Skip to main content
Home Security

Security, locations and certificates

NexPatch runs your systems in Germany or in an EU zone you name, under German and EU data protection law. We hold ISO 27001 and SOC 2 Type II, both with a stated audit date, not just a badge. Models run on open weights, so you can take them with you at any time. Everything on this page is written to be checked, not taken on faith.

01  Where the processing happens

Primary locationProcessing runs in a data centre in Frankfurt am Main, Germany, or in a named EU zone agreed with you before the contract is signed.Named in the contract, not decided afterwards
OperatorInfrastructure is operated by NexPatch directly, or by a named subcontractor bound by a documented data processing agreement.No silent hand-off to a third party
SubcontractorsEvery subcontractor with system access is listed by name, function and location as part of the contract, not disclosed after the fact.Updated before a change, never after

02  Data processing agreement

Contract positionA data processing agreement under Art. 28 GDPR is signed before any customer data moves, standard for every engagement, not a negotiated extra.Template available on request
Deletion conceptDeletion periods are defined per data category, executed on schedule, and confirmed in writing on request.Documented, auditable
LoggingEvery access to customer data is logged: who, when, on what, for what purpose, retained for the agreed audit period.Exportable for your own audit

03  Technical measures

Access control

Role-based access with a per-user permission check on every request. No shared service accounts.

Separation

Your data and models run in a dedicated environment, isolated from other customers at network and storage level.

Encryption

At rest and in transit. Keys are managed within the named location, no key access from outside the EU.

Logs

Full request and access logging, exportable in a documented format for your own compliance function.

04  Certificates

CertificateScopeAudit statusDate
ISO 27001Information security management systemCertified, external auditAudited Mar 2026, next surveillance Mar 2027
SOC 2 Type IISecurity, availability and confidentiality controlsReport available on requestPeriod audited Jan to Dec 2025, issued Feb 2026
Art. 28 GDPR DPAData processing agreement, standard contractSigned per customer, reviewed annuallyCurrent version dated Aug 2026

05  Test criteria for sovereignty

The differentiator

Ask us these seven questions, and check the answers yourself

No reviewed competitor publishes criteria against which sovereignty can be tested. Here is ours. Take it to any provider, including us.

  • Name the exact location and the operator, in writing, before the contract is signed.
  • Name every subcontractor with system access, by name and function.
  • Show the audit report or certificate, with a date, not just a badge on a page.
  • Confirm in the contract that model weights and fine-tuning are yours to take with you.
  • State the deletion period per data category, and confirm it executes on schedule.
  • Name a single accountable contact if a deadline under the AI Act or NIS2 is missed.
  • Publish this list. If a provider will not, that is itself the answer.
Download this checklist as a PDF →

06  Regulatory classification

RegulationDeadlineWhat it means for you
EU AI ActPhased, high-risk obligations from Aug 2026We classify your use case and tell you which obligations apply, before you ask.
NIS2German transposition in progress, 2026Relevant if your company counts as an essential or important entity under the national law.
Data ActApplies from Sep 2025Governs access to and portability of data generated by connected products and services.
Deadlines as of August 2026, we track changes and notify affected customers. This is not legal advice, the classification is what we deliver.

Operations and Service Level →  ·  Private AI infrastructure →  ·  Book an initial call →