Trust Center
Trust, verifiable.
Serpentine is built for security teams. We secure your security data with the same rigor you bring to your own infrastructure.
Data Residency
EU-hosted infrastructure
EU-hosted by default. Designed for EU data residency. Infrastructure and subprocessors are documented in the Trust Center.
Primary Region
Frankfurt, Germany
Backup Region
Amsterdam, Netherlands
Data Residency
EU-hosted by default
Jurisdiction
German and EU law applies
Infrastructure provided by datacenter partners that maintain ISO 27001 and SOC 2 certifications.
AI Data Handling
Controlled AI processing
Your data is never used to train AI models. All AI processing happens within our EU infrastructure with full source traceability.
AI Data Controls
Security Posture
How we secure Serpentine
We apply the same standards to our infrastructure that we help you achieve.
Access control
Role-based access with principle of least privilege. All access logged and auditable.
Logging and audit trails
Complete audit trail of all data access, modifications, and administrative actions.
Vulnerability management
Continuous scanning, prioritized remediation, and validated fixes. We use Serpentine on Serpentine.
Incident response
Documented incident response procedures with defined SLAs and communication protocols.
Data isolation
Tenant data is logically isolated. No cross-tenant data access.
Infrastructure hardening
CIS-benchmarked compute instances with automated configuration drift detection.
Documentation
Security and legal documents
Transparent documentation for your compliance and legal teams. Request access to detailed security documentation.
Data Processing Agreement
GDPR-compliant DPA available for all customers
Subprocessor List
Third parties who process customer data
Responsible Disclosure
How to report security vulnerabilities
Security Posture
Technical security overview and controls
AI Data Handling
How we handle data in AI processing
Infrastructure Controls
Physical and logical security controls
Certifications & Registries
Third-party validation
Serpentine is listed in the Cloud Security Alliance STAR Registry at Level One: Self-Assessment, with a published Consensus Assessment Initiative Questionnaire (CAIQ) v4 covering all 261 CCM control criteria. The listing is publicly searchable on the CSA STAR Registry and is refreshed at least annually.
Serpentine infrastructure runs on datacenter partners that maintain ISO 27001 and SOC 2 Type II certifications.
EU AI Act Compliance
AI Act self-classification completed
SPNT/Serpentine has completed EU AI Act self-classification assessment via the official Commission AI Act Service Desk tool. Classified as a limited-risk AI system, with Article 50 transparency obligations implemented. Not subject to high-risk AI system requirements under Chapter 3.
SOC 2 Type II
Controls operationalOur SOC 2 control environment is operational today — access control, logging, change management, and incident response are implemented and running. The independent third-party audit is scheduled for 2027, which will formally validate our security, availability, processing integrity, confidentiality, and privacy practices.
Credentials & Registrations
Partnerships and registrations
Verifiable partnerships and government registrations that back our security and sovereignty claims.
Anthropic — Claude Partner
CVP-approved frontier-model access. Serpentine's reasoning layer is built on Anthropic Claude in the cloud, with sovereign on-prem inference via Jadro.
NSPA (NATO) Registration
Registered supplier with the NATO Support and Procurement Agency, with an assigned NCAGE commercial and government entity code.
CSA STAR Level 1
Listed in the Cloud Security Alliance STAR Registry at Level One, with a published CAIQ v4 covering all CCM control criteria.
EU Small-Business Certificate
Certified small business and part of the European tender network, eligible to participate in EU public procurement.
EU AI Act & GDPR
AI Act self-classification completed (limited-risk, Article 50 transparency). GDPR-aligned, EU-hosted, with zero customer data used for model training.
EU-Hosted Infrastructure
Sovereign EU infrastructure on OVHcloud, with on-prem and air-gapped deployment available via Jadro for regulated and classified environments.
