Compliance

Compliance built in, not bolted on.

Plugsky's compliance model gives you data residency by default, isolation when you need it, and on-prem control when you require it — with Arabic-first support across the Gulf.

Our compliance approach

Plugsky treats compliance as architecture, not paperwork. Because customers can choose in-region hosting, private endpoints, or on-prem deployment, data localization is built into the product instead of bolted on later. Every deployment tier maps to a different compliance posture.

Compliance by deployment tier

TierCompliance postureTypical use
Sovereign AI CloudIn-region data residency (EU, GCC, APAC, US)Data localization requirements
Private AI EndpointDedicated endpoint in your VPCRegulated industries with isolation needs
On-prem LLMEverything stays inside your perimeterAir-gapped, classified, highest-control workloads

Regional regulation readiness

  • GCC — alignment with regional data localization expectations, Arabic-first support.
  • EU — EU data residency for GDPR-oriented workloads.
  • Export controls — open-weight models mean your capability is not hostage to export rules on a single provider's API.

Compliance FAQ

Is Plugsky SOC 2 or ISO 27001 certified?

See the security page for the full current certification and control details.

Can my data stay in my country?

Yes — that's the core product. See data residency.

Do you offer DPAs?

Yes — our data processing agreement is published at /legal/dpa.

Can I run models fully inside my own data center?

Yes — on-prem LLM deployment is supported.

Get started in minutes

OpenAI-compatible API with 30+ models, free trial, and a 99.9% uptime SLA. No code changes required.

Start free trial → Read the docs