Every field is source-linked and dated.See the rubric behind the grades.

How we grade
Sovereign AI Registry
ExploreBlogGov accessCertsCountries

Footer

Sovereign AI Registry

The compliance registry for AI vendors. Data residency, training defaults, retention, subprocessors and EU AI Act posture — one row per vendor, product and deployment, every claim linked to its source.

Registry

  • Explore vendors
  • Deployment models
  • Categories
  • Countries

Compliance

  • Gov access exposure
  • EU AI Act roles
  • Certifications

Resources

  • FAQ
  • Methodology
Built with ShipMore·Build yours →

© 2026 Sovereign AI Registry. All rights reserved.

  1. Explore
  2. Amp
A

Amp

Sovereignty grade C (49/100). No EU residency; no training on your data. Sourcegraph, United States.

Category
coding-assistant
Categories
Coding assistant
EU AI Act role
Deployer
Deployments
Hosted API
Certifications
SOC 2 Type II
Government access exposure
US CLOUD Act
Countries
United States

Details

Deployment
hosted
Hq Country
United States
Hq City
San Francisco
Ownership
private
Founded
2013
Trust Center Url
ampcode.com/security
Training Default
never
Residency Options
multi-tenant Google Cloud Platform project; no EU region is published
Gov Access Exposure
us-cloud-act
Eu Ai Act Role
deployer
Certs
SOC 2 Type II
DPA available
yes
Zero Retention Available
Yes
Retention Default
Minimal Data Retention is available to all Amp users, not only Enterprise: for inference through Amp-managed model provider connections on Amp credits, Amp's agreements with major model providers limit retention to narrow safety, abuse and legal exceptions, and availability and exceptions vary by model and feature. Customers needing specific retention terms are directed to Amp Enterprise or to bring their own model provider key (BYOK), in which case the provider account's terms apply. Thread data is removed within 30 days of thread deletion; threads owned by an Enterprise workspace are kept until the enterprise's contract ends.
Retention Exceptions
ZDR has two documented exceptions: content flagged by a provider's abuse classifiers may be retained in that provider's abuse-monitoring systems, and some models require extended prompt caching, where key/value tensors derived from prompts sit in provider infrastructure for a limited period. Enterprise workspace threads are owned by the enterprise and survive a user deleting their account; they are deleted when the contract ends. Deleted threads clear within 30 days.
Subprocessors
Anthropic — USA, OpenAI — USA, Google (Cloud and LLM) — USA, Fireworks AI — USA, Cloudflare — USA, Observe — USA
Subprocessor Count
6
Transfer Mechanism
sccs
Eu Procurement Ready
conditional
Eu Procurement Reason
Amp documents its data handling better than most of this batch and then puts all of it in the United States. The security page is specific in the way procurement wants — zero data retention on Enterprise with both exceptions named rather than hidden, training that can never be switched on for an Enterprise workspace, thread-deletion semantics spelled out for three different workspace types, SOC 2 Type II, a complete sub-processor table — and every entry in that table says USA. The Amp Server runs in a multi-tenant Google Cloud project with no published EU region, so an EU buyer gets contractual protection under SCCs and no data-residency story at all. The one lever that changes this is the customer-managed model provider connection: bring your own API key and inference falls under your contract with that provider, which is also why this row scores above the closed assistants on exit cost.
Training Evidence Url
ampcode.com/security
Training Claim Basis
stated
Training Confidence
high
Residency Evidence Url
ampcode.com/security
Residency Claim Basis
stated
Residency Confidence
high
Retention Evidence Url
ampcode.com/security
Retention Claim Basis
stated
Retention Confidence
medium
Subprocessors Evidence Url
sourcegraph.com/terms/subprocessors
Subprocessors Claim Basis
stated
Subprocessors Confidence
high
Residency Class
non-eu-only
Portability / Exit Path
open-api-standard
Subprocessor Jurisdiction
non-eu
Underlying model providers
Anthropic (US), OpenAI (US), Google (US), Fireworks AI (US), customer-managed model provider connections

Change history

  1. Sep 12, 2026Retention Default

    "Neither Amp nor our subprocessors train models on your data, unless you have explicitly opted into training." On an Amp Enterprise workspace training can never be enabled at all. Enterprise also carries zero data retention: LLMs retain prompts and responses only as long as needed to generate a response. → Minimal Data Retention is available to all Amp users, not only Enterprise: for inference through Amp-managed model provider connections on Amp credits, Amp's agreements with major model providers limit retention to narrow safety, abuse and legal exceptions, and availability and exceptions vary by model and feature. Customers needing specific retention terms are directed to Amp Enterprise or to bring their own model provider key (BYOK), in which case the provider account's terms apply. Thread data is removed within 30 days of thread deletion; threads owned by an Enterprise workspace are kept until the enterprise's contract ends.

    Source
At a glance
Governance Grade
C
Governance Score
48
EC SOV-2 Legal & Jurisdictional (0-4)
1
EC SOV-3 Data & AI (0-4)
1
Website

Similar

Read AI · Sep 2026

RARead AI meeting assistant

Sovereignty grade F (24/100). No EU residency. Read AI, United States.

meeting-ai
Governance Grade
F
Fathom · Aug 2026

FAFathom AI notetaker

Sovereignty grade D (35/100). No EU residency. Fathom, United States.

meeting-ai
Governance Grade
D
Granola · Sep 2026

GAGranola AI notepad

Sovereignty grade D (30/100). No EU residency. Granola, United States.

meeting-ai
Governance Grade
D

More Categories

  • Coding assistant15
  • meeting-ai13
  • Sovereign host13
  • Inference host13
  • SaaS-embedded11
  • Foundation model11
  • Cloud platform7

More EU AI Act role

  • Deployer59
  • General-purpose AI (GPAI)10
  • provider9
  • GPAI with systemic risk5

More Deployments

  • Hosted API68
  • Self-hosted weights6
  • On-premise6
  • Private VPC2

More Certifications

  • SOC 2 Type II46
  • ISO 2700136
  • ISO 4200113
  • ISO 270177
  • ISO 277017
  • ISO 270186
  • HDS5
  • HIPAA4
  • CSA STAR4
  • C54
  • ISO 90013
  • PCI DSS3
  • FedRAMP High3
  • ISO 27001:20223
  • SOC 2 (type unverified)2
  • ISO 500012
  • BSI C52
  • SOC 32
  • FedRAMP2
  • GDPR2
  • CSA STAR Level 12

More Government access exposure

  • US CLOUD Act44
  • No non-EU government access27
  • Mixed jurisdiction9
  • PRC National Intelligence Law2

More Countries

  • United States45
  • Germany9
  • France7
  • Switzerland5
  • Singapore3
  • Israel2
  • United Kingdom2
  • China2
  • Netherlands2