Every field is source-linked and dated.See the rubric behind the grades.

How we grade
Sovereign AI Registry
ExploreBlogGov accessCertsCountries

Footer

Sovereign AI Registry

The compliance registry for AI vendors. Data residency, training defaults, retention, subprocessors and EU AI Act posture — one row per vendor, product and deployment, every claim linked to its source.

Registry

  • Explore vendors
  • Deployment models
  • Categories
  • Countries

Compliance

  • Gov access exposure
  • EU AI Act roles
  • Certifications

Resources

  • FAQ
  • Methodology
Built with ShipMore·Build yours →

© 2026 Sovereign AI Registry. All rights reserved.

  1. Explore
  2. Duo Self-Hosted
DS

Duo Self-Hosted

Sovereignty grade A (96/100). You control where it runs; no training on your data; self-hosted weights. GitLab, United States.

Category
coding-assistant
Categories
Coding assistant
EU AI Act role
Deployer
Certifications
ISO 27001ISO 27017ISO 27018SOC 2 Type II
Government access exposure
No non-EU government access
Deployments
Self-hosted weights
Countries
United States

Details

Deployment
self-hosted-weights
Hq Country
United States
Hq City
San Francisco
Ownership
public
Founded
2014
Trust Center Url
about.gitlab.com/security
Training Default
never
Residency Options
the customer's own network, fully isolated / offline networks with an offline licence
Gov Access Exposure
none-eu
Eu Ai Act Role
deployer
Certs
ISO 27001, ISO 27017, ISO 27018, SOC 2 Type II, CSA Trusted Cloud Provider
DPA available
yes
Zero Retention Available
Yes
Self Host Option
Yes
Retention Default
"Inference data, including code inputs, model prompts, and model responses, does not leave the customer network." GitLab does not train generative AI models, and its model sub-processors are contractually barred from training on input or output.
Retention Exceptions
With an online licence, a JSON billing record leaves the network: instance ID, a SHA-256 de-identified GlobalUserId, a call count and a timestamp — no prompts. With an offline licence the instance does not connect to GitLab's billing components at all. This row grades the fully self-hosted configuration; the GitLab.com AI Gateway path routes to Anthropic, Fireworks AI and Google Vertex and is a different product shape.
Subprocessors
none in the inference path when the AI Gateway and the models are self-hosted — GitLab's published list (Google LLC, AWS, Zendesk, Fireworks AI) applies to the GitLab-managed gateway
Subprocessor Count
0
Transfer Mechanism
intra-eu
Eu Procurement Ready
pass
Eu Procurement Reason
The clearest example in this batch of a US vendor selling a genuinely sovereign configuration, and it does it by getting out of the way. Run your own AI Gateway and your own models — vLLM on your metal, or Bedrock and Azure OpenAI behind your gateway — and GitLab's documentation commits in plain words that code inputs, prompts and responses do not leave the customer network. An offline licence removes even the billing callback. Everything else is unusually well disclosed for this category: a complete sub-processor table, ISO 27001:2022 with 27017 and 27018, SOC 2 Type 2, and an explicit statement that model sub-processors are barred from training. The caveat is that all of this belongs to the self-hosted configuration and a Premium or Ultimate tier plus the Duo add-on; the default GitLab.com gateway sends prompts to Anthropic, Fireworks and Google Vertex in the US and would score like the rest of the hosted field.
Training Evidence Url
docs.gitlab.com/user/gitlab_duo/data_usage
Training Claim Basis
stated
Training Confidence
high
Residency Evidence Url
docs.gitlab.com/administration/gitlab_duo_self_hosted
Residency Claim Basis
stated
Residency Confidence
high
Retention Evidence Url
docs.gitlab.com/user/gitlab_duo/data_usage
Retention Claim Basis
stated
Retention Confidence
high
Subprocessors Evidence Url
about.gitlab.com/privacy/subprocessors
Subprocessors Claim Basis
stated
Subprocessors Confidence
high
Residency Class
customer-controlled
Portability / Exit Path
serves-open-models
Subprocessor Jurisdiction
structurally-none
Underlying model providers
customer-selected — vLLM, AWS Bedrock or Azure OpenAI behind a self-hosted AI Gateway
At a glance
Governance Grade
A
Governance Score
96
EC SOV-2 Legal & Jurisdictional (0-4)
3
EC SOV-3 Data & AI (0-4)
3
Website

Similar

Read AI · Sep 2026

RARead AI meeting assistant

Sovereignty grade F (24/100). No EU residency. Read AI, United States.

meeting-ai
Governance Grade
F
Fathom · Aug 2026

FAFathom AI notetaker

Sovereignty grade D (35/100). No EU residency. Fathom, United States.

meeting-ai
Governance Grade
D
Granola · Sep 2026

GAGranola AI notepad

Sovereignty grade D (30/100). No EU residency. Granola, United States.

meeting-ai
Governance Grade
D

More Categories

  • Coding assistant15
  • meeting-ai13
  • Sovereign host13
  • Inference host13
  • SaaS-embedded11
  • Foundation model11
  • Cloud platform7

More EU AI Act role

  • Deployer59
  • General-purpose AI (GPAI)10
  • provider9
  • GPAI with systemic risk5

More Certifications

  • SOC 2 Type II46
  • ISO 2700136
  • ISO 4200113
  • ISO 270177
  • ISO 277017
  • ISO 270186
  • HDS5
  • HIPAA4
  • CSA STAR4
  • C54
  • ISO 90013
  • PCI DSS3
  • FedRAMP High3
  • ISO 27001:20223
  • SOC 2 (type unverified)2
  • ISO 500012
  • BSI C52
  • SOC 32
  • FedRAMP2
  • GDPR2
  • CSA STAR Level 12

More Government access exposure

  • US CLOUD Act44
  • No non-EU government access27
  • Mixed jurisdiction9
  • PRC National Intelligence Law2

More Deployments

  • Hosted API68
  • Self-hosted weights6
  • On-premise6
  • Private VPC2

More Countries

  • United States45
  • Germany9
  • France7
  • Switzerland5
  • Singapore3
  • Israel2
  • United Kingdom2
  • China2
  • Netherlands2