Key facts
| Tool type | Free sovereign AI readiness questionnaire and score |
| Domains | Residency, keys, deployment, audit logs, RBAC/SSO, legal, incident response, exit |
| Output | Readiness score plus a prioritised gap list with evidence to collect |
| Deployment options | Plugsky cloud, your VPC, on-prem and air-gapped |
| Governance inputs | DPA, SLA, audit logs, region selection and key management |
| Nature of the score | Self-assessment; validate with your security and legal teams |
| Free plan | 2 free AI models (plugsky-micro, plugsky-lite), no card required |
| Product status | Live |
TL;DR
- Residency is an architecture decision, not a checkbox on a vendor page.
- Map every control to evidence: a document, a config or a test result.
- Deployment model — cloud, VPC, on-prem, air-gapped — should follow data sensitivity.
- Plan the exit before you sign: portability and deletion terms matter.
- The score is a self-assessment; use it to sequence work, not to certify compliance.
How it works, step by step
- Classify your data by sensitivity and the residency obligations attached to it.
- Complete the sovereign AI readiness questionnaire domain by domain.
- For each gap, identify the evidence that would close it: policy, config, contract or test.
- Assign owners and sequence fixes by risk and effort.
- Choose a deployment model per workload: cloud, VPC, on-prem or air-gapped.
- Review legal agreements, key management and audit-log coverage with security.
- Re-score after remediation and set a recurring review cadence.
Try it yourself
Open the sovereign AI readiness score →
What the score measures
The questionnaire covers the controls auditors and security teams actually ask about. Residency: where data is processed and stored, and whether the provider offers region selection. Keys: who holds encryption keys, whether BYOK is available and how rotation works. Deployment: whether you can run in your VPC, on-prem or air-gapped, and what isolation that provides. Operations: audit logs, RBAC, SSO and incident response. Legal: DPA terms, SLA commitments and subprocessor transparency. And exit: data export, retention and deletion on termination. Each answer maps to evidence you can collect and review.
Reading the gap list
A score is a conversation starter; the gap list is the work. Gaps fall into three kinds. Missing artefacts — a DPA, an SLA, an audit-log export — are the easiest to close because they are procurement and configuration tasks. Architectural gaps, such as needing on-prem isolation for a specific data class, take longer and should be sequenced early. Process gaps, like an untested incident-response plan, are easy to defer and dangerous to ignore; test them on a schedule rather than trusting the document. Order by risk first, then effort.
Turning readiness into a plan
The output should be a plan your security and platform teams share. Start with residency because it constrains architecture; Plugsky supports region selection plus VPC, on-prem and air-gapped deployments for enterprise workloads. Then close identity and logging gaps, since RBAC, SSO and audit trails are prerequisites for almost every regulated framework. Finally, rehearse the exit: export your data, confirm deletion terms and verify that your application can run against another endpoint. A sovereign posture is proven by rehearsed procedures, not by slides — and the score should be re-run after each remediation cycle.
Honest comparison
| Domain | Control to evidence | Weak signal | Strong signal |
|---|---|---|---|
| Residency | Region selection and processing boundaries | Vendor page claims only | Documented region plus config |
| Key management | Encryption keys and BYOK options | Unknown key ownership | Customer-managed keys with rotation |
| Deployment | Cloud, VPC, on-prem or air-gapped | Single public-cloud option | Isolation matched to data class |
| Identity and logs | RBAC, SSO and audit-log export | No export capability | Tested access reviews and log retention |
| Legal | DPA, SLA and subprocessor list | Unclear terms | Signed agreements on file |
| Exit | Data export and deletion on termination | No portability terms | Rehearsed migration and deletion |
Frequently asked questions
What is sovereign AI readiness?
The ability to run AI workloads under your own legal, residency and operational controls — region choice, key management, deployment isolation, audit trails and a workable exit path.
Is the readiness score a certification?
No. It is a structured self-assessment that produces a score and a prioritised gap list. Validate findings with your security, legal and compliance teams.
Why does residency matter?
It determines where data is processed and stored, which is often a legal requirement for regulated industries and public-sector work. Region selection plus private deployment options address it.
What deployment options does Plugsky offer?
Managed cloud, your VPC, on-prem and air-gapped deployments, with region selection for data residency.
How do audit logs fit in?
They provide evidence of access and activity for investigations and audits. Confirm export format and retention before you need them.
What should we fix first?
Residency and deployment, because they constrain architecture, then identity and logging, then legal and exit rehearsals.
How often should we re-score?
After each remediation cycle and at least annually, plus whenever the workload, data classification or provider changes.
Is there a free plan to start with?
Yes. The free plan includes 2 free AI models with no card required, so teams can run a pilot while governance work proceeds.