EU data-residency is an opt-in add-on for eligible API/Enterprise; the default routes globally. As a US company, data remains reachable under the CLOUD Act / FISA 702.
AI Vendor Residency Lookup
Where popular AI vendors host and process your data, their EU-residency options, and US CLOUD Act exposure — at a glance. Filter, search, shortlist.
Strong EU posture via the Microsoft EU Data Boundary and EU regions — but Microsoft is a US parent, so the CLOUD Act still reaches the data even when it is stored in the EU.
EU regions (eu-*) are available and processing can stay in-region, but the US parent keeps the data reachable under the CLOUD Act.
EU regions and data-residency controls exist, but Google is a US company subject to the CLOUD Act. The consumer Gemini app is separate and not residency-controlled.
Processing is primarily US-based; the API does not expose EU regional endpoints the way hyperscalers do. A DPA is published, but data leaves the EU and is CLOUD-Act reachable.
A French company under EU law, processing on EU servers with contractual EU-residency. Not subject to US jurisdiction. Open-weight models can also be self-hosted.
German provider built for sovereignty — EU / on-premise deployment, no US nexus. A strong fit for public sector and regulated industry. Note: a combination with Cohere (Canada) was announced in April 2026 and is reported as subject to regulatory approval; processing and deployment remain German/EU today, but confirm the ownership position directly with the vendor if it matters to your assessment.
German cloud, EU data centres, German/EU law. Managed inference without a US parent in the chain.
Sovereign German cloud (Schwarz Group). No US parent; aimed squarely at EU data-sovereignty requirements.
French cloud with EU data centres and EU law. SecNumCloud-aligned options; no US jurisdiction over the core EU offering.
US-incorporated, so CLOUD-Act exposed for the hosted service — but the catalogue of open models can be downloaded and run entirely on your own infrastructure.
Open models running on your own servers — air-gappable. No vendor, no egress, nothing reachable by a foreign authority. The sovereign default RAGSuite is built around.
No vendors match — try a different filter or search.
Reference, not legal advice. Positions are summarised from each provider’s stated terms as of June 2026 and change often. Confirm against the current DPA, sub-processor list and your own DPIA. “CLOUD Act exposure” reflects corporate reachability, not any specific disclosure.
Good to know
Where does this data come from?
Each entry summarises the provider’s own stated position — jurisdiction, EU-residency options and deployment model — as of June 2026. Providers change terms often; treat this as a starting map and confirm against their current DPA and sub-processor list.
Why does a US provider’s EU region still show exposure?
The US CLOUD Act reaches any US-incorporated company regardless of where the data sits. An EU region helps with latency and some residency requirements, but the parent company remains legally compellable. Only a non-US provider — or self-hosting — removes that.
Is this legal advice?
No. It’s an informational reference for shortlisting. Pair it with your own DPIA and qualified counsel before a procurement decision.
Want this guaranteed in your own infrastructure?
Get a copy of these results by email and see RAGSuite running on a setup like yours — citation-backed, self-hosted, EU-ready.
Thanks — we’ll be in touch within one business day (DE/EN).
There’s a row with no exposure at all.
Self-hosted, with local models via Ollama, RAGSuite keeps retrieval and generation on your own infrastructure — no vendor, no egress, nothing a foreign authority can reach.