Key facts
| Government fit | Boundary matched to classification; one API across placements |
| Private access | Private endpoints; traffic stays in the deployment you select |
| Residency | Region-locked planes plus on-prem and air-gapped for sovereign work |
| Identity | Agency-held scoped keys, SSO with SCIM and RBAC |
| Retention | Configurable prompt retention; confirm your terms in the DPA |
| Audit | Inference, key and admin events exportable to SIEM |
| Models | 30+ models; air-gapped bundles confirmed under the licensing agreement |
| Pricing | Flat monthly self-serve plans; enterprise deployment scoped on the pricing page |
TL;DR
- Match the boundary to the classification: plane, VPC, on-prem or air-gapped.
- Keep keys in agency custody with documented rotation and dual control.
- Configure retention to records policy and confirm the terms in the DPA.
- Give assessors one evidence path in the agency SIEM across all placements.
- Keep the API portable so applications survive a change of boundary.
How it works, step by step
- Classify candidate workloads and record the permitted boundary and handling rules for each.
- Document data flows for the chosen boundary: inputs, logs, embeddings, retention and egress paths.
- Place key custody in the agency's secret management with rotation, dual control and an auditable issue and revoke process.
- Integrate SSO with SCIM for staff and RBAC for administrative actions; keep services on scoped keys.
- Set prompt retention per workload to the minimum records policy allows and align it with privacy obligations.
- Export authentication, key lifecycle, admin and inference events to the agency SIEM, and test reconstruction.
- Pilot on unclassified or synthetic data with a named owner, then prepare the accreditation pack for wider use.
Try it yourself
Open the sovereign AI readiness score →
Boundary per classification
Public sector AI programmes rarely have a single deployment answer. A policy research assistant might run on a region-locked plane; a case-management workload may require a VPC inside an agency tenancy; national security or disconnected-site work needs on-prem or air-gapped deployment. Plugsky supports all four with the same OpenAI-compatible API, so the classification decision does not force an application rewrite.
That portability matters over a multi-year programme: workloads move as classifications change, and the migrations stay in the deployment layer rather than in code.
Controls and evidence assessors expect
Private deployment answers where data lives; accreditation also asks who can reach it and how you prove it. Design the evidence trail at the same time as the topology.
- Key custody: agency-held secrets, rotation schedule, dual control, documented revocation.
- Identity: SSO with SCIM for staff, scoped keys for services, RBAC for admin actions.
- Retention: configured per workload and aligned with records and privacy obligations.
- Audit: auth, key, admin and inference events in the SIEM, reconstructable per workload.
Keep the scope statement honest: Plugsky provides the model API, deployment variants, scoped authentication, retention settings and audit events — not identity proofing, classification authority or accreditation.
Procurement, cost and capability reality
Self-hosting carries capacity, patching and incident-response costs that belong in the business case alongside licensing. Compare on-prem and VPC options with the flat monthly plans on the live pricing page so the trade-off is explicit: control versus operational effort.
Confirm capability coverage for each use case before acceptance testing. Chat completions with streaming, JSON mode and function calling, plus embeddings, are live in all placements. Audio, images, files, batch, moderation, fine-tuning and assistants endpoints are labelled coming soon, so design around extraction adapters until they ship.
Honest comparison
| Concern | Region-locked plane | VPC deployment | On-prem or air-gapped |
|---|---|---|---|
| Data location | Sovereign Plugsky region | Agency cloud tenancy | Agency network or enclave |
| Classification fit | Controlled and lower | Controlled | Classified, subject to assessment |
| Key custody | Agency-managed | Agency cloud secrets | Agency secret management |
| Update path | Vendor-managed, region-bound | Provider and vendor | Agency-controlled import |
| Operational effort | Lowest of the private options | Moderate | Highest |
Frequently asked questions
Can different workloads use different boundaries?
Yes, and they usually should. Match each workload to the lightest boundary that satisfies its classification, and keep one OpenAI-compatible integration pattern so moves stay cheap.
Who holds the keys?
The agency does, in its own secret management, with rotation, dual control and documented revocation procedures that assessors can inspect.
How is retention handled?
Retention is configurable per workload. Set the minimum records policy allows and confirm the contractual terms in the DPA before production.
Which workloads suit air-gapped deployment?
Classified or disconnected-site workloads where no external network path is permitted. Model bundles and platform updates are carried in under the licensing agreement and agency change control.
What evidence is available to auditors?
Authentication, key lifecycle, administrative and inference events exported to the agency SIEM, giving one reconstruction path across placements.
Does Plugsky meet our procurement framework?
Review the documented security controls, deployment options, SLA and DPA against your framework. Plugsky supplies the technical evidence; the agency makes the compliance determination.
How do we start?
Run a pilot on unclassified or synthetic data on the free plan, prove the workflow, then plan accreditation for production use.