Every field is source-linked and dated.See the rubric behind the grades.

How we grade
Sovereign AI Registry
ExploreBlogGov accessCertsCountries

Footer

Sovereign AI Registry

The compliance registry for AI vendors. Data residency, training defaults, retention, subprocessors and EU AI Act posture — one row per vendor, product and deployment, every claim linked to its source.

Registry

  • Explore vendors
  • Deployment models
  • Categories
  • Countries

Compliance

  • Gov access exposure
  • EU AI Act roles
  • Certifications

Resources

  • FAQ
  • Methodology
Built with ShipMore·Build yours →

© 2026 Sovereign AI Registry. All rights reserved.

  1. Explore
  2. GroqCloud
G

GroqCloud

Sovereignty grade C (52/100). No EU residency; no training on your data. Groq, United States.

Category
inference-host
EU AI Act role
Deployer
Deployments
Hosted API
Categories
Inference host
Certifications
SOC 2 Type II
Government access exposure
US CLOUD Act
Countries
United States

Details

Deployment
hosted
Hq Country
United States
Hq City
Mountain View
Ownership
private
Founded
2016
Trust Center Url
trust.groq.com
Training Default
never
Residency Options
global fleet (US, Canada, Finland, Saudi Arabia), no customer-selectable residency published
Gov Access Exposure
us-cloud-act
Eu Ai Act Role
deployer
Certs
SOC 2 Type II
DPA available
yes
Zero Retention Available
Yes
Retention Default
Groq does not access, use, store or retain Inputs or Outputs except as necessary to provide the service, ensure reliable operation, or confirm AUP compliance.
Retention Exceptions
Zero Data Retention is self-serve for every customer — an org admin enables it in Console Data Controls, globally or per feature — which removes the reliability and abuse-monitoring exception.
Subprocessors
Stytch, Google Cloud Platform, Stripe, Oracle NetSuite
Subprocessor Count
4
Transfer Mechanism
sccs
Eu Procurement Ready
conditional
Eu Procurement Reason
Contractually strong: the services agreement states Groq is not permitted to use Inputs or Outputs for training or fine-tuning, ZDR is self-serve rather than an enterprise upsell, and the DPA incorporates the 2021 EU SCCs with Groq UK Limited as the contracting entity for EEA and Swiss customers. Groq operates a Helsinki data centre but publishes no customer-selectable data residency, so EU processing cannot be guaranteed.
Training Evidence Url
console.groq.com/docs/legal/services-agreement
Training Claim Basis
stated
Training Confidence
high
Residency Evidence Url
console.groq.com/docs/legal/services-agreement
Residency Claim Basis
inferred
Residency Confidence
medium
Retention Evidence Url
console.groq.com/docs/legal/services-agreement
Retention Claim Basis
stated
Retention Confidence
high
Subprocessors Evidence Url
trust.groq.com
Subprocessors Claim Basis
stated
Subprocessors Confidence
high
Residency Class
non-eu-only
Portability / Exit Path
serves-open-models
Subprocessor Jurisdiction
non-eu
Underlying model providers
Meta (Llama), OpenAI (gpt-oss), Qwen, Moonshot AI (Kimi), Groq (Whisper hosting)
At a glance
Governance Grade
C
Governance Score
52
EC SOV-2 Legal & Jurisdictional (0-4)
1
EC SOV-3 Data & AI (0-4)
1
Website

Similar

Read AI · Sep 2026

RARead AI meeting assistant

Sovereignty grade F (24/100). No EU residency. Read AI, United States.

meeting-ai
Governance Grade
F
Fathom · Aug 2026

FAFathom AI notetaker

Sovereignty grade D (35/100). No EU residency. Fathom, United States.

meeting-ai
Governance Grade
D
Granola · Sep 2026

GAGranola AI notepad

Sovereignty grade D (30/100). No EU residency. Granola, United States.

meeting-ai
Governance Grade
D

More EU AI Act role

  • Deployer59
  • General-purpose AI (GPAI)10
  • provider9
  • GPAI with systemic risk5

More Deployments

  • Hosted API68
  • Self-hosted weights6
  • On-premise6
  • Private VPC2

More Categories

  • Coding assistant15
  • meeting-ai13
  • Sovereign host13
  • Inference host13
  • SaaS-embedded11
  • Foundation model11
  • Cloud platform7

More Certifications

  • SOC 2 Type II46
  • ISO 2700136
  • ISO 4200113
  • ISO 270177
  • ISO 277017
  • ISO 270186
  • HDS5
  • HIPAA4
  • CSA STAR4
  • C54
  • ISO 90013
  • PCI DSS3
  • FedRAMP High3
  • ISO 27001:20223
  • SOC 2 (type unverified)2
  • ISO 500012
  • BSI C52
  • SOC 32
  • FedRAMP2
  • GDPR2
  • CSA STAR Level 12

More Government access exposure

  • US CLOUD Act44
  • No non-EU government access27
  • Mixed jurisdiction9
  • PRC National Intelligence Law2

More Countries

  • United States45
  • Germany9
  • France7
  • Switzerland5
  • Singapore3
  • Israel2
  • United Kingdom2
  • China2
  • Netherlands2