SPNT

Trust Center

Trust, verifiable.

Serpentine is built for security teams. We secure your security data with the same rigor you bring to your own infrastructure.

Data Residency

EU-hosted infrastructure

EU-hosted by default. Designed for EU data residency. Infrastructure and subprocessors are documented in the Trust Center.

Primary Region

Frankfurt, Germany

Backup Region

Amsterdam, Netherlands

Data Residency

EU-hosted by default

Jurisdiction

German and EU law applies

Infrastructure provided by datacenter partners that maintain ISO 27001 and SOC 2 certifications.

AI Data Handling

Controlled AI processing

Your data is never used to train AI models. All AI processing happens within our EU infrastructure with full source traceability.

No customer data used for model training
AI inference runs on EU infrastructure
Full reasoning traces preserved for audit
Human review required for compliance decisions
Opt-out available for all AI features

AI Data Controls

AI-assisted analysisPer-org configurable
Source traceabilityAlways enabled
Reasoning trace loggingAlways enabled
Data retentionCustomer controlled
Compliance decisionsHuman review required

Security Posture

How we secure Serpentine

We apply the same standards to our infrastructure that we help you achieve.

Access control

Role-based access with principle of least privilege. All access logged and auditable.

Logging and audit trails

Complete audit trail of all data access, modifications, and administrative actions.

Vulnerability management

Continuous scanning, prioritized remediation, and validated fixes. We use Serpentine on Serpentine.

Incident response

Documented incident response procedures with defined SLAs and communication protocols.

Data isolation

Tenant data is logically isolated. No cross-tenant data access.

Infrastructure hardening

CIS-benchmarked compute instances with automated configuration drift detection.

Certifications & Registries

Third-party validation

Serpentine is listed in the Cloud Security Alliance STAR Registry at Level One: Self-Assessment, with a published Consensus Assessment Initiative Questionnaire (CAIQ) v4 covering all 261 CCM control criteria. The listing is publicly searchable on the CSA STAR Registry and is refreshed at least annually.

Serpentine infrastructure runs on datacenter partners that maintain ISO 27001 and SOC 2 Type II certifications.

EU AI Act Compliance

AI Act self-classification completed

SPNT/Serpentine has completed EU AI Act self-classification assessment via the official Commission AI Act Service Desk tool. Classified as a limited-risk AI system, with Article 50 transparency obligations implemented. Not subject to high-risk AI system requirements under Chapter 3.

SOC 2 Type II

Controls operational

Our SOC 2 control environment is operational today — access control, logging, change management, and incident response are implemented and running. The independent third-party audit is scheduled for 2027, which will formally validate our security, availability, processing integrity, confidentiality, and privacy practices.

Credentials & Registrations

Partnerships and registrations

Verifiable partnerships and government registrations that back our security and sovereignty claims.

Active

Anthropic — Claude Partner

CVP-approved frontier-model access. Serpentine's reasoning layer is built on Anthropic Claude in the cloud, with sovereign on-prem inference via Jadro.

Active

NSPA (NATO) Registration

Registered supplier with the NATO Support and Procurement Agency, with an assigned NCAGE commercial and government entity code.

Achieved

CSA STAR Level 1

Listed in the Cloud Security Alliance STAR Registry at Level One, with a published CAIQ v4 covering all CCM control criteria.

Registered

EU Small-Business Certificate

Certified small business and part of the European tender network, eligible to participate in EU public procurement.

Aligned

EU AI Act & GDPR

AI Act self-classification completed (limited-risk, Article 50 transparency). GDPR-aligned, EU-hosted, with zero customer data used for model training.

OVHcloud

EU-Hosted Infrastructure

Sovereign EU infrastructure on OVHcloud, with on-prem and air-gapped deployment available via Jadro for regulated and classified environments.