Key facts
| Sovereignty criteria | Data residency, model control, operational sovereignty and compliance alignment |
| Deployment models | Plugsky cloud region, VPC/private endpoint, on-prem and fully air-gapped |
| Region-locked planes | EU (Frankfurt), GCC (UAE and KSA), APAC (Singapore) and US (Virginia and Oregon); confirm the current list |
| Air-gapped mode | No internet egress, a local model registry and offline update channels |
| Key custody | BYOK via AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM |
| Audit | Per-request logs with region; SIEM export; retention up to 7 years |
| Compliance | SOC 2 Type II under NDA, ISO 27001, HIPAA with a BAA; FedRAMP Moderate in process |
| Local presence | No Amsterdam office or facility claimed; sovereignty is deployment-based |
TL;DR
- Amsterdam teams work under GDPR and the EU AI Act, so EEA processing and processor terms are design inputs.
- Plugsky publishes no Amsterdam facility; options are cloud regions, VPC, on-prem and air-gapped.
- BYOK keeps key custody with you via your KMS or an on-prem HSM.
- VPC and private-endpoint deployments keep the control plane inside your cloud account.
- One OpenAI-compatible API reaches 30+ models, so SDK code and prompts carry over.
How it works, step by step
- Define which sovereignty criteria your regulator, board or customer requires.
- Choose the deployment topology: cloud region, private cloud, on-prem or air-gapped.
- Decide key custody — managed KMS or an on-prem HSM with BYOK.
- Design offline update and model-approval workflows for air-gapped sites.
- Validate audit log fields, SIEM export and retention against your policy.
- Run a pilot on one workload and collect the evidence procurement needs.
- Move to production once the controls are signed off.
Try it yourself
Open the EU AI Act compliance checker →
The Amsterdam case for sovereign AI
Amsterdam is the capital of the Netherlands and one of Europe's densest digital and financial centres, with Schiphol airport and a large base of technology, fintech and logistics companies. Dutch and international organisations here operate under the EU's data protection regime, and many handle data that cannot leave the EEA without a legal basis. That makes deployment location and processor terms a first-order design decision rather than a legal afterthought.
Sovereign AI means data, models, compute and operations stay inside your jurisdiction and perimeter, with local administrators able to run, patch and audit the stack. Plugsky publishes no Amsterdam office or data centre; options and the current region list are at /data-residency.
Cloud, VPC, on-prem or air-gapped: what each proves
There are four deployment patterns to choose from in the Netherlands:
- Region-locked cloud: a pinned data plane — EU (Frankfurt), GCC (UAE and KSA), APAC (Singapore) or US (Virginia and Oregon); see /data-residency.
- VPC or private endpoint: runs inside your AWS, Azure or GCP account with no public ingress.
- On-prem: open-weight models on hardware you own, operated and patched locally.
- Air-gapped: no internet egress, a local model registry and offline update channels.
For the Netherlands teams, the Frankfurt plane keeps prompts, completions, embeddings and logs inside the EU; verify current availability at /data-residency before pinning production. BYOK keeps key custody with you via AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM, and per-request audit logs capture model, tokens, latency, user and region.
What procurement can verify
The review pack is evidence-based: SOC 2 Type II under NDA, ISO 27001/27017/27018, HIPAA with a BAA and GDPR alignment, with FedRAMP Moderate in process and pending for US federal use. Enterprise agreements add a DPA with EU SCCs, named sub-processors, right-to-audit clauses and custom SLAs.
In the EU, the GDPR governs personal data processing, the Dutch Autoriteit Persoonsgegevens supervises it in the Netherlands, and the EU AI Act adds obligations for AI systems placed on the EU market. Verify the current rules and your role under them with counsel.
Starting small: a sovereign pilot checklist
Pick one non-critical workload to prove the pattern. Write down the residency, model-control and audit requirements it must meet, choose the matching deployment topology and key-custody model, and rehearse the update path if the site is air-gapped. Check that logs carry the fields your policy expects and export cleanly to your SIEM before expanding scope.
Because the API is OpenAI-compatible, existing SDK code, prompts and evaluation harnesses keep working, and one key reaches 30+ models. New accounts can start on the free plan with plugsky-micro and plugsky-lite and a 14-day full-access trial; current plans are listed on the live pricing page.
Honest comparison
| Capability | Plugsky | Typical public-cloud AI | Building in-house |
|---|---|---|---|
| Sovereignty scope | Data, model, operations and compliance covered | Usually data location only | You must build and prove all four |
| Deployment models | Cloud region, VPC, on-prem, air-gapped | Shared public cloud only | Your own infrastructure only |
| Air-gapped mode | No internet egress, offline updates | Not offered | Custom engineering effort |
| Key custody | BYOK via KMS or on-prem HSM | Provider-managed keys | You operate the HSMs |
| Audit | Per-request logs with region; SIEM export; up to 7 years | Often limited retention | You build the pipeline |
| Local presence in Amsterdam | No facility claimed; sovereignty is deployment-based | Varies by provider | Depends on your own sites |
Frequently asked questions
Does Plugsky have a facility in Amsterdam?
No. Plugsky does not claim an office or data centre in Amsterdam; sovereign deployments are delivered as cloud regions, private environments or customer-owned infrastructure. See /data-residency for the current region list.
What makes a deployment sovereign?
Four criteria at once: data residency, model control, operational sovereignty and compliance alignment. Pinning storage to a region alone does not satisfy the full set.
Can Plugsky run fully air-gapped?
Yes. Air-gapped deployments run with no internet egress, a local model registry and offline update channels, which suits defence, government and critical infrastructure programmes.
Who holds the encryption keys?
You can. BYOK is supported through AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM, with per-region envelope encryption for data at rest.
What compliance evidence can we review?
SOC 2 Type II under NDA, ISO 27001/27017/27018 and HIPAA with a BAA; FedRAMP Moderate is in process. Enterprise contracts add a DPA with EU SCCs, sub-processor terms and right-to-audit clauses.
Can we keep using the OpenAI SDK?
Yes. The API is OpenAI-compatible, so you change the base URL and model name and keep your existing SDK, prompts and evaluations.
How do we start a sovereign pilot?
Pick one workload, define the sovereignty criteria in writing, choose the deployment topology and key custody, then run the pilot and collect the evidence procurement needs before production.
How does data protection law in the Netherlands affect deployment choice?
The GDPR governs personal data, and the EU AI Act adds obligations for AI systems placed on the EU market. Residency and processing-location requirements usually decide whether a hosted, VPC, on-prem or air-gapped pattern is acceptable.