SovInfra / Security
Sovereignty and Security
Where your data is processed, who operates the service, and how it is handled.
Inference operated in Europe, using open-weight models and an explicit data handling policy.
01 / Where is your data processed?
Inference processing takes place within the European Union. Our infrastructure combines GPUs in the Czech Republic, orchestration in France and redundancy in Germany. The inference service is separate from payment services and any third-party tools enabled by the client.
02 / Who is responsible for the service?
SovInfra is operated by FPLC SAS, a French company with no US parent company. Server locations, operator identities and administrative access are key factors when assessing the sovereignty of the service.
03 / Who operates the infrastructure?
Operations are handled by teams in Europe: VS Hosting for GPU hosting, RINF for inference operations, Selectiv T & C for network monitoring, Hetzner for redundancy, and the SovInfra team for the gateway and billing.
04 / What can you verify?
The models served are identified by version and numerical precision. The Arena lets you measure performance. The status page reports availability and its history. Technical resources published on Codeberg complement this documentation.
Your data. Your workloads.
SovAPI data handling commitments.
Inference content and caching
Requests, documents, images, audio files and responses are processed in memory, without content logging or persistent server-side retention. They are not used to train models. Prefix caching may temporarily retain context in memory; the cache is volatile and isolated by API key.
The API does not retain conversation history. In the SovAPI console, text history remains in the browser. Account data, billing data and usage metadata follow the retention periods specified in the privacy policy.
Encryption and access controls
Data in transit is encrypted using TLS 1.3, and retained data is encrypted using AES-256. System access is restricted and logged. API keys can be revoked from the console. No third-party connector is enabled by default.
| Provider | Role | Location |
|---|---|---|
| VS Hosting | GPU hosting | Czech Republic |
| RINF / Selectiv T & C | Operations / monitoring | Romania |
| Hetzner | Redundancy and backup | Germany |
| Stripe / Brevo | Payments / transactional emails | See the privacy policy |
Documents and certifications
The privacy policy, legal notice and terms of service define the framework for the service. The Data Processing Agreement (DPA) complements these documents. Rinf.tech holds ISO 27001 certification. For FPLC SAS, ISO 27001 certification and SecNumCloud qualification are in preparation and have not yet been obtained.