Key facts
| Sovereignty criteria | Data residency, model control, operational sovereignty and compliance alignment |
| Deployment models | Plugsky cloud region, VPC/private endpoint, on-prem and fully air-gapped |
| Region-locked planes | EU (Frankfurt), GCC (UAE and KSA), APAC (Singapore) and US (Virginia and Oregon); confirm the current list |
| Air-gapped mode | No internet egress, a local model registry and offline update channels |
| Key custody | BYOK via AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM |
| Audit | Per-request logs with region; SIEM export; retention up to 7 years |
| Compliance | SOC 2 Type II under NDA, ISO 27001, HIPAA with a BAA; FedRAMP Moderate in process |
| Local presence | No Amwaj Islands office or facility claimed; sovereignty is deployment-based |
TL;DR
- Amwaj Islands businesses serve Gulf-wide customers, so vendors must show exactly where processing happens.
- Plugsky publishes no Amwaj Islands facility; options are cloud regions, VPC, on-prem and air-gapped.
- SOC 2 Type II, ISO 27001 and HIPAA evidence support review; FedRAMP Moderate is in process.
- Per-request audit logs with region fields export to your SIEM, retained up to 7 years.
- Air-gapped sites run with no internet egress and offline update channels.
How it works, step by step
- Define which sovereignty criteria your regulator, board or customer requires.
- Choose the deployment topology: cloud region, private cloud, on-prem or air-gapped.
- Decide key custody — managed KMS or an on-prem HSM with BYOK.
- Design offline update and model-approval workflows for air-gapped sites.
- Validate audit log fields, SIEM export and retention against your policy.
- Run a pilot on one workload and collect the evidence procurement needs.
- Move to production once the controls are signed off.
Try it yourself
Open the AI data residency checklist →
The Amwaj Islands case for sovereign AI
Amwaj Islands is a group of man-made islands off Muharraq in Bahrain, close to Bahrain International Airport, with residential, hospitality and retail developments. Businesses based there serve both local customers and the wider Gulf market, so their data often crosses borders as part of normal operations. Buyers increasingly ask vendors to prove exactly where processing and storage happen.
Sovereign AI keeps prompts, completions, embeddings, tuned models and logs inside your jurisdiction and perimeter, with local administrators able to run, patch and audit the stack. Plugsky publishes no Amwaj Islands facility; see the data-residency overview for current deployment options and regions.
Cloud, VPC, on-prem or air-gapped: what each proves
Sovereign programmes in Bahrain typically pick one of four patterns:
- Region-locked cloud: a pinned data plane — EU (Frankfurt), GCC (UAE and KSA), APAC (Singapore) or US (Virginia and Oregon); see /data-residency.
- VPC or private endpoint: runs inside your AWS, Azure or GCP account with no public ingress.
- On-prem: open-weight models on hardware you own, operated and patched locally.
- Air-gapped: no internet egress, a local model registry and offline update channels.
For Bahrain teams, start from the published region list; where no in-country plane exists, VPC, on-prem or air-gapped patterns are how residency requirements are met. Keys stay under your control with BYOK through AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM, and audit logs record model, tokens, latency, user and region with SIEM export.
What procurement can verify
Enterprise buyers get documentation rather than slogans: SOC 2 Type II under NDA, ISO 27001/27017/27018, HIPAA with a BAA and GDPR alignment; FedRAMP Moderate is in process. Contracts can include a DPA with EU SCCs, sub-processor terms, audit rights and custom SLAs.
In Bahrain, the Personal Data Protection Law (Law No. 30 of 2018) governs personal data and is supervised by the Personal Data Protection Authority. Confirm current obligations with counsel.
Starting small: a sovereign pilot checklist
A sovereign pilot works best as a bounded exercise: one workload, written requirements, one deployment pattern. Decide early whether keys are managed through your KMS or an on-prem HSM, and define how models are approved and updated without internet egress. Capture audit fields, retention and SIEM export during the pilot and hand that evidence to procurement.
The API stays OpenAI-compatible and one key reaches 30+ models, so existing SDK code, prompts and evaluations carry over. New accounts start on the free plan with plugsky-micro and plugsky-lite and a 14-day full-access trial; see the live pricing page for current plans.
Honest comparison
| Capability | Plugsky | Typical public-cloud AI | Building in-house |
|---|---|---|---|
| Sovereignty scope | Data, model, operations and compliance covered | Usually data location only | You must build and prove all four |
| Deployment models | Cloud region, VPC, on-prem, air-gapped | Shared public cloud only | Your own infrastructure only |
| Air-gapped mode | No internet egress, offline updates | Not offered | Custom engineering effort |
| Key custody | BYOK via KMS or on-prem HSM | Provider-managed keys | You operate the HSMs |
| Audit | Per-request logs with region; SIEM export; up to 7 years | Often limited retention | You build the pipeline |
| Local presence in Amwaj Islands | No facility claimed; sovereignty is deployment-based | Varies by provider | Depends on your own sites |
Frequently asked questions
Does Plugsky have a facility in Amwaj Islands?
No. Plugsky does not claim an office or data centre in Amwaj Islands; sovereign deployments are delivered as cloud regions, private environments or customer-owned infrastructure. See /data-residency for the current region list.
What makes a deployment sovereign?
Four criteria at once: data residency, model control, operational sovereignty and compliance alignment. Pinning storage to a region alone does not satisfy the full set.
Can Plugsky run fully air-gapped?
Yes. Air-gapped deployments run with no internet egress, a local model registry and offline update channels, which suits defence, government and critical infrastructure programmes.
Who holds the encryption keys?
You can. BYOK is supported through AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM, with per-region envelope encryption for data at rest.
What compliance evidence can we review?
SOC 2 Type II under NDA, ISO 27001/27017/27018 and HIPAA with a BAA; FedRAMP Moderate is in process. Enterprise contracts add a DPA with EU SCCs, sub-processor terms and right-to-audit clauses.
Can we keep using the OpenAI SDK?
Yes. The API is OpenAI-compatible, so you change the base URL and model name and keep your existing SDK, prompts and evaluations.
How do we start a sovereign pilot?
Pick one workload, define the sovereignty criteria in writing, choose the deployment topology and key custody, then run the pilot and collect the evidence procurement needs before production.
How does data protection law in Bahrain affect deployment choice?
Bahrain's PDPL (Law No. 30 of 2018) governs personal data and is supervised by the Personal Data Protection Authority. Residency and processing-location requirements usually decide whether a hosted, VPC, on-prem or air-gapped pattern is acceptable.