Key facts
| Deployment models | Region-locked cloud planes, private endpoint in your VPC, on-prem and air-gapped |
| Plane for this market | EU plane, Frankfurt (eu-central-1); region-locked for GDPR-aligned processing |
| Models | 30+ models behind one OpenAI-compatible API |
| Pricing | Flat monthly self-serve plans, no per-token billing; see the live pricing page |
| Residency enforcement | Architectural region lock; prompts, completions, embeddings and logs stay in-region |
| Access control | Scoped API keys, RBAC, SSO/SCIM and SIEM-exportable audit logs |
| Compliance alignment | The EU plane is aligned with GDPR and ISO 27001 expectations |
| Product status | Chat, streaming, JSON mode, function calling, embeddings and agents are live |
TL;DR
- Pin the EU plane (Frankfurt) or deploy in your own network to meet the GDPR as implemented by the UAVG.
- The same OpenAI-compatible API works across every deployment model, so no rewrite is needed.
- 30+ models, from free plugsky-micro and plugsky-lite to frontier reasoning tiers.
- Self-serve pricing is flat monthly; no per-token billing - see the live pricing page.
- Enterprise adds BYOK, zero-knowledge mode, audit export and right-to-audit clauses.
How it works, step by step
- Map your data classes and decide which must stay in Netherlands.
- Pick a deployment model: the EU plane (Frankfurt), private endpoint, on-prem or air-gapped.
- Create a workspace and issue scoped API keys per environment and team.
- Point your OpenAI-compatible client at api.plugsky.com and map model names.
- Configure prompt retention, RBAC/SSO and audit export to your SIEM.
- Run an evaluation set on local-language and local-regulatory cases before scaling.
- Document the evidence path - DPA, sub-processors and residency attestations - for auditors.
Original data
Try it yourself
Open the AI data residency checklist →
What sovereign AI cloud means for Netherlands
The Netherlands combines strict GDPR enforcement with an active government cloud policy and one of Europe's densest connectivity hubs. Amsterdam's interconnection ecosystem shapes latency expectations. Azure West Europe is hosted in the Netherlands and Amsterdam's AMS-IX exchange anchors connectivity; Dutch government buyers follow the national cloud policy and BIO baseline.
Sovereignty is an architecture decision covering processing location, storage location, key custody and audit evidence. Plugsky separates these layers, so you can adopt a strict posture for one workload and a lighter one for the next without running two platforms.
Regulatory context: the GDPR as implemented by the UAVG
GDPR applies as implemented by the UAVG, enforced by the Autoriteit Persoonsgegevens (AP). Government procurement adds sovereignty criteria through the Rijksbrede cloudbeleid and the BIO security baseline.
Plugsky's response is architectural: the EU plane is aligned with GDPR and ISO 27001 expectations. Prompts, completions, embeddings and logs stay inside the selected plane, and the guarantee does not rest on a contractual promise alone.
Deployment options, from region-locked planes to air-gapped
Dutch teams pin the EU (Frankfurt) plane as a GDPR-aligned default, or run VPC, on-prem and air-gapped deployments when sovereignty criteria require it.
- Region-locked plane: managed inference in the EU (Frankfurt), GCC (UAE), APAC (Singapore) or US (Virginia), with Riyadh on Enterprise.
- Private endpoint: the same API inside your VPC.
- On-prem: run inside your own data centre.
- Air-gapped: fully disconnected environments for critical infrastructure.
Because the API surface is identical, moving a workload between these modes is configuration, not a rewrite.
Models, pricing and proof
Model choice is configuration: 30+ models behind one endpoint, with plugsky-micro and plugsky-lite free and larger reasoning models on paid plans. Self-serve pricing is flat monthly, and a 14-day full-access trial exists for teams that want to test the full catalogue before committing.
Dutch-language service obligations for government work mean evaluation sets should include Dutch prompts, not only English. Where Plugsky does not replace other providers yet: audio, images, moderation, files, batch, fine-tuning, assistants and responses are roadmap items. Chat, streaming, tools, JSON mode, embeddings, RAG and agents are live today.
Honest comparison
| Consideration | Plugsky | Global hyperscaler AI | Self-managed in-country |
|---|---|---|---|
| Residency enforcement | Region-locked planes plus VPC, on-prem and air-gapped | Contractual commitments across shared regions | You build networking and controls |
| Model access | 30+ models on one OpenAI-compatible API | Vendor catalogue per platform | You serve and patch every model |
| Pricing | Flat monthly self-serve plans; see the live pricing page | Consumption-based line items | GPU capex plus operations |
| Time to first request | API key and a base-URL change | Platform-specific setup | Weeks to months |
| Audit and keys | Audit-log export, BYOK on Enterprise | Varies by service | You build everything |
Frequently asked questions
How does the GDPR as implemented by the UAVG affect AI cloud choices in Netherlands?
GDPR applies as implemented by the UAVG, enforced by the Autoriteit Persoonsgegevens (AP). Government procurement adds sovereignty criteria through the Rijksbrede cloudbeleid and the BIO security baseline. Dutch teams pin the EU (Frankfurt) plane as a GDPR-aligned default, or run VPC, on-prem and air-gapped deployments when sovereignty criteria require it.
Can Netherlands teams keep data in-country with Plugsky?
Dutch teams pin the EU (Frankfurt) plane as a GDPR-aligned default, or run VPC, on-prem and air-gapped deployments when sovereignty criteria require it. Plugsky publishes region-locked planes in the EU (Frankfurt), GCC (UAE), APAC (Singapore) and US (Virginia), with Riyadh on Enterprise; stricter in-country requirements are met with VPC, on-prem or air-gapped deployment.
Does Plugsky have a data centre or office in Netherlands?
Plugsky publishes region-locked planes rather than country-by-country facilities, so check /data-residency for the current list. Deployments in your own VPC, on-prem or air-gapped cover requirements that demand an in-country footprint.
Can we keep prompts, embeddings and logs in our jurisdiction?
Yes, on a region-locked plane the processing path - inference, embeddings and logs - stays in the selected region by architecture rather than by contract. Enterprise agreements add customer-managed keys, zero-knowledge mode and right-to-audit clauses.
What deployment models are available?
Four: a managed region-locked plane, a private endpoint inside your VPC, on-premises deployment, and air-gapped installation for disconnected environments. The API surface is identical across all four.
How is pricing structured, and is there a free option?
Self-serve plans are flat monthly with no per-token billing on the free plan or paid tiers beyond it; plugsky-micro and plugsky-lite are free with no card, and a 14-day full-access trial exists. See the live pricing page for current plans.
Which capabilities are live today?
Chat completions, streaming, JSON mode, function calling, embeddings, RAG and agent loops are live. Audio, images, moderation, files, batch, fine-tuning, assistants and responses are coming-soon endpoints.
How do we prove residency to an auditor?
Provide the DPA, the current sub-processor list, exported audit logs and a description of the residency architecture; Enterprise contracts add right-to-audit clauses. Keep sub-processor notifications in your evidence trail.