Key facts
| Deployment tiers | In-country region, VPC, on-prem and air-gapped |
| Air-gap update | Bundle ships on physical media with periodic model refresh by courier |
| Key custody | BYOK via cloud KMS or HSM; offline custody for air-gapped sites |
| Identity | SSO/SCIM and RBAC tied to government identity systems |
| Audit | Key/admin events plus per-request logs, exportable to SIEM |
| Resilience | Multi-region options and tested DR for continuity tiers |
| Contractual frame | Terms at /legal/terms and service commitments at /legal/sla |
| Compliance posture | SOC 2 Type II and ISO 27001 readiness in progress (not yet certified) |
TL;DR
- Sovereignty is a full-stack property, not a region setting.
- For classified work, the network has no path out — including support access.
- Keys, updates and personnel stay inside the jurisdiction.
- Audit every model call and every administrative action.
- Start with an unclassified pilot, then expand by classification level.
How it works, step by step
- Classify workloads and map each to its legal and security requirements.
- Choose the tier: in-country region, VPC, on-prem or fully air-gapped.
- Define key custody and the update process, including physical media where required.
- Connect identity to the government IdP and define least-privilege roles.
- Confirm personnel and support access rules, with logging for every access.
- Stand up audit export and define anomaly alerting.
- Pilot on unclassified data, document evidence, then expand by classification level.
Try it yourself
Open the sovereign AI readiness score →
Sovereignty across every layer
- Compute and storage: inference and data live in-country; for classified workloads, in a network with no external path.
- Keys: held in a KMS or HSM under national control, with offline custody for air-gapped sites.
- Updates: model and platform refreshes arrive through a controlled process — physical media for air-gapped networks.
- Identity: federated with the government identity provider, with RBAC and SCIM lifecycle automation.
- Audit: request and administrative events retained and exportable to the national SIEM.
- Personnel: support and operations access constrained by clearance and jurisdiction, and logged.
Building for air-gapped operation
Air-gapped sites invert normal operations. There is no telemetry streaming out, no live support session, and no automatic model update. Design for it: a gateway that works without external dependencies, a local model catalogue, a documented media-based update process with integrity verification and rollback, and an offline key ceremony for initial key material. Capacity planning becomes more conservative because you cannot burst to the cloud, so reserve failover headroom inside the installation. Plugsky's air-gapped option ships on physical media with periodic model refresh by courier, which makes the logistics contract part of the architecture review rather than an afterthought.
Continuity tiers for public services
Not every government workload needs the same isolation. A pragmatic portfolio separates citizen-facing services, internal productivity, analytical workloads and classified systems. Citizen-facing and analytical workloads often fit an in-country region with strict residency and audit; internal productivity sits between; classified systems take on-prem or air-gapped. Design the gateway once and deploy it across tiers so prompts, evaluation suites and application code transfer without rewrites — the same OpenAI-compatible contract holds across all of them.
Procurement evidence and honest gaps
Public sector diligence is evidence-heavy: architecture diagrams, data-flow maps, key custody descriptions, audit samples, personnel and access policy, update procedures and DR test results. Record what is proven and what is pending — Plugsky documents SOC 2 Type II and ISO 27001 as readiness in progress rather than completed certification, and specialised endpoints such as audio, images and fine-tuning are coming soon. Neither is fatal; both belong in the risk register with milestones and compensating controls. Contractual commitments should reference /legal/terms and /legal/sla, with sovereign deployment obligations written into the enterprise agreement.
Honest comparison
| Requirement | Sovereign deployment | In-country cloud region | General cloud |
|---|---|---|---|
| Data path | Air-gapped option with no external route | In-country region with pinning | Provider regions |
| Key custody | National KMS/HSM, offline option | BYOK to national KMS | Provider-managed |
| Updates | Physical media, controlled process | Standard releases | Automatic |
| Support access | Clearance-bound and logged | Region-constrained support | Global support teams |
| Continuity | Reserved local capacity | Multi-region options | Provider-managed |
| Startup effort | Highest | Moderate | Lowest |
Frequently asked questions
What makes AI deployment sovereign?
Every layer sits inside the jurisdiction: compute, storage, keys, updates, audit and personnel. For classified workloads, the network has no external path and updates arrive physically.
Can Plugsky run fully air-gapped?
Yes. The air-gapped deployment ships on physical media with periodic model refresh by courier, and the same OpenAI-compatible API contract applies so applications stay portable.
How do updates work without internet?
Through a documented media-based process with integrity verification and rollback. Treat update logistics, chain of custody and version pinning as part of the architecture review.
Who can access government data?
Support and operations access should be constrained by clearance and jurisdiction, with every access logged. Air-gapped deployments remove external access paths entirely.
How do we maintain audit evidence?
Request and administrative events are logged with actor, timestamp and resource, and export to the national SIEM. Define retention to match your records policy.
Does sovereignty conflict with using third-party model providers?
It can. Provider choice is part of the boundary. For the strictest tiers, plan to run models inside your own installation rather than calling external endpoints.
How should a pilot be scoped?
Start unclassified and low-risk: internal summarisation or document search on non-sensitive data. Verify the boundary, audit and support model, then expand by classification level with documented evidence at each step.
What is Plugsky's certification status for government?
SOC 2 Type II and ISO 27001 are readiness in progress rather than completed. Sovereign deployment controls — private tiers, BYOK/HSM, audit export, SSO/SCIM — can support your assessment while milestones are tracked.