Skip to content

Privatemode

Edgeless Systems GmbH (Amtsgericht Bochum HRB 18566, Stadionring 1, 44791 Bochum, Germany); founder-controlled, no parent company

Sovereign AI · Germany
Founded 2020 · privatemode.ai

Confidential AI chat and OpenAI-compatible API from Bochum: open models run in attested, memory-encrypted GPU enclaves on Scaleway and Lyceum in the EU, with prompts unreadable to the operator.

Privatemode is a European service hosted in France, with at most minor, transient US exposure under the CLOUD Act. It is listed under Sovereign AI.

Assessment notes

Privatemode is the confidential-computing AI service of Edgeless Systems GmbH (HRB 18566, Amtsgericht Bochum, founded 2020), and the content path is as strong as anything in this category: prompts are encrypted on the client, decrypted only inside remotely attested confidential VMs with NVIDIA H100/B200 GPUs in confidential-computing mode, held in encrypted memory, never stored and, per the vendor, never used for training. The public DPA (updated 24 July 2026, accepted with the terms) names only two sub-processors, Scaleway SAS (France, Iliad group) and Lyceum Technology Germany GmbH (Berlin, founder-majority with Swiss/Luxembourg and German VC), both EU-owned, and the API was observed answering from a Scaleway server in Paris. The company is founder-controlled (about 61% held by the two founders per the August 2024 shareholder list; US-domiciled investors under 3% combined) and holds ISO 27001 for its own entity. The score is held at 3 by the account layer around that path: sign-in runs on Clerk (US), the portal backend on Google Cloud Run (europe-west1, Belgium), payments on Stripe, and the hosted chat app, portal and docs are served through Cloudflare, which the vendor's own documentation lists as part of the hosted web app's trusted computing base. None of these appear in the DPA's sub-processor list, and the privacy policy covers only the marketing website (Google Analytics, PostHog, HubSpot). They touch account, identity, billing and code-delivery data, not prompt content, which is why CLOUD Act exposure is minor rather than material, but they are three or more undisclosed US-owned processors, which is the rubric's 3/5 line. The C5:2026 statement on the homepage is the vendor's own reading of criterion OPS-33, not a C5 attestation.

Findings

CLOUD Act
Ownership
Sub-processors
0 none disclosed

Verified signals

Jurisdiction
  • EU / adequacy hosting: Yes
  • EU / adequacy operator: Yes
  • No US CLOUD Act exposure: Not assessed
Transparency
  • Public DPA: Yes
  • Sub-processors disclosed: Yes
  • Open-source clients: Yes
  • Third-party certification: Yes
CLOUD Act by deployment

Exposure depends on how you run this product.

Hosted SaaS (default)

Vendor-operated: the sub-processors below apply.

Self-hosted (open-source)

Deploy on your own EU infrastructure and you control hosting and every sub-processor.

Jump to

About Privatemode

Privatemode is a confidential AI service from Edgeless Systems GmbH in Bochum, a confidential-computing specialist founded in 2020 by Felix Schuster and Thomas Tendyck. It offers a browser chat app and an OpenAI-compatible API, which also accepts the Anthropic Messages format so coding tools such as Claude Code can point at it. The models are open-weight: GLM-5.3 and GLM-5.3-Flash from Z.ai, OpenAI's gpt-oss-120b, DeepSeek-OCR-2, Qwen3-Embedding 4B, and Mistral's Voxtral Mini 3B plus Whisper large-v3 for transcription. Pricing is usage-based in euros excluding VAT: gpt-oss-120b and GLM-5.3-Flash cost €0.20 per million input and €0.65 per million output tokens, GLM-5.3 €1.55 and €5.74, speech-to-text from €0.004 per audio minute. The free tier gives 5 million tokens on sign-up and 1 million a month without a card; Enterprise adds SSO, SLAs, custom models and optional per-seat pricing.

The difference is technical rather than contractual. Before sending anything, the client proxy, SDK or web app checks an attestation report signed by the AMD or Intel CPUs and NVIDIA H100 or B200 GPUs against reference values that can be reproduced from the published source code. Only then is the prompt encrypted with a key that the attested AI worker alone receives. Processing happens in confidential VMs whose memory stays encrypted; prompts are not stored after the request and, according to the vendor, never used for training. The public DPA names two infrastructure sub-processors, Scaleway (France) and Lyceum Technology (Berlin), both EU-owned, and at audit the API answered from a Scaleway server in France. Until spring 2025 the documentation said the service ran in many cases on Microsoft Azure. Metadata such as IP address, API key and token counts is kept for up to 90 days.

Edgeless Systems is controlled by its founders, who held about 61 per cent at the last register filing; SquareOne, SIX Group and German angel vehicles hold most of the rest, and US-based investors under 3 per cent combined. Ownership is recorded as EU-owned, and the company holds ISO 27001. CLOUD Act exposure is recorded as Minor because the account layer uses US-owned services that the DPA does not list: Clerk for sign-in, Google Cloud Run for the portal backend, Stripe for payments, and Cloudflare in front of the chat app, portal and docs. The vendor's documentation counts Cloudflare as part of the hosted web app's trusted computing base; self-hosting the MIT-licensed web app removes it. Best fit: regulated teams that want cloud AI on sensitive data with verifiable operator exclusion and can work with open models. If a closed model such as GPT or Claude is a requirement, the vendor itself says Privatemode is not the answer.

Sub-processor map · none disclosed

Source
Vendor discloses zero sub-processors. All data processing happens in-house.

Frameworks & certifications

ISO/IEC 27001
Active
Certifications of the infrastructure it runs on

Held by the provider that operates the hosting, not by Privatemode itself.

ISO/IEC 27001 HDS

Capability matrix

Table 1Capabilities of Privatemode

Self-hostable Yes
API access Yes
Chat assistant Yes
Open-weight models No
Fine-tuning No
Multimodal Yes
Function calling Yes
RAG Yes

Integration & access

REST API Yes
SSO (SAML / OIDC) Yes

Compliance & governance

Audit log No
Self-host / on-prem option Yes

Pricing & tiers

Custom pricing

Contact vendor for tier or volume pricing.

View pricing page

Public documents

  • Data Processing Addendum (DPA)
    www.privatemode.ai/dpa…
    Open
  • Sub-processors list
    www.privatemode.ai/dpa…
    Open
  • Terms of Service
    www.privatemode.ai/terms-of-service…
    Open

Alternatives in this category

  • Germany
    EU-Hosted
    Public DPA: No Sub-processors: No Open source: No
  • EU-Hosted
    Public DPA: No Sub-processors: No Open source: Yes
  • Germany · €7.49/mo
    EU-Hosted
    Public DPA: Not assessed Sub-processors: No Open source: No