Tools + TOFU

How ready is your organisation for sovereign AI?

The sovereign AI readiness score assesses an enterprise against the controls that matter: data residency, key management, deployment model (cloud, VPC, on-prem, air-gapped), audit logs, RBAC and SSO, legal agreements and exit planning. You answer a structured questionnaire and receive a readiness score plus a prioritised gap list with the evidence each control requires.

Key facts

Tool typeFree sovereign AI readiness questionnaire and score
DomainsResidency, keys, deployment, audit logs, RBAC/SSO, legal, incident response, exit
OutputReadiness score plus a prioritised gap list with evidence to collect
Deployment optionsPlugsky cloud, your VPC, on-prem and air-gapped
Governance inputsDPA, SLA, audit logs, region selection and key management
Nature of the scoreSelf-assessment; validate with your security and legal teams
Free plan2 free AI models (plugsky-micro, plugsky-lite), no card required
Product statusLive

TL;DR

  • Residency is an architecture decision, not a checkbox on a vendor page.
  • Map every control to evidence: a document, a config or a test result.
  • Deployment model — cloud, VPC, on-prem, air-gapped — should follow data sensitivity.
  • Plan the exit before you sign: portability and deletion terms matter.
  • The score is a self-assessment; use it to sequence work, not to certify compliance.

How it works, step by step

  1. Classify your data by sensitivity and the residency obligations attached to it.
  2. Complete the sovereign AI readiness questionnaire domain by domain.
  3. For each gap, identify the evidence that would close it: policy, config, contract or test.
  4. Assign owners and sequence fixes by risk and effort.
  5. Choose a deployment model per workload: cloud, VPC, on-prem or air-gapped.
  6. Review legal agreements, key management and audit-log coverage with security.
  7. Re-score after remediation and set a recurring review cadence.
1Classify your databy sensitivity andthe residency2Complete thesovereign AIreadiness3For each gap,identify theevidence that would4Assign owners andsequence fixes byrisk and effort.5Choose a deploymentmodel per workload:cloud, VPC, on-prem6Review legalagreements, keymanagement and

Try it yourself

Open the sovereign AI readiness score →

What the score measures

The questionnaire covers the controls auditors and security teams actually ask about. Residency: where data is processed and stored, and whether the provider offers region selection. Keys: who holds encryption keys, whether BYOK is available and how rotation works. Deployment: whether you can run in your VPC, on-prem or air-gapped, and what isolation that provides. Operations: audit logs, RBAC, SSO and incident response. Legal: DPA terms, SLA commitments and subprocessor transparency. And exit: data export, retention and deletion on termination. Each answer maps to evidence you can collect and review.

Reading the gap list

A score is a conversation starter; the gap list is the work. Gaps fall into three kinds. Missing artefacts — a DPA, an SLA, an audit-log export — are the easiest to close because they are procurement and configuration tasks. Architectural gaps, such as needing on-prem isolation for a specific data class, take longer and should be sequenced early. Process gaps, like an untested incident-response plan, are easy to defer and dangerous to ignore; test them on a schedule rather than trusting the document. Order by risk first, then effort.

Turning readiness into a plan

The output should be a plan your security and platform teams share. Start with residency because it constrains architecture; Plugsky supports region selection plus VPC, on-prem and air-gapped deployments for enterprise workloads. Then close identity and logging gaps, since RBAC, SSO and audit trails are prerequisites for almost every regulated framework. Finally, rehearse the exit: export your data, confirm deletion terms and verify that your application can run against another endpoint. A sovereign posture is proven by rehearsed procedures, not by slides — and the score should be re-run after each remediation cycle.

Honest comparison

DomainControl to evidenceWeak signalStrong signal
ResidencyRegion selection and processing boundariesVendor page claims onlyDocumented region plus config
Key managementEncryption keys and BYOK optionsUnknown key ownershipCustomer-managed keys with rotation
DeploymentCloud, VPC, on-prem or air-gappedSingle public-cloud optionIsolation matched to data class
Identity and logsRBAC, SSO and audit-log exportNo export capabilityTested access reviews and log retention
LegalDPA, SLA and subprocessor listUnclear termsSigned agreements on file
ExitData export and deletion on terminationNo portability termsRehearsed migration and deletion

Frequently asked questions

What is sovereign AI readiness?

The ability to run AI workloads under your own legal, residency and operational controls — region choice, key management, deployment isolation, audit trails and a workable exit path.

Is the readiness score a certification?

No. It is a structured self-assessment that produces a score and a prioritised gap list. Validate findings with your security, legal and compliance teams.

Why does residency matter?

It determines where data is processed and stored, which is often a legal requirement for regulated industries and public-sector work. Region selection plus private deployment options address it.

What deployment options does Plugsky offer?

Managed cloud, your VPC, on-prem and air-gapped deployments, with region selection for data residency.

How do audit logs fit in?

They provide evidence of access and activity for investigations and audits. Confirm export format and retention before you need them.

What should we fix first?

Residency and deployment, because they constrain architecture, then identity and logging, then legal and exit rehearsals.

How often should we re-score?

After each remediation cycle and at least annually, plus whenever the workload, data classification or provider changes.

Is there a free plan to start with?

Yes. The free plan includes 2 free AI models with no card required, so teams can run a pilot while governance work proceeds.