kontinent / compliance index

B

Infercom

Infercom SCS · LU · Last reviewed: 2026-07-30

75

Data Protection Contracts

100/100

Infercom has a Data Processing Agreement (DPA v1.3) under Art. 28 GDPR, automatically incorporated upon acceptance of the terms of service.

ja

Source: Infercom DPA v1.3 (wirksam 04.03.2026), Öffentlich als PDF verfügbar, inkl. Subprozessor-Tabelle + TOM-Annex; automatisch per ToS-Akzeptanz inkorporiert (reviewed 2026-07-24)

Infercom contractually provides Standard Contractual Clauses and/or EU-US Data Privacy Framework coverage for necessary data transfers.

ja

Source: Infercom DPA v1.3, §7a - EU-US DPF und/oder Standardvertragsklauseln für Datentransfers vereinbart, Transfer Impact Assessment auf Anfrage (reviewed 2026-07-24)

Infercom contractually commits to notifying security incidents within 48 hours.

ja

Source: Infercom DPA v1.3, §9(1)(b) - 48 Stunden vertraglich zugesichert (reviewed 2026-07-24)

Data Residency & Sovereignty

50/100

Infercom operates a model catalog hosted exclusively in the EU (Munich) alongside a global catalog that processes requests outside the EU. On enquiry, Infercom does not guarantee any specific region for the global catalog beyond outside-the-EU, and no account-level restriction is available; separation relies on per-model metadata. Kontinent uses only the EU-hosted catalog.

teilweise

Source: Infercom Produktkatalog / DPA v1.3 + schriftliche Bestätigung Infercom (Go-To-Market Lead, 29.07.2026), EU-Hosted-Katalog ausschließlich Equinix München MU4 (vertraglich zugesichert); Global Model Catalog verarbeitet auf SambaNova-Infrastruktur außerhalb der EU. Schriftlich bestätigt 29.07.2026: für den globalen Katalog wird keine Region über 'außerhalb der EU' hinaus garantiert, und eine Restriktion auf Kontoebene ist nicht verfügbar ('That control does not exist yet'); Trennung nur per Modell-Metadaten möglich. Kontinent bindet ausschließlich den EU-gehosteten Katalog ein. (reviewed 2026-07-29)

The divergence between the DPA and the privacy policy is resolved (written statement, 2026-08-04): the DPA covers Infercom as an Article 28 processor and names the sub-processors it engages directly (SambaNova Systems, Stripe Payments Europe, TECLIB); the privacy policy covers Infercom as controller of account, billing and support data and names Auth0 and Metronome as recipients there. Two documents, two roles, no contradiction. The status remains partial because the chain includes US recipients: SambaNova (US) operates the platform, and Auth0 and Metronome (both US) sit one level below it under SambaNova's Article 28(4) flow-down. A complete second-tier list has been requested.

teilweise

Source: Infercom DPA v1.3 §7 / Privacy Policy §7.1 + schriftliche Auskunft Thomas Vits (Infercom) 2026-08-04, Abschnitt 'Sub-processor list': DPA = Auftragsverarbeiter-Rolle mit direkt beauftragten Subprozessoren, Datenschutzerklärung = Verantwortlichen-Rolle mit Empfängern; Auth0 und Metronome von SambaNova beauftragt, Art.-28(4)-Flow-down bei SambaNova, Infercom bleibt uns gegenüber voll verantwortlich (reviewed 2026-08-04)

Infercom operates as Infercom SCS, headquartered in Luxembourg (RCS B298727); official confirmation of the trade register entry is still pending.

teilweise

Source: Infercom Selbstangabe / RCS-Auszug (ausstehend), Infercom SCS, Luxemburg, RCS B298727 (Selbstangabe des Anbieters) - amtlicher Registerauszug zur Bestätigung noch nicht beschafft (reviewed 2026-07-24)

Data Use

100/100

Infercom contractually processes requests statelessly and does not store content (zero data retention).

ja

Source: Infercom DPA v1.3, §2(1) - stateless; §11(4) - 'Not retained' (reviewed 2026-07-24)

Infercom contractually does not use customer data for training, fine-tuning, or analytics purposes.

ja

Source: Infercom Terms of Service v2.1, §2.4/§6.3 - 'does not use your Input or Output for model training, fine-tuning, analytics, or any other purpose' (reviewed 2026-07-24)

No opt-out is needed at Infercom, since the use of customer data for training or analytics is contractually excluded without exception.

ja

Source: Infercom Terms of Service v2.1, §2.4/§6.3 - Trainings-/Analysenutzung unbedingt ausgeschlossen, kein Opt-out-Mechanismus nötig (reviewed 2026-07-24)

Certifications

50/100

Infercom holds its own ISO 27001:2022 certification.

ja

Source: Infercom ISO-27001:2022-Zertifikat, ISO 27001:2022 für Infercom selbst zertifiziert, Zertifikat-PDF abgelegt (reviewed 2026-07-24)

Infercom does not hold its own SOC 2 or C5 attestation; corresponding certificates exist only for the data center facility it uses.

nein

Source: Infercom Compliance-Übersicht, Kein eigenes SOC-2-Testat; nur die Equinix-MU4-Rechenzentrumsfacility verfügt über eigene Zertifikate. Kein C5-Testat vorhanden. (reviewed 2026-07-24)

AI Act Readiness

n/a

Pure inference/hosting provider: the AI Act's Article 53 documentation duty falls on the provider of the GPAI model, not on whoever runs the inference. This provider cannot discharge it for third-party models; the duty sits with the respective model provider.

nicht_anwendbar

Source: Verordnung (EU) 2024/1689 (KI-VO), Art. 53 Abs. 1 i. V. m. Art. 3 Nr. 3 – Pflichten des Anbieters eines GPAI-Modells (reviewed 2026-08-04)

Pure inference/hosting provider: the GPAI Code of Practice is open to providers of general-purpose AI models. A provider that merely operates third-party models is not eligible to sign, so an absent signature is not a shortcoming.

nicht_anwendbar

Source: Verordnung (EU) 2024/1689 (KI-VO), Art. 53 Abs. 1 i. V. m. Art. 3 Nr. 3 – Pflichten des Anbieters eines GPAI-Modells (reviewed 2026-08-04)

Contract Quality & Transparency

50/100

Infercom's contract documents (terms of service, privacy policy, DPA) are publicly available, and contracting is done via self-service.

ja

Source: Infercom Terms of Service v2.1 / Privacy Policy v2.2 / DPA v1.3, Öffentlich als PDF verfügbare Vertragsdokumente, Self-Service-Signup über infercom.ai (reviewed 2026-07-24)

Infercom does not offer an SLA for pay-as-you-go plans; an SLA is only available for dedicated instances under a separate contract.

nein

Source: Infercom Produktdokumentation, Kein SLA für Pay-as-you-go-Tarife; ein SLA existiert nur für Dedicated-Instanzen im Rahmen eines separaten Vertrags (reviewed 2026-07-24)

Infercom's liability is contractually capped at six months' fees – lower than the standard 12-month market cap.

teilweise

Source: Infercom Terms of Service v2.1, §11.1 - Haftungsdeckel auf 6 Monatsgebühren begrenzt (reviewed 2026-07-24)

Do you represent Infercom and think something is inaccurate? Write to legal@kontinent.ai. We check every report and correct verified errors with full transparency.

Report error

Methodology Version 2.0