FAQ + Objections

Can Plugsky keep data in the GCC?

Yes — GCC residency is a supported deployment option. Plugsky offers region selection on the shared cloud and dedicated deployments (VPC, on-prem, air-gapped) that keep prompts and data inside a GCC jurisdiction. Confirm the model-by-region matrix and sign the DPA before you commit regulated workloads.

Key facts

Residency optionsRegion selection plus dedicated and sovereign deployments
GCC coverageRegion guides cover UAE, Saudi Arabia, Qatar, Bahrain, Kuwait and Oman
Deployment modelsPlugsky cloud region, your VPC, on-prem, air-gapped
Data in transitTLS on all API traffic
Sub-processorsDisclosed in the DPA and legal terms
Model availabilityVaries by region and model — confirm the matrix
Free tier2 free AI models (plugsky-micro, plugsky-lite), no card
Product statusLive

TL;DR

  • Residency is a deployment choice, not a promise in the fine print.
  • Dedicated deployments keep data inside your chosen jurisdiction.
  • Model availability can differ by region — validate your shortlist first.
  • Get the DPA, sub-processor list and audit evidence before procurement signs.
  • Self-serve gives a fast start; regulated workloads usually end in a dedicated deployment.

How it works, step by step

  1. Classify your data and note which categories must remain in-country.
  2. Pick the jurisdiction and review the matching Plugsky region guide.
  3. Confirm that your required models are available in that region and deployment model.
  4. Request the DPA, sub-processor list and residency evidence for legal review.
  5. Prototype on the free plan with two models, then validate on the full-access trial.
  6. Scope the production deployment (shared region, VPC, on-prem or air-gapped) with the team.
1Classify your dataand note whichcategories must2Pick thejurisdiction andreview the matching3Confirm that yourrequired models areavailable in that4Request the DPA,sub-processor listand residency5Prototype on thefree plan with twomodels, then6Scope theproductiondeployment (shared

Try it yourself

Open the data residency checker →

What 'data residency' actually covers

Residency is broader than where a database sits. For an AI API, check at least four layers: where prompts and completions are processed, where logs and usage metadata are stored, where backups and disaster-recovery copies live, and which sub-processors can touch any of it. A credible answer names each layer and the controls around it. Plugsky's region guides walk through these layers per GCC market, and the DPA documents sub-processors and handling obligations in writing. Ask providers to state the retention period for each layer, not just the location — retention and location together define your exposure.

Which deployment fits which requirement

Match the requirement to the model:

  • Shared cloud region: fastest start, cost-efficient, suitable when policy allows a managed multi-tenant service in-country.
  • VPC: the gateway and model serving run inside your cloud boundary, with private networking and restricted egress.
  • On-prem: your data centre, your hardware, your controls — used by banks, government and critical infrastructure.
  • Air-gapped: no internet path at all, for the strictest sovereignty rules.

Most GCC enterprises start on the shared region for prototyping and move regulated production workloads to a dedicated deployment once the model matrix and DPA are confirmed.

What we do and what we do not do

What we do: offer region selection, dedicated and sovereign deployment paths, publish a DPA and SLA, and document sub-processors. What we do not do: guarantee that every model is available in every region — catalogues differ, so validate your shortlist — or treat residency as implicit. If residency is a hard requirement, make it a contractual commitment in the agreement rather than relying on default routing, and review the SLA alongside the residency terms.

Honest comparison

CapabilityPlugsky GCC regionPlugsky dedicated (VPC/on-prem)Global hosted API
Processing locationSelected GCC regionYour boundary, in-countryProvider-selected regions
Logs and metadataRegion-scoped controlsInside your boundaryProvider-controlled
Sub-processor controlDocumented in DPAMinimal, you approveProvider list
Model availabilityRegion matrix appliesOpen-weight catalogue in-boundaryLargest catalogue
Operational burdenLowModerate to highLowest
Best fitMost GCC workloadsRegulated and sovereignNon-residency-bound teams

Frequently asked questions

Which GCC countries can data stay in?

Plugsky publishes region guidance for the UAE, Saudi Arabia, Qatar, Bahrain, Kuwait and Oman. Confirm the specific region and deployment model for your workload during scoping.

Is in-country processing guaranteed by default?

No. Residency is a deployment and contractual choice — select the region or dedicated deployment you need and have it written into the agreement.

Are all models available in every GCC region?

Not necessarily. Model availability can differ by region and deployment model, so validate your shortlist against the current matrix before committing.

What evidence can legal and procurement review?

The DPA, sub-processor list, SLA and residency documentation. The GCC region guides summarise the architecture and governance questions to ask.

Can we run without any cross-border traffic?

Yes — on-prem and air-gapped deployments keep processing, storage and keys inside your environment with no external path.

Does the free plan keep data in the GCC?

The free plan runs on the shared managed cloud under standard terms. For contractual residency, move to a region-specific or dedicated deployment.

How long does a GCC deployment take to scope?

Timelines depend on the deployment model and procurement process. Start the conversation with the model matrix and DPA review so security and legal can run in parallel.