Key facts
| DPA | Available for review and signature |
| SLA | Published service-level commitments |
| Data residency | Region selection and sovereign deployments |
| Access control | RBAC, SSO and audit logs |
| Key custody | BYOK in enterprise deployments |
| Private deployment | VPC, on-prem and air-gapped options |
| Certification coverage | Varies — request the current compliance pack |
| Product status | Live |
TL;DR
- DPA, SLA and residency options are the contractual core.
- RBAC, SSO and audit logs cover access governance.
- Private deployments address the strictest regulatory constraints.
- Certifications vary — verify against your framework before assuming coverage.
- Start procurement early; legal review runs in parallel with the technical pilot.
How it works, step by step
- List the obligations that apply to each workload: residency, retention, access, audit, key custody.
- Request the DPA, SLA, sub-processor list and current compliance documentation.
- Map each obligation to a control and note where a private deployment is required.
- Run the technical pilot while legal and security review the documentation.
- Confirm data flows and sub-processors against your vendor register.
- Record decisions and residual risks in your compliance file before production.
Try it yourself
Open the EU AI Act compliance checker →
The contractual layer
Compliance conversations start with paperwork and end with architecture, so get the contractual layer settled first. Plugsky publishes an SLA and terms, and makes a DPA available so you can document processing purposes, retention and sub-processors in a form your legal team recognises. Residency can be committed as a deployment characteristic — region selection for shared cloud, or a dedicated deployment in your own boundary. The important discipline is specificity: name the region, name the deployment model, and have both written into the agreement rather than inferred.
The control layer
Controls are what auditors actually test:
- Access: RBAC and SSO for who can use the platform and what they can do.
- Audit: logs of authentication and usage events for investigation and evidence.
- Isolation: VPC, on-prem or air-gapped deployments where network boundaries matter.
- Key custody: BYOK so encryption keys stay under your control in high-assurance environments.
- Retention: configurable logging, with private deployments able to minimise application logs.
Map each control to the obligation it satisfies and note the evidence you can produce. Where a framework requires a certification you have not been shown, treat it as an open item, not an assumption.
What we do and what we do not do
What we do: provide the DPA, SLA, security controls and private deployment paths that regulated workloads typically require, and support your due-diligence process with documentation. What we do not do: claim blanket certification coverage, substitute marketing statements for evidence, or take responsibility for your own governance obligations — model usage policies, end-user notices and data classification remain yours. Read the terms and SLA, and press for specifics where your regulator expects them.
Honest comparison
| Compliance need | Plugsky shared cloud | Plugsky private deployment | Typical API provider |
|---|---|---|---|
| DPA and SLA | Available | Available plus custom terms | Usually available |
| Data residency | Selected regions | Your boundary or jurisdiction | Limited options |
| Access controls | RBAC, SSO, audit logs | Integrated with your identity | Varies |
| Key custody | Plugsky-managed | BYOK, your KMS/HSM | Provider-managed |
| Isolation | Multi-tenant | VPC, on-prem, air-gapped | Rarely |
| Certification coverage | Request current pack | Scoped in agreement | Varies |
Frequently asked questions
Do you offer a DPA?
Yes — a DPA is available for review and signature, covering processing purposes, retention and sub-processors. Request it before your legal review rather than after the pilot.
Is there an SLA?
Yes, a published SLA defines service-level commitments. For enterprise deployments, additional terms can be scoped in the agreement.
Which certifications are covered?
Certification coverage varies and changes; request the current compliance pack so you are reviewing up-to-date documentation rather than assumptions.
How do you support regulated data?
Through residency options, private deployments, BYOK, RBAC/SSO and audit logs. The right combination depends on your specific obligations and deployment model.
Can auditors access evidence?
Usage and access logs support audit requirements, and private deployments keep them in your environment. Agree the evidence format with your audit team in advance.
Are you EU AI Act compliant?
Framework obligations fall largely on deployers as well as providers. Use the compliance checker to map your role, and review Plugsky documentation against the specific requirements that apply to you.
Where do I start?
Request the DPA, SLA and current compliance pack, then run a pilot on the free plan and full-access trial while legal review proceeds in parallel. See the live pricing page for contact paths.