Infrastructure & Sub-Processors
Streamdiver runs on dedicated infrastructure from three European hosting providers. This page names them, states what each one is certified for, and links to every certificate at its source so your security team can verify it independently.
Each certificate on this page belongs to the hosting provider named with it and covers that provider's information security management system and data centers. Streamdiver operates its own ISMS on top, aligned with ISO/IEC 27001:2022. The platform-level controls are documented in Cryptography & Data Protection and made contractually binding through our Data Processing Agreement.
Hosting providers
| Provider | Legal entity | Data location | Provider jurisdiction |
|---|---|---|---|
| Hetzner | Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen | Germany | Germany (EU) |
| Exoscale | Akenes S.A., Boulevard de Grancy 19a, 1006 Lausanne | Austria | Switzerland (EU adequacy decision under Art. 45 GDPR) |
| Verda | Verda Cloud Oy | Finland | Finland (EU) |
All three are European companies with no US ownership — the basis for the CLOUD Act assessment in LLM Infrastructure. Customer data is processed and stored only in Austria, Germany, and Finland; see Data Privacy for the breakdown by data category.
Switzerland is not an EU or EEA member. It is covered by a European Commission adequacy decision, so transfers to a Swiss controller or processor require no additional safeguards under Art. 46 GDPR. In practice this is a question of vendor domicile only: no Streamdiver customer data is stored in Switzerland.
Certifications
Hetzner Online GmbH
| Standard | ISO/IEC 27001:2022 |
| Certification body | SOCOTEC Certification Deutschland GmbH, accredited by DAkkS (D-ZM-18855-01-00) |
| Certificate number | ZN-2025-35 |
| Validity | 27 September 2025 – 26 September 2028 |
| Certified scope | All hosting services and the data centers. Locations named on the certificate: Nuremberg and Falkenstein/Vogtland (Germany), Tuusula (Finland) |
| Verify | ISO/IEC 27001:2022 certificate (PDF) · Hetzner certification page |
Hetzner additionally holds a BSI C5 Type 2 attestation. Both documents are published on Hetzner's certificate overview.
Verda Cloud Oy
| Standard | ISO/IEC 27001:2022 |
| Certification body | KPMG IT Certification Ltd, accredited by FINAS (S045, EN ISO/IEC 17021-1) |
| Certificate number | FI260123-224 |
| Validity | 23 January 2026 – 23 January 2029 (first issued 22 January 2022) |
| Certified scope | ISMS covering the provision, development, operation and maintenance of the Verda cloud platform and the supporting infrastructure used to deliver bare-metal and virtual machine services |
| Verify | Verda Trust Center · ISO/IEC 27001:2022 certificate |
Verda's Trust Center also lists ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701 and a SOC 2 Type II report. Those documents are published there separately and are not covered by the ISO/IEC 27001 certificate above.
Exoscale (Akenes S.A.)
| Standards | ISO/IEC 27001:2022 and ISO/IEC 27018:2019, certified in one document |
| Certification body | TÜV AUSTRIA GMBH, Vienna, accredited by Akkreditierung Austria (0944, ISO/IEC 17021-1) |
| Registration numbers | 10201250012843, 10207250012879 |
| Validity | until 10 January 2028 (first certified 11 January 2019) |
| Certified scope | Cloud – Hosting |
| Verify | Exoscale Compliance Center · ISO/IEC 27001 compliance page |
Exoscale releases the certificate document through its Compliance Center rather than as a public download. The certificate carries TÜV AUSTRIA's reproduction terms, so we link to the source instead of mirroring the file. Exoscale additionally holds ISO/IEC 27017, BSI C5, SOC 2 Type II, CSA STAR, HDS and TISAX attestations, each documented on its own page in the Compliance Center.
Sub-processors
Our hosting providers are sub-processors within the meaning of Art. 28 GDPR. How they are disclosed and changed is governed by our Data Processing Agreement (AVV), Sections 7 and 8:
- Disclosure before you sign. We inform you of the identity and role of every sub-processor before the contract is concluded.
- Advance notice of changes. Planned additions or replacements are announced in advance by email or inside the Cloud Service, including the new sub-processor's name, address and role.
- A right to object. You may object within 30 days on legitimate data protection grounds. If we engage the sub-processor despite your objection, you may terminate the affected part of the service.
- Emergency replacement. A sub-processor may be replaced without prior notice where security or other urgent reasons require it; you are informed immediately afterwards.
- Europe only. We engage sub-processors established in the European Union or Switzerland. No personal data is transferred to sub-processors based in the United States without your explicit consent.
Sub-processors are contractually bound to the same geographic restrictions described under Data Residency.
Documentation
| Document | Where |
|---|---|
| Data Processing Agreement (AVV), including technical and organizational measures in Annex 1 | streamdiver.com/legal |
| General terms and terms of use | streamdiver.com/legal |
| Cryptography and data protection | Cryptography & Data Protection |
| LLM infrastructure and CLOUD Act assessment | LLM Infrastructure |
| Provider ISO/IEC 27001 certificates | Certifications |
| Completed security questionnaires (e.g. CAIQ, SIG-Lite) | On request |
If a procurement process requires the provider certificates as attachments rather than links, contact us and we will assemble what we are permitted to share.
Provider certification details last verified: 11 September 2026.
For questions about our infrastructure or to request documentation, contact us.