Our compliance approach
Plugsky treats compliance as architecture, not paperwork. Because customers can choose in-region hosting, private endpoints, or on-prem deployment, data localization is built into the product instead of bolted on later. Every deployment tier maps to a different compliance posture.
Compliance by deployment tier
| Tier | Compliance posture | Typical use |
|---|---|---|
| Sovereign AI Cloud | In-region data residency (EU, GCC, APAC, US) | Data localization requirements |
| Private AI Endpoint | Dedicated endpoint in your VPC | Regulated industries with isolation needs |
| On-prem LLM | Everything stays inside your perimeter | Air-gapped, classified, highest-control workloads |
Regional regulation readiness
- GCC — alignment with regional data localization expectations, Arabic-first support.
- EU — EU data residency for GDPR-oriented workloads.
- Export controls — open-weight models mean your capability is not hostage to export rules on a single provider's API.
Compliance FAQ
Is Plugsky SOC 2 or ISO 27001 certified?
See the security page for the full current certification and control details.
Can my data stay in my country?
Yes — that's the core product. See data residency.
Do you offer DPAs?
Yes — our data processing agreement is published at /legal/dpa.
Can I run models fully inside my own data center?
Yes — on-prem LLM deployment is supported.
Get started in minutes
OpenAI-compatible API with 30+ models, free trial, and a 99.9% uptime SLA. No code changes required.
Start free trial → Read the docs