Key facts
| Deployment models | Region-locked cloud planes, private endpoint in your VPC, on-prem and air-gapped |
| Plane for this market | EU plane, Frankfurt (eu-central-1) - the same region anchors German commercial cloud |
| Models | 30+ models behind one OpenAI-compatible API |
| Pricing | Flat monthly self-serve plans, no per-token billing; see the live pricing page |
| Residency enforcement | Architectural region lock; prompts, completions, embeddings and logs stay in-region |
| Access control | Scoped API keys, RBAC, SSO/SCIM and SIEM-exportable audit logs |
| Compliance alignment | The EU plane is aligned with GDPR and ISO 27001 expectations |
| Product status | Chat, streaming, JSON mode, function calling, embeddings and agents are live |
TL;DR
- Pin the EU plane (Frankfurt) or deploy in your own network to meet the GDPR as supplemented by the BDSG.
- The same OpenAI-compatible API works across every deployment model, so no rewrite is needed.
- 30+ models, from free plugsky-micro and plugsky-lite to frontier reasoning tiers.
- Self-serve pricing is flat monthly; no per-token billing - see the live pricing page.
- Enterprise adds BYOK, zero-knowledge mode, audit export and right-to-audit clauses.
How it works, step by step
- Map your data classes and decide which must stay in Germany.
- Pick a deployment model: the EU plane (Frankfurt), private endpoint, on-prem or air-gapped.
- Create a workspace and issue scoped API keys per environment and team.
- Point your OpenAI-compatible client at api.plugsky.com and map model names.
- Configure prompt retention, RBAC/SSO and audit export to your SIEM.
- Run an evaluation set on local-language and local-regulatory cases before scaling.
- Document the evidence path - DPA, sub-processors and residency attestations - for auditors.
Original data
Try it yourself
Open the AI data residency checklist →
What sovereign AI cloud means for Germany
Germany's AI cloud market is shaped by data-protection federalism and a procurement culture that asks for attestations first. Sovereignty is a checklist item, not a slogan. Frankfurt (AWS eu-central-1, Azure Germany West Central) is the country's cloud hub, and Plugsky's EU plane is the same eu-central-1 region.
Sovereignty is an architecture decision covering processing location, storage location, key custody and audit evidence. Plugsky separates these layers, so you can adopt a strict posture for one workload and a lighter one for the next without running two platforms.
Regulatory context: the GDPR as supplemented by the BDSG
The GDPR applies as supplemented by the Bundesdatenschutzgesetz (BDSG); the BfDI and the Lander authorities coordinate through the DSK. BSI C5 attestation and IT-Grundschutz are common procurement baselines, and CLOUD Act exposure drives sovereign-cloud demand.
Plugsky's response is architectural: the EU plane is aligned with GDPR and ISO 27001 expectations. Prompts, completions, embeddings and logs stay inside the selected plane, and the guarantee does not rest on a contractual promise alone.
Deployment options, from region-locked planes to air-gapped
German teams can pin the EU (Frankfurt) plane for in-country processing, or go further with VPC, on-prem and air-gapped deployments where CLOUD Act exposure must be removed entirely.
- Region-locked plane: managed inference in the EU (Frankfurt), GCC (UAE), APAC (Singapore) or US (Virginia), with Riyadh on Enterprise.
- Private endpoint: the same API inside your VPC.
- On-prem: run inside your own data centre.
- Air-gapped: fully disconnected environments for critical infrastructure.
Because the API surface is identical, moving a workload between these modes is configuration, not a rewrite.
Models, pricing and proof
Model choice is configuration: 30+ models behind one endpoint, with plugsky-micro and plugsky-lite free and larger reasoning models on paid plans. Self-serve pricing is flat monthly, and a 14-day full-access trial exists for teams that want to test the full catalogue before committing.
Works councils scrutinise the employee-monitoring implications of AI tooling, so involve them early in rollout planning. Where Plugsky does not replace other providers yet: audio, images, moderation, files, batch, fine-tuning, assistants and responses are roadmap items. Chat, streaming, tools, JSON mode, embeddings, RAG and agents are live today.
Honest comparison
| Consideration | Plugsky | Global hyperscaler AI | Self-managed in-country |
|---|---|---|---|
| Residency enforcement | Region-locked planes plus VPC, on-prem and air-gapped | Contractual commitments across shared regions | You build networking and controls |
| Model access | 30+ models on one OpenAI-compatible API | Vendor catalogue per platform | You serve and patch every model |
| Pricing | Flat monthly self-serve plans; see the live pricing page | Consumption-based line items | GPU capex plus operations |
| Time to first request | API key and a base-URL change | Platform-specific setup | Weeks to months |
| Audit and keys | Audit-log export, BYOK on Enterprise | Varies by service | You build everything |
Frequently asked questions
How does the GDPR as supplemented by the BDSG affect AI cloud choices in Germany?
The GDPR applies as supplemented by the Bundesdatenschutzgesetz (BDSG); the BfDI and the Lander authorities coordinate through the DSK. BSI C5 attestation and IT-Grundschutz are common procurement baselines, and CLOUD Act exposure drives sovereign-cloud demand. German teams can pin the EU (Frankfurt) plane for in-country processing, or go further with VPC, on-prem and air-gapped deployments where CLOUD Act exposure must be removed entirely.
Can Germany teams keep data in-country with Plugsky?
German teams can pin the EU (Frankfurt) plane for in-country processing, or go further with VPC, on-prem and air-gapped deployments where CLOUD Act exposure must be removed entirely. Plugsky publishes region-locked planes in the EU (Frankfurt), GCC (UAE), APAC (Singapore) and US (Virginia), with Riyadh on Enterprise; stricter in-country requirements are met with VPC, on-prem or air-gapped deployment.
Does Plugsky have a data centre or office in Germany?
Plugsky publishes region-locked planes rather than country-by-country facilities, so check /data-residency for the current list. Deployments in your own VPC, on-prem or air-gapped cover requirements that demand an in-country footprint.
Can we keep prompts, embeddings and logs in our jurisdiction?
Yes, on a region-locked plane the processing path - inference, embeddings and logs - stays in the selected region by architecture rather than by contract. Enterprise agreements add customer-managed keys, zero-knowledge mode and right-to-audit clauses.
What deployment models are available?
Four: a managed region-locked plane, a private endpoint inside your VPC, on-premises deployment, and air-gapped installation for disconnected environments. The API surface is identical across all four.
How is pricing structured, and is there a free option?
Self-serve plans are flat monthly with no per-token billing on the free plan or paid tiers beyond it; plugsky-micro and plugsky-lite are free with no card, and a 14-day full-access trial exists. See the live pricing page for current plans.
Which capabilities are live today?
Chat completions, streaming, JSON mode, function calling, embeddings, RAG and agent loops are live. Audio, images, moderation, files, batch, fine-tuning, assistants and responses are coming-soon endpoints.
How do we prove residency to an auditor?
Provide the DPA, the current sub-processor list, exported audit logs and a description of the residency architecture; Enterprise contracts add right-to-audit clauses. Keep sub-processor notifications in your evidence trail.