Key facts
| Deployment models | Region-locked cloud planes, private endpoint in your VPC, on-prem and air-gapped |
| Plane for this market | EU plane, Frankfurt (eu-central-1); region-locked for GDPR-aligned processing |
| Models | 30+ models behind one OpenAI-compatible API |
| Pricing | Flat monthly self-serve plans, no per-token billing; see the live pricing page |
| Residency enforcement | Architectural region lock; prompts, completions, embeddings and logs stay in-region |
| Access control | Scoped API keys, RBAC, SSO/SCIM and SIEM-exportable audit logs |
| Compliance alignment | The EU plane is aligned with GDPR and ISO 27001 expectations |
| Product status | Chat, streaming, JSON mode, function calling, embeddings and agents are live |
TL;DR
- Pin the EU plane (Frankfurt) or deploy in your own network to meet the GDPR and the Loi Informatique et Libertes.
- The same OpenAI-compatible API works across every deployment model, so no rewrite is needed.
- 30+ models, from free plugsky-micro and plugsky-lite to frontier reasoning tiers.
- Self-serve pricing is flat monthly; no per-token billing - see the live pricing page.
- Enterprise adds BYOK, zero-knowledge mode, audit export and right-to-audit clauses.
How it works, step by step
- Map your data classes and decide which must stay in France.
- Pick a deployment model: the EU plane (Frankfurt), private endpoint, on-prem or air-gapped.
- Create a workspace and issue scoped API keys per environment and team.
- Point your OpenAI-compatible client at api.plugsky.com and map model names.
- Configure prompt retention, RBAC/SSO and audit export to your SIEM.
- Run an evaluation set on local-language and local-regulatory cases before scaling.
- Document the evidence path - DPA, sub-processors and residency attestations - for auditors.
Original data
Try it yourself
Score your sovereign AI readiness →
What sovereign AI cloud means for France
France pairs GDPR enforcement with an explicit industrial policy on sovereign cloud. Public-sector buyers check SecNumCloud before they check benchmarks, and health projects check HDS. Paris (AWS eu-west-3, Azure France Central) and the Marseille connectivity corridor anchor commercial capacity; HDS-certified hosting governs health data.
AI cloud sovereignty breaks into four questions: which jurisdiction processes the request, where data at rest lives, who controls keys, and how you prove all three. Plugsky answers each with configuration - a region-locked plane for regulated work, the same API for everything else.
Regulatory context: the GDPR and the Loi Informatique et Libertes
GDPR, as implemented by the Loi Informatique et Libertes, applies with the CNIL as regulator. The state 'cloud au centre' doctrine requires sovereign-qualified services for public workloads, and ANSSI's SecNumCloud is the reference certification for them. HDS certification governs health data hosting.
Plugsky's response is architectural: the EU plane is aligned with GDPR and ISO 27001 expectations. Prompts, completions, embeddings and logs stay inside the selected plane, and the guarantee does not rest on a contractual promise alone.
Deployment options, from region-locked planes to air-gapped
French teams pin the EU plane (Frankfurt) for GDPR-aligned processing, or run in-country VPC, on-prem or air-gapped deployments when SecNumCloud-style guarantees are mandatory.
- Region-locked plane: managed inference in the EU (Frankfurt), GCC (UAE), APAC (Singapore) or US (Virginia), with Riyadh on Enterprise.
- Private endpoint: the same API inside your VPC.
- On-prem: run inside your own data centre.
- Air-gapped: fully disconnected environments for critical infrastructure.
Because the API surface is identical, moving a workload between these modes is configuration, not a rewrite.
Models, pricing and proof
The same OpenAI-compatible endpoint exposes 30+ models - free tiers for classification and drafting, larger models for reasoning and code. Pricing is flat monthly on self-serve plans rather than per token, and the free plan includes plugsky-micro and plugsky-lite with no card.
CNIL guidance on AI expects a documented legal basis for training and inference data, so keep a record of your processing decisions. Be honest about scope: the live surface is chat, streaming, JSON mode, function calling, embeddings, RAG and agents. Audio, images, moderation, files, batch, fine-tuning, assistants and responses are coming-soon endpoints, so keep those workloads on their current provider for now.
Honest comparison
| Consideration | Plugsky | Global hyperscaler AI | Self-managed in-country |
|---|---|---|---|
| Residency enforcement | Region-locked planes plus VPC, on-prem and air-gapped | Contractual commitments across shared regions | You build networking and controls |
| Model access | 30+ models on one OpenAI-compatible API | Vendor catalogue per platform | You serve and patch every model |
| Pricing | Flat monthly self-serve plans; see the live pricing page | Consumption-based line items | GPU capex plus operations |
| Time to first request | API key and a base-URL change | Platform-specific setup | Weeks to months |
| Audit and keys | Audit-log export, BYOK on Enterprise | Varies by service | You build everything |
Frequently asked questions
How does the GDPR and the Loi Informatique et Libertes affect AI cloud choices in France?
GDPR, as implemented by the Loi Informatique et Libertes, applies with the CNIL as regulator. The state 'cloud au centre' doctrine requires sovereign-qualified services for public workloads, and ANSSI's SecNumCloud is the reference certification for them. HDS certification governs health data hosting. French teams pin the EU plane (Frankfurt) for GDPR-aligned processing, or run in-country VPC, on-prem or air-gapped deployments when SecNumCloud-style guarantees are mandatory.
Can France teams keep data in-country with Plugsky?
French teams pin the EU plane (Frankfurt) for GDPR-aligned processing, or run in-country VPC, on-prem or air-gapped deployments when SecNumCloud-style guarantees are mandatory. Plugsky publishes region-locked planes in the EU (Frankfurt), GCC (UAE), APAC (Singapore) and US (Virginia), with Riyadh on Enterprise; stricter in-country requirements are met with VPC, on-prem or air-gapped deployment.
Does Plugsky have a data centre or office in France?
Plugsky publishes region-locked planes rather than country-by-country facilities, so check /data-residency for the current list. Deployments in your own VPC, on-prem or air-gapped cover requirements that demand an in-country footprint.
Can we keep prompts, embeddings and logs in our jurisdiction?
Yes, on a region-locked plane the processing path - inference, embeddings and logs - stays in the selected region by architecture rather than by contract. Enterprise agreements add customer-managed keys, zero-knowledge mode and right-to-audit clauses.
What deployment models are available?
Four: a managed region-locked plane, a private endpoint inside your VPC, on-premises deployment, and air-gapped installation for disconnected environments. The API surface is identical across all four.
How is pricing structured, and is there a free option?
Self-serve plans are flat monthly with no per-token billing on the free plan or paid tiers beyond it; plugsky-micro and plugsky-lite are free with no card, and a 14-day full-access trial exists. See the live pricing page for current plans.
Which capabilities are live today?
Chat completions, streaming, JSON mode, function calling, embeddings, RAG and agent loops are live. Audio, images, moderation, files, batch, fine-tuning, assistants and responses are coming-soon endpoints.
How do we prove residency to an auditor?
Provide the DPA, the current sub-processor list, exported audit logs and a description of the residency architecture; Enterprise contracts add right-to-audit clauses. Keep sub-processor notifications in your evidence trail.