Security
Trust and compliance
This page collects the facts that security, privacy, and compliance teams need when assessing Privatemode. It links to the authoritative documents on privatemode.ai where they exist, and to the technical details elsewhere in these docs.
Provider and jurisdiction
| Topic | Details |
|---|---|
| Service provider | Edgeless Systems GmbH, Bochum, Germany. See the imprint. |
| Infrastructure providers | Scaleway SAS (France) and Lyceum Technology Germany GmbH (Germany). Both provide infrastructure with confidential-computing capabilities in the EU. |
| Data location | Prompts and responses are processed exclusively within the EU. |
| Governing law | German law, as set out in the data processing agreement. |
Confidential computing ensures that neither the infrastructure providers nor Edgeless Systems can access prompts or responses. The Security overview explains which parties are involved in an inference request and why they can't access your data. The Architecture section describes how this is enforced.
Contracts and data protection
- Data processing agreement (DPA): The DPA lists the sub-processors and the technical and organizational measures. It's available to all customers.
- Privacy policy and terms: See the privacy policy and the terms of service.
- Professional secrecy: A review by an external advisory firm recommends Privatemode for professions bound by professional secrecy under § 203 of the German Criminal Code (StGB), such as doctors, lawyers, and tax advisors. The review is available on request.
Certifications and audits
- ISO 27001: Edgeless Systems is ISO 27001 certified.
- BSI C5:2026: Privatemode meets the criteria for "very strong attestation," the highest grade that Germany's Federal Office for Information Security (BSI) defines for confidential computing in cloud services. See the blog post for details.
- External audits and penetration tests: Reviews and audits by Big Four firms and cybersecurity consultancies confirm Privatemode's security and privacy properties. Reports are available on request.
Data processing and retention
Prompts and responses are encrypted end-to-end and processed only inside confidential-computing environments. They aren't stored after a request completes, and they aren't used for training.
For operating the service, the following metadata is stored for up to 90 days:
- IP address
- Timestamp
- API key
- Token usage
- Request metadata: path, method, status code
- Response time
Token usage per API key is stored permanently for billing purposes.
Two further details matter for a data-flow assessment:
- A few request fields, such as the model name and token limits, remain unencrypted so that the service can route and account for requests. The Encryption page lists them.
- Transient inference state is kept in a prompt cache in worker memory. Prompt cache security describes how cache entries are isolated between tenants.
Verifiability
Privatemode's source code is public and built reproducibly. Clients verify the deployed software through remote attestation before any data is sent. The Verification from source code and Verification of model integrity guides show how to reproduce the reference values independently.
Operations
- Service status: See the status page.
- Hardware vulnerabilities: The Hardware integrity status page tracks published CPU and GPU vulnerabilities and their mitigation status in Privatemode.
- Changes: The release notes list every change to the service, including new and removed models.
- Contact: For questions that this page doesn't answer, contact support.