Public previewRAGSuite is open-source, self-hosted and EU-ready — and we build it in the open.See it live

Platform Platform overviewSee it in actionAI SearchAI AssistantAI Connectors & MCPIntegrationsQuality LoopAdministration & SecurityMobile app
Solutions IT & Platform teamsCompliance & Data ProtectionDevelopersAgencies & Partners
Sovereignty
References
Pricing
Resources Trust CenterEU AI ActSecurity & disclosureFree toolsOpen source & open coreDocumentation ↗API reference ↗GitHub ↗ReferencesBlogChangelog
Company AboutPartnersContact
Search See it live Book a demo
Free tools Sovereignty & compliance

AI Vendor Residency Lookup

Where popular AI vendors host and process your data, their EU-residency options, and US CLOUD Act exposure — at a glance. Filter, search, shortlist.

Runs in your browser No upload · no third-party calls Free · no sign-up · no tracking
OpenAI API
LLM API · United States
EU region available CLOUD Act: High exposure

EU data-residency is an opt-in add-on for eligible API/Enterprise; the default routes globally. As a US company, data remains reachable under the CLOUD Act / FISA 702.

Azure OpenAI
Hyperscaler AI · United States (Microsoft)
EU region available CLOUD Act: High exposure

Strong EU posture via the Microsoft EU Data Boundary and EU regions — but Microsoft is a US parent, so the CLOUD Act still reaches the data even when it is stored in the EU.

AWS Bedrock
Hyperscaler AI · United States (Amazon)
EU region available CLOUD Act: High exposure

EU regions (eu-*) are available and processing can stay in-region, but the US parent keeps the data reachable under the CLOUD Act.

Google Vertex AI / Gemini
Hyperscaler AI · United States (Google)
EU region available CLOUD Act: High exposure

EU regions and data-residency controls exist, but Google is a US company subject to the CLOUD Act. The consumer Gemini app is separate and not residency-controlled.

Anthropic API (Claude)
LLM API · United States
US / global default CLOUD Act: High exposure

Processing is primarily US-based; the API does not expose EU regional endpoints the way hyperscalers do. A DPA is published, but data leaves the EU and is CLOUD-Act reachable.

Mistral API
LLM API · France (EU)
EU-native CLOUD Act: Not reachable Self-hostable

A French company under EU law, processing on EU servers with contractual EU-residency. Not subject to US jurisdiction. Open-weight models can also be self-hosted.

Aleph Alpha
EU sovereign · Germany (EU)
EU-native CLOUD Act: Not reachable Self-hostable

German provider built for sovereignty — EU / on-premise deployment, no US nexus. A strong fit for public sector and regulated industry. Note: a combination with Cohere (Canada) was announced in April 2026 and is reported as subject to regulatory approval; processing and deployment remain German/EU today, but confirm the ownership position directly with the vendor if it matters to your assessment.

IONOS AI Model Hub
EU sovereign · Germany (EU)
EU-native CLOUD Act: Not reachable

German cloud, EU data centres, German/EU law. Managed inference without a US parent in the chain.

STACKIT
EU sovereign · Germany (EU)
EU-native CLOUD Act: Not reachable

Sovereign German cloud (Schwarz Group). No US parent; aimed squarely at EU data-sovereignty requirements.

OVHcloud AI
EU sovereign · France (EU)
EU-native CLOUD Act: Not reachable

French cloud with EU data centres and EU law. SecNumCloud-aligned options; no US jurisdiction over the core EU offering.

Hugging Face Inference
LLM API · United States (FR founders)
EU region available CLOUD Act: Exposed Self-hostable

US-incorporated, so CLOUD-Act exposed for the hosted service — but the catalogue of open models can be downloaded and run entirely on your own infrastructure.

Ollama / self-hosted (local)
Self-hosted · Your infrastructure
EU-native CLOUD Act: Not reachable Self-hostable

Open models running on your own servers — air-gappable. No vendor, no egress, nothing reachable by a foreign authority. The sovereign default RAGSuite is built around.

Reference, not legal advice. Positions are summarised from each provider’s stated terms as of June 2026 and change often. Confirm against the current DPA, sub-processor list and your own DPIA. “CLOUD Act exposure” reflects corporate reachability, not any specific disclosure.

About this tool

Good to know

Where does this data come from?

Each entry summarises the provider’s own stated position — jurisdiction, EU-residency options and deployment model — as of June 2026. Providers change terms often; treat this as a starting map and confirm against their current DPA and sub-processor list.

Why does a US provider’s EU region still show exposure?

The US CLOUD Act reaches any US-incorporated company regardless of where the data sits. An EU region helps with latency and some residency requirements, but the parent company remains legally compellable. Only a non-US provider — or self-hosting — removes that.

Is this legal advice?

No. It’s an informational reference for shortlisting. Pair it with your own DPIA and qualified counsel before a procurement decision.

Take it further

Want this guaranteed in your own infrastructure?

Get a copy of these results by email and see RAGSuite running on a setup like yours — citation-backed, self-hosted, EU-ready.

There’s a row with no exposure at all.

Self-hosted, with local models via Ollama, RAGSuite keeps retrieval and generation on your own infrastructure — no vendor, no egress, nothing a foreign authority can reach.