FAQ + Objections

What compliance options does Plugsky offer?

Plugsky provides a DPA and a published SLA, supports data-residency choices, and offers private deployments (VPC, on-prem, air-gapped) for regulated workloads. Access controls include RBAC, SSO and audit logs, with BYOK available in enterprise deployments. Certification coverage and sector attestations vary — request the current compliance pack rather than assuming every framework is covered.

Key facts

DPAAvailable for review and signature
SLAPublished service-level commitments
Data residencyRegion selection and sovereign deployments
Access controlRBAC, SSO and audit logs
Key custodyBYOK in enterprise deployments
Private deploymentVPC, on-prem and air-gapped options
Certification coverageVaries — request the current compliance pack
Product statusLive

TL;DR

  • DPA, SLA and residency options are the contractual core.
  • RBAC, SSO and audit logs cover access governance.
  • Private deployments address the strictest regulatory constraints.
  • Certifications vary — verify against your framework before assuming coverage.
  • Start procurement early; legal review runs in parallel with the technical pilot.

How it works, step by step

  1. List the obligations that apply to each workload: residency, retention, access, audit, key custody.
  2. Request the DPA, SLA, sub-processor list and current compliance documentation.
  3. Map each obligation to a control and note where a private deployment is required.
  4. Run the technical pilot while legal and security review the documentation.
  5. Confirm data flows and sub-processors against your vendor register.
  6. Record decisions and residual risks in your compliance file before production.
1List theobligations thatapply to each2Request the DPA,SLA, sub-processorlist and current3Map each obligationto a control andnote where a4Run the technicalpilot while legaland security review5Confirm data flowsand sub-processorsagainst your vendor6Record decisionsand residual risksin your compliance

Try it yourself

Open the EU AI Act compliance checker →

The contractual layer

Compliance conversations start with paperwork and end with architecture, so get the contractual layer settled first. Plugsky publishes an SLA and terms, and makes a DPA available so you can document processing purposes, retention and sub-processors in a form your legal team recognises. Residency can be committed as a deployment characteristic — region selection for shared cloud, or a dedicated deployment in your own boundary. The important discipline is specificity: name the region, name the deployment model, and have both written into the agreement rather than inferred.

The control layer

Controls are what auditors actually test:

  • Access: RBAC and SSO for who can use the platform and what they can do.
  • Audit: logs of authentication and usage events for investigation and evidence.
  • Isolation: VPC, on-prem or air-gapped deployments where network boundaries matter.
  • Key custody: BYOK so encryption keys stay under your control in high-assurance environments.
  • Retention: configurable logging, with private deployments able to minimise application logs.

Map each control to the obligation it satisfies and note the evidence you can produce. Where a framework requires a certification you have not been shown, treat it as an open item, not an assumption.

What we do and what we do not do

What we do: provide the DPA, SLA, security controls and private deployment paths that regulated workloads typically require, and support your due-diligence process with documentation. What we do not do: claim blanket certification coverage, substitute marketing statements for evidence, or take responsibility for your own governance obligations — model usage policies, end-user notices and data classification remain yours. Read the terms and SLA, and press for specifics where your regulator expects them.

Honest comparison

Compliance needPlugsky shared cloudPlugsky private deploymentTypical API provider
DPA and SLAAvailableAvailable plus custom termsUsually available
Data residencySelected regionsYour boundary or jurisdictionLimited options
Access controlsRBAC, SSO, audit logsIntegrated with your identityVaries
Key custodyPlugsky-managedBYOK, your KMS/HSMProvider-managed
IsolationMulti-tenantVPC, on-prem, air-gappedRarely
Certification coverageRequest current packScoped in agreementVaries

Frequently asked questions

Do you offer a DPA?

Yes — a DPA is available for review and signature, covering processing purposes, retention and sub-processors. Request it before your legal review rather than after the pilot.

Is there an SLA?

Yes, a published SLA defines service-level commitments. For enterprise deployments, additional terms can be scoped in the agreement.

Which certifications are covered?

Certification coverage varies and changes; request the current compliance pack so you are reviewing up-to-date documentation rather than assumptions.

How do you support regulated data?

Through residency options, private deployments, BYOK, RBAC/SSO and audit logs. The right combination depends on your specific obligations and deployment model.

Can auditors access evidence?

Usage and access logs support audit requirements, and private deployments keep them in your environment. Agree the evidence format with your audit team in advance.

Are you EU AI Act compliant?

Framework obligations fall largely on deployers as well as providers. Use the compliance checker to map your role, and review Plugsky documentation against the specific requirements that apply to you.

Where do I start?

Request the DPA, SLA and current compliance pack, then run a pilot on the free plan and full-access trial while legal review proceeds in parallel. See the live pricing page for contact paths.