Enterprise + Sovereign AI

How do you keep AI data inside the GCC?

Keeping AI data in the GCC means pinning inference, storage, logs and backups to an in-region deployment, constraining failover and support access to the same jurisdiction, and evidencing it with configuration exports and subprocessor locations. Plugsky offers GCC region pinning — including the UAE default and a Riyadh region on Enterprise — plus VPC, on-prem and air-gapped tiers for stricter requirements.

Key facts

GCC regionsme-central-1 (UAE) default GCC region; sa-central-1 (Riyadh) on Enterprise
PinningRegion selected per workspace; data stays in the pinned region
Deployment tiersCloud, VPC, on-prem and air-gapped for stricter requirements
Key custodyBYOK via cloud KMS or HSM; customer-controlled revocation
SubprocessorsPublished list with change notification and locations
AuditPer-request logs and audit export with region attribution
Contractual frameTerms at /legal/terms and service commitments at /legal/sla
Compliance postureSOC 2 Type II and ISO 27001 readiness in progress (not yet certified)

TL;DR

  • Pinning is a configuration decision — verify it, do not assume it.
  • Failover and support access are the usual sources of accidental export.
  • Choose the lightest deployment tier that satisfies the strictest regime.
  • Collect evidence: region maps, config exports and subprocessor locations.
  • Align UAE, Saudi and sector rules separately — they are not identical.

How it works, step by step

  1. List the data classes and the GCC regimes that apply to each workload.
  2. Select the GCC region per workspace and export the configuration as evidence.
  3. Decide the permitted failover behaviour and test it before go-live.
  4. Confirm where logs, backups and vector stores live, not just inference.
  5. Review the subprocessor list and where each provider processes data.
  6. Choose key custody — provider, BYOK or HSM — and document revocation authority.
  7. Rehearse an incident and a deletion request so the evidence trail is complete.
1List the dataclasses and the GCCregimes that apply2Select the GCCregion perworkspace and3Decide thepermitted failoverbehaviour and test4Confirm where logs,backups and vectorstores live, not5Review thesubprocessor listand where each6Choose key custody— provider, BYOK orHSM — and document

Try it yourself

Open the AI data residency checklist →

What "keeping data in the GCC" actually requires

Residency is not a single setting. Six stores need a location decision:

  • Inference: where prompts and completions are processed.
  • Prompt and response logs: often the largest uncontrolled copy.
  • Embeddings and vector indexes: derived data that mirrors your documents.
  • Backups and disaster recovery: a common accidental export path.
  • Support access: engineers viewing data from outside the jurisdiction.
  • Metadata and billing records: may contain identifiers even when content does not.

Map each store, then pin the region and verify with a configuration export rather than assuming the default.

UAE, Saudi and the wider GCC

The regimes differ and evolve. The UAE has federal PDPL plus free-zone regimes such as DIFC and ADGM; Saudi Arabia applies PDPL with sector guidance from SDAIA and financial rules from SAMA; Qatar, Bahrain, Kuwait and Oman each add their own expectations. A practical approach is to define the strictest applicable regime per workload, then satisfy it rather than designing to an average. Plugsky's GCC default is the UAE region, with a Riyadh region available on Enterprise and on-prem or air-gapped deployment when data must not leave a specific national boundary at all.

Residency architecture that holds under pressure

  • Failover: make permitted failover regions explicit; if none are permitted, capacity-plan inside the jurisdiction instead of relying on automatic rerouting.
  • Keys: hold encryption keys in a KMS or HSM you control so revocation is yours.
  • Logs: keep request logs in-region and export only the fields your monitoring needs.
  • Support: agree who can access data, from where, under what approval, and how it is logged.
  • Deletion: cover primary storage, backups and vector indexes, with evidence.

What to put in the vendor file

Collect evidence that a reviewer can follow: a store-by-store residency map, a workspace configuration export showing the pinned region, the subprocessor list with locations, sample audit events, and the retention and deletion schedule. Confirm the contractual positions in the terms and SLA — /legal/terms and /legal/sla — and record that SOC 2 Type II and ISO 27001 are readiness in progress rather than completed. If your regulator requires a physical boundary, ask for the on-prem or air-gapped option rather than negotiating a clause that the architecture cannot enforce.

Honest comparison

Residency approachPlugskyGlobal API providerSelf-hosted in-country
GCC regionUAE default; Riyadh on EnterpriseVaries; often nearest foreign regionYour data centre
Failover controlPinned region plus explicit behaviourProvider routing decidesYou design it
Deployment tiersCloud, VPC, on-prem, air-gappedProvider cloud onlyAll of it is yours
Key custodyBYOK or HSM with revocationUsually provider-managedYou operate the HSM
EvidenceConfig exports, logs, subprocessor listVariesYour own tooling
Ops burdenManagedManagedHigh

Frequently asked questions

Does Plugsky have a GCC region?

Yes. me-central-1 (UAE) is the default GCC region, with sa-central-1 (Riyadh) available on Enterprise. Region pinning keeps data in the selected region, and on-prem or air-gapped options exist for stricter boundaries.

Is pinning enough for Saudi PDPL?

Not by itself. You also need to control failover, logs, backups, support access and key custody, and to evidence the configuration. Review the specific PDPL and sector requirements with counsel.

What about data in embeddings?

Embeddings are derived data and belong in the same residency and deletion scope as source documents. Keep the vector store in-region and test deletion across the collection and its backups.

Can support staff access our data from outside the GCC?

Support access should be contractually and operationally constrained, and logged. For strict requirements, on-prem or air-gapped deployment removes external access paths entirely.

How do we prove residency to an auditor?

Provide a store-by-store map, a workspace configuration export showing the pinned region, subprocessor locations, sample audit events and the retention schedule. Evidence beats assurance language.

What happens during a region incident?

Failover behaviour should be explicit and tested. If cross-border failover is not permitted, plan capacity within the jurisdiction rather than relying on automatic rerouting.

Does Plugsky keep data in the UAE by default?

The UAE region is the GCC default, but verify the setting in your own workspace and export the configuration for your file. Do not assume a default equals a commitment.

What certifications support GCC diligence?

Plugsky documents UAE PDPL and DIFC DPL alignment plus SOC 2 Type II and ISO 27001 readiness in progress. Treat certifications as pending and validate controls directly with the enterprise team.