Key facts
| Bahrain context | Built in Bahrain; Arabic-first platform with strong Arabic model support |
| Data plane | GCC region-locked plane (me-central-1, UAE); EU, APAC and US planes also available |
| Deployment models | In-region cloud, private endpoint in your VPC, on-prem, air-gapped |
| Key custody | BYOK via AWS KMS, Azure Key Vault, HashiCorp Vault or on-prem HSM |
| Identity | SAML 2.0 / OIDC SSO and SCIM on Enterprise; workspace/role/resource RBAC |
| Audit | Audit log export to SIEM; logs stored in the selected residency plane |
| Compliance posture | SOC 2 Type II and ISO 27001 readiness in progress (not yet certified); GDPR and PDPL alignment |
| SLA | 99.9% uptime on paid plans; Enterprise 4-hour support SLA — see /legal/sla |
TL;DR
- Residency is an architecture property: choose the data plane, then prove where every store lives.
- Keep keys and identity under your control with BYOK and SSO/SCIM; escrow nothing you cannot revoke.
- Treat Bahrain PDPL obligations as design inputs — lawful basis, rights, retention, breach process.
- Make deletion and export paths concrete for prompts, logs, vectors and backups.
- Document the control map so internal audit and regulators can verify it without vendor interviews.
How it works, step by step
- Classify data types in scope: prompts, completions, embeddings, logs, files, backups.
- Select the GCC residency plane for production and confirm which services are in scope.
- Decide whether shared cloud, private endpoint, on-prem or air-gapped fits each workload.
- Configure SSO/SCIM, role assignments and audit export before onboarding users.
- Set retention and deletion rules per store; test that deletion is complete and evidenced.
- Validate failover behavior to ensure regional boundaries survive an incident.
- Review annually as Bahraini guidance and vendor subprocessors evolve.
Original data
Try it yourself
Open the AI data residency checklist →
Reference architecture for Bahrain residency
A clean design has four layers. Access: users authenticate through your identity provider (SAML 2.0 or OIDC, SCIM for provisioning). Processing: inference and embedding requests terminate in the GCC data plane; nothing routes to an out-of-region endpoint without an explicit, logged exception. Storage: prompts, completions, logs and vectors live in region-locked stores. Control: keys are customer-managed through KMS or HSM, and audit events stream to your SIEM.
Plugsky supports each layer today through its GCC region-locked plane, SSO/SCIM, BYOK and audit export. The remaining work is yours: governance, retention policy and evidence collection.
Bahrain PDPL as a design input
Bahrain's Personal Data Protection Law (Law No. 30 of 2018) shapes how personal data may be processed and transferred. For AI systems that means documenting a lawful basis for processing, supporting data subject access and deletion, defining retention, and having a breach process. Map each obligation to a technical control — for example, deletion requests must reach vector stores and logs, not just the primary database. Confirm your specific obligations with Bahraini counsel; this article is architectural guidance, not legal advice.
Governance operating model
- Name an AI data owner accountable for classification and residency decisions.
- Require architecture review before any workload leaves the selected region.
- Review subprocessors quarterly and track change notifications.
- Keep evidence packs current: region maps, control descriptions, audit samples, DPA.
- Run an annual restore-and-delete drill to prove the full lifecycle.
Common pitfalls
Three failures recur. First, a global endpoint that technically serves the region but stores logs elsewhere. Second, BYOK that is configured but never tested by revoking a key. Third, a pilot that leaves test data in a shared workspace after production moves to a private plane. Treat each as a control failure and schedule verification, not just configuration.
Honest comparison
| Capability | Plugsky | Hyperscaler AI platform | Building in-house |
|---|---|---|---|
| Regional processing | GCC plane plus EU, APAC, US planes | Region selection per service | Wherever you host |
| Deployment range | Cloud, VPC, on-prem, air-gapped | Mostly shared cloud, some dedicated | You own everything |
| Arabic capability | Arabic-first platform and multilingual embeddings | Model-dependent | Model-dependent |
| Key custody | BYOK via KMS or HSM | Cloud KMS and HSM services | You operate the HSM |
| Audit evidence | SIEM export and region-locked logs | Native cloud audit | Custom pipelines |
| Certifications | SOC 2 / ISO 27001 readiness in progress | Completed audits in many regions | Your own audit burden |
Frequently asked questions
Does Plugsky have a Bahrain data centre?
Plugsky was built in Bahrain and offers a GCC region-locked data plane. Confirm the exact facility and service mapping with the enterprise team before committing to a specific location claim.
Which Bahrain law applies to AI processing?
The Personal Data Protection Law (Law No. 30 of 2018) is the baseline. Sector rules may add obligations. Validate your specific case with Bahraini counsel.
Can data leave Bahrain for failover?
Failover must respect your residency commitments. Ask for the failover design in writing and test it; region-locked planes are intended to keep traffic in-region.
How do we prove residency to a regulator?
Combine contractual commitments, architecture diagrams, region configuration exports, and audit logs showing request routing. Evidence beats assurances.
Is on-prem deployment available for the strictest workloads?
Yes — on-prem and air-gapped deployments run open-weight models behind your firewall with the same OpenAI-compatible API.
What licenses do we need for on-prem models?
Open-weight models avoid proprietary runtime licensing. Review each model's licence terms for your commercial context before deployment.
How does pricing work for enterprise deployments?
Deployment and support terms are quoted per engagement. See the live pricing page for self-serve plans and contact the enterprise team for private deployments.