Key facts
| Sovereignty criteria | Data residency, model control, operational sovereignty and compliance alignment |
| Deployment models | Plugsky cloud region, VPC/private endpoint, on-prem and fully air-gapped |
| Air-gapped mode | No internet egress, local model registry and offline update channels |
| Key custody | BYOK via AWS KMS, Azure Key Vault, HashiCorp Vault or on-prem HSM |
| Audit | Per-request logs with region; SIEM export; retention up to 7 years |
| Compliance | SOC 2 Type II under NDA, ISO 27001, HIPAA with BAA; FedRAMP Moderate in process |
| API compatibility | OpenAI-compatible /v1/chat/completions; change the base URL |
| Local presence | No Lyon office or facility claimed; sovereignty is delivered by deployment model |
TL;DR
- Sovereign AI for Lyon is deployment-based — no local facility is claimed.
- Sovereignty covers data, models, operations and compliance — not just server location.
- Four deployment paths: region-locked cloud, private VPC endpoint, on-prem and air-gapped.
- Air-gapped sites run with no internet egress and offline update channels.
- Keys stay with you via BYOK; per-request audit logs export to your SIEM.
How it works, step by step
- Write down the sovereignty criteria that apply to your Lyon workloads.
- Pick a deployment topology: cloud region, private cloud, on-prem or air-gapped.
- Settle key custody: managed KMS or an on-prem HSM using BYOK.
- Plan offline update and model-approval workflows if the site is air-gapped.
- Confirm audit log fields, SIEM export and retention meet policy.
- Pilot one workload end to end and gather procurement evidence.
- Cut over to production after security and legal sign-off.
Original data
Try it yourself
Open the private LLM deployment estimator →
Why Lyon organisations need sovereign deployment
Lyon is France's third-largest city, set where the Rhone and Saone rivers meet, with a UNESCO-listed old town and a dense health, biotech and banking cluster. Companies here handle clinical, financial and industrial data that often cannot leave the EU perimeter.
Teams across Lyon are moving AI from pilot to production, and that raises a governance question: who controls the data, the models and the operations? For healthcare, biotech and banking organisations, sovereign AI answers all three.
In practice, prompts, completions, embeddings, fine-tuned models and logs stay inside your legal jurisdiction and physical perimeter, while local administrators run, patch and audit the stack themselves. Plugsky publishes no Lyon facility; sovereign deployments are delivered as cloud regions, private environments or customer-owned infrastructure — see the data-residency overview for the current region list.
Sovereign deployment options for Lyon
Plugsky ships four deployment patterns for sovereign programmes:
- Region-locked cloud: a pinned data plane in the region you select; the current region list is published at /data-residency.
- VPC or private endpoint: the control plane inside your AWS, Azure or GCP account with no public ingress.
- On-prem: open-weight models on hardware you own, with local operations and patching.
- Air-gapped: no internet egress, a local model registry and offline update channels for defence, government and critical infrastructure.
Key custody moves to you with BYOK via AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM. Audit logs capture model, tokens, latency, user and region per request and stream to your SIEM, with retention up to 7 years.
Evidence and audit for sovereign AI
Instead of assurances, security teams get documented programs: SOC 2 Type II under NDA, ISO 27001, HIPAA with a BAA, and GDPR/PDPL alignment. FedRAMP Moderate is in process — treat US federal work as pending. Enterprise agreements add a DPA with EU SCCs, sub-processor terms, right-to-audit clauses and custom SLAs.
For France-linked programmes, request the current evidence pack and sub-processor list; data-protection expectations vary by sector and regulator.
From pilot to air-gapped production
Begin with a single workload and a written definition of the sovereignty criteria in scope. Pick the deployment topology — cloud region, private cloud, on-prem or air-gapped — decide key custody, plan offline update and model-approval workflows for air-gapped sites, and test audit fields, SIEM export and retention against your policy.
Run the pilot, collect the evidence procurement needs, then move to production once controls are signed off. The API stays OpenAI-compatible and one key reaches 30+ models, so existing SDK code, prompts and evaluations carry over. New accounts start on the free plan with plugsky-micro and plugsky-lite, and a 14-day full-access trial covers higher tiers; see the live pricing page for current plans.
Honest comparison
| Capability | Plugsky | Typical global AI API | Building in-house |
|---|---|---|---|
| Sovereignty scope | Data, model, operations and compliance covered | Usually data location only | You must build and prove all four |
| Deployment models | Cloud region, VPC, on-prem, air-gapped | Shared public cloud only | Your own infrastructure only |
| Air-gapped mode | No internet egress, offline updates | Not offered | Custom engineering effort |
| Key custody | BYOK via KMS or on-prem HSM | Provider-managed keys | You operate the HSMs |
| Audit | Per-request logs with region; SIEM export; up to 7 years | Often limited retention | You build the pipeline |
| Local presence in Lyon | No facility claimed; sovereignty is deployment-based | Varies by provider | Depends on your own sites |
Frequently asked questions
Does Plugsky have a facility in Lyon?
No. Plugsky does not claim an office or data centre in Lyon; sovereign deployments are delivered as cloud regions, private environments or customer-owned infrastructure. See /data-residency for the current region list.
Can Plugsky run fully air-gapped?
Yes. Air-gapped deployments run with no internet egress, a local model registry and offline update channels, which suits defence, government and critical infrastructure programmes.
Who holds the encryption keys?
You can. BYOK is supported through AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM, with per-region envelope encryption for data at rest.
What compliance evidence can we review?
SOC 2 Type II under NDA, ISO 27001/27017/27018 and HIPAA with a BAA; FedRAMP Moderate is in process. Enterprise contracts add a DPA with EU SCCs, sub-processor terms and right-to-audit clauses.
Can we keep using the OpenAI SDK?
Yes. The API is OpenAI-compatible, so you change the base URL and model name and keep your existing SDK, prompts and evaluations.
How do we start a sovereign pilot?
Pick one workload, define the sovereignty criteria in writing, choose the deployment topology and key custody, then run the pilot and collect the evidence procurement needs. Teams in Lyon typically start on the free plan and use the 14-day full-access trial for larger models.
Which capabilities are live today?
Chat, streaming, JSON mode, function calling, embeddings, RAG and agents are live. Audio, images, moderation, files, batch, fine-tuning, assistants and responses are coming soon — check the docs before planning those workloads.
Would our data be used to train models?
No — prompts are not used to train models. For strict requirements, use a private, on-prem or air-gapped deployment so data stays inside the contracted environment.