Security, locations and certificates
NexPatch runs your systems in Germany or in an EU zone you name, under German and EU data protection law. We hold ISO 27001 and SOC 2 Type II, both with a stated audit date, not just a badge. Models run on open weights, so you can take them with you at any time. Everything on this page is written to be checked, not taken on faith.
01 Where the processing happens
02 Data processing agreement
03 Technical measures
Role-based access with a per-user permission check on every request. No shared service accounts.
Your data and models run in a dedicated environment, isolated from other customers at network and storage level.
At rest and in transit. Keys are managed within the named location, no key access from outside the EU.
Full request and access logging, exportable in a documented format for your own compliance function.
04 Certificates
| Certificate | Scope | Audit status | Date |
|---|---|---|---|
| ISO 27001 | Information security management system | Certified, external audit | Audited Mar 2026, next surveillance Mar 2027 |
| SOC 2 Type II | Security, availability and confidentiality controls | Report available on request | Period audited Jan to Dec 2025, issued Feb 2026 |
| Art. 28 GDPR DPA | Data processing agreement, standard contract | Signed per customer, reviewed annually | Current version dated Aug 2026 |
05 Test criteria for sovereignty
Ask us these seven questions, and check the answers yourself
No reviewed competitor publishes criteria against which sovereignty can be tested. Here is ours. Take it to any provider, including us.
- Name the exact location and the operator, in writing, before the contract is signed.
- Name every subcontractor with system access, by name and function.
- Show the audit report or certificate, with a date, not just a badge on a page.
- Confirm in the contract that model weights and fine-tuning are yours to take with you.
- State the deletion period per data category, and confirm it executes on schedule.
- Name a single accountable contact if a deadline under the AI Act or NIS2 is missed.
- Publish this list. If a provider will not, that is itself the answer.
06 Regulatory classification
| Regulation | Deadline | What it means for you |
|---|---|---|
| EU AI Act | Phased, high-risk obligations from Aug 2026 | We classify your use case and tell you which obligations apply, before you ask. |
| NIS2 | German transposition in progress, 2026 | Relevant if your company counts as an essential or important entity under the national law. |
| Data Act | Applies from Sep 2025 | Governs access to and portability of data generated by connected products and services. |
Operations and Service Level → · Private AI infrastructure → · Book an initial call →