not in server logs.

Usage data is metadata only

usage_records holds only token counts, latency, status, and model/provider, never content.

Prunable raw records

Usage records are prunable; aggregates and the ledger carry the durable truth, not the individual rows.

Traceability

Append-only audit log

Every control-plane change (sign-ins, org creation, key create/revoke, top-ups, suspensions) lands in the append-only audit_log.

Append-only credit ledger

All balance movements flow through ledger_entries with a unique idempotency_key, so double-booking is structurally impossible.

Per-org audit view

Every organization sees its own audit trail at /audit in the dashboard.

Tenancy separation & access

Strict organization separation

Every request is isolated by organization and API key; other organizations' data is never reachable.

API key auth with rate limits

Every key carries its own RPM limit; authentication runs on hashed keys (SHA-256), never stored in plaintext.

Audited key handling

API key creation and revocation are logged and traceable in the audit log.

EU infrastructure

Hosted in Frankfurt

All infrastructure runs in AWS eu-central-1 (Frankfurt).

EU providers only

Requests are routed exclusively to inference providers hosted in the EU.

Legal review before going live

Every provider goes through a legal review before any traffic flows to it.

How we vet providers

  1. 01

    Collect documents

    Terms of service, DPAs, and certificates are gathered systematically.

  2. 02

    Full-text review & clarifying questions

    Every document is read in full; open points go back to the provider as clarifying questions.

  3. 03

    Contractual evidence, not website claims

    Only what's backed by contract clauses or written commitments is scored, not marketing copy.

  4. 04

    Ongoing review with dated snapshots

    Every rating carries a review date and is re-checked whenever something changes.

Provider Compliance Ranking

Every provider in the Kontinent catalog, rated on publicly verifiable compliance facts: six dimensions, tiers A–E, an open methodology, and a source citation for every rating.

View full ranking

FAQ

Where is my data processed?+

The Kontinent gateway runs in AWS eu-central-1 (Frankfurt); requests are routed exclusively to providers hosted in the EU.

Are my prompts stored?+

No. Prompt and response content is never persisted or logged. Only metadata such as token counts, latency, status code, and the model used is stored (see "What happens to a request" above).

Is my data used for training?+

Kontinent itself never stores content, so it cannot use it for training. Whether an individual provider contractually commits to a training exclusion varies by provider; see the compliance ranking for the per-provider rating.

How are providers vetted?+

Every provider goes through a legal review of its terms, DPA, and certificates before any traffic flows to it; details in "How we vet providers" above and in the full compliance ranking.

What certifications does Kontinent hold?+

ISO/IEC 27001 certification is in preparation, and SOC 2 Type II is on the roadmap. GDPR-compliant processing and an Art. 28 DPA are already available.

How do I report a security issue?+

Email security@kontinent.ai or follow the details at /.well-known/security.txt.

Subprocessors

All service providers who may process data as part of delivering the service. Inference providers are only added after a completed legal review.

SubprocessorPurposeLocation / ZDR
Amazon Web Services (AWS)Hosting & infrastructureEU (eu-central-1, Frankfurt)
StripePayment processingEU / USA (SCCs)
MetronomeUsage-based billing (metering, credits; no customer content)USA (SCCs)
PostHogProduct analytics (consent-based only)EU (Frankfurt)
AWS Bedrock (EU Irland)AI model inference (EU)EU · ZDR (partial)
Mistral La PlateformeAI model inference (EU)EU · ZDR (partial)
Scaleway Generative APIsAI model inference (EU)EU · ZDR (partial)
OVHcloud AI EndpointsAI model inference (EU)EU · Zero Data Retention
IONOS AI Model HubAI model inference (EU)EU · Zero Data Retention
InceptronAI model inference (EU)EU · Zero Data Retention
Regolo AIAI model inference (EU)EU · Zero Data Retention
NebulAI model inference (EU)EU · Zero Data Retention
Nebius Token FactoryAI model inference (EU)EU · ZDR (partial)
AKI.IOAI model inference (EU)EU · Zero Data Retention
Google Vertex AI (EU)AI model inference (EU)EU · Zero Data Retention
TensorXAI model inference (EU)EU · Zero Data Retention
InfercomAI model inference (EU)EU · Zero Data Retention
Azure OpenAI (EU Data Zone)AI model inference (EU)EU
AWS Bedrock (EU Frankfurt)AI model inference (EU)EU · ZDR (partial)

Documents

We provide further evidence (e.g. TOM annex, provider DPAs, certification confirmations) on request: security@kontinent.ai.

Report a security issue: security@kontinent.ai or /.well-known/security.txt.