Security

Trust and compliance

This page collects the facts that security, privacy, and compliance teams need when assessing Privatemode. It links to the authoritative documents on privatemode.ai where they exist, and to the technical details elsewhere in these docs.

Provider and jurisdiction

TopicDetails
Service providerEdgeless Systems GmbH, Bochum, Germany. See the imprint.
Infrastructure providersScaleway SAS (France) and Lyceum Technology Germany GmbH (Germany). Both provide infrastructure with confidential-computing capabilities in the EU.
Data locationPrompts and responses are processed exclusively within the EU.
Governing lawGerman law, as set out in the data processing agreement.

When you use the Privatemode SDK or proxy, confidential computing and client-verified end-to-end encryption ensure that neither the infrastructure providers nor Edgeless Systems can access prompts or responses. The Security overview explains which parties are involved in an inference request and why they can't access your data. The Architecture section describes how this is enforced.

The proxyless API provides memory encryption and TLS termination inside a confidential computing environment, but no client-side attestation. Edgeless Systems controls the deployment and its TLS credentials.

Contracts and data protection

  • Data processing agreement (DPA): The DPA lists the sub-processors and the technical and organizational measures. It's available to all customers.
  • Privacy policy and terms: See the privacy policy and the terms of service.
  • Professional secrecy: A review by an external advisory firm recommends Privatemode for professions bound by professional secrecy under § 203 of the German Criminal Code (StGB), such as doctors, lawyers, and tax advisors. The review is available on request.

Certifications and audits

  • ISO 27001: Edgeless Systems is ISO 27001 certified.
  • BSI C5:2026: Privatemode meets the criteria for "very strong attestation," the highest grade that Germany's Federal Office for Information Security (BSI) defines for confidential computing in cloud services. See the blog post for details.
  • External audits and penetration tests: Reviews and audits by Big Four firms and cybersecurity consultancies confirm Privatemode's security and privacy properties. Reports are available on request.

Data processing and retention

Prompts and responses are encrypted end-to-end and processed only inside confidential-computing environments. They aren't stored after a request completes, and they aren't used for training.

For operating the service, the following metadata is stored for up to 90 days:

  • IP address
  • Timestamp
  • API key
  • Token usage
  • Request metadata: path, method, status code
  • Response time

Token usage per API key is stored permanently for billing purposes.

Two further details matter for a data-flow assessment:

  • A few request fields, such as the model name and token limits, remain unencrypted so that the service can route and account for requests. The Encryption page lists them.
  • Transient inference state is kept in a prompt cache in worker memory. Prompt cache security describes how cache entries are isolated between tenants.

Verifiability

Privatemode's source code is public and built reproducibly. The SDK and proxy verify the backend through remote attestation before sending inference data. The Verification from source code and Verification of model integrity guides show how to reproduce the reference values independently.

The proxyless API verifies the inference backend on your behalf. Client-side remote attestation and reproducible verification of the proxyless API deployment aren't currently supported. See Implementation details for its request flow and public deployment manifest.

Operations

  • Service status: See the status page.
  • Hardware vulnerabilities: The Hardware integrity status page tracks published CPU and GPU vulnerabilities and their mitigation status in Privatemode.
  • Changes: The release notes list every change to the service, including new and removed models.
  • Contact: For questions that this page doesn't answer, contact support.