Local / City

Can Medina enterprises keep AI data and models inside their jurisdiction?

Sovereign AI for Medina means data, models, compute and operations stay inside your jurisdiction and perimeter. Plugsky supports four deployment models — region-locked cloud planes, a private endpoint in your VPC, on-prem and fully air-gapped — with BYOK key custody, SIEM audit export and no internet egress on air-gapped sites. Plugsky publishes no Medina facility; see /data-residency for the current region list.

Key facts

Sovereignty criteriaData residency, model control, operational sovereignty and compliance alignment
Deployment modelsPlugsky cloud region, VPC/private endpoint, on-prem and fully air-gapped
Air-gapped modeNo internet egress, local model registry and offline update channels
Key custodyBYOK via AWS KMS, Azure Key Vault, HashiCorp Vault or on-prem HSM
AuditPer-request logs with region; SIEM export; retention up to 7 years
ComplianceSOC 2 Type II under NDA, ISO 27001, HIPAA with BAA; FedRAMP Moderate in process
API compatibilityOpenAI-compatible /v1/chat/completions; change the base URL
Local presenceNo Medina office or facility claimed; sovereignty is delivered by deployment model

TL;DR

  • Plugsky claims no Medina facility; control comes from the deployment topology.
  • Sovereignty covers data, models, operations and compliance — not just server location.
  • Deploy in a pinned cloud region, your VPC, your data centre or an air-gapped site.
  • Air-gapped sites run with no internet egress and offline update channels.
  • BYOK through your KMS or HSM, plus per-request audit logs for review.

How it works, step by step

  1. Map your Medina data flows and define the required residency boundary.
  2. Choose region-locked cloud, a private VPC endpoint, on-prem or air-gapped deployment.
  3. Choose between managed KMS and an on-prem HSM for key custody.
  4. Design offline update and model-approval processes for air-gapped sites.
  5. Test audit log fields, SIEM export and retention against your policy.
  6. Run one workload as a pilot and collect the evidence procurement needs.
  7. Move to production once controls are signed off.
1Map your Medinadata flows anddefine the required2Chooseregion-lockedcloud, a private3Choose betweenmanaged KMS and anon-prem HSM for key4Design offlineupdate andmodel-approval5Test audit logfields, SIEM exportand retention6Run one workload asa pilot and collectthe evidence

Original data

Per-request loAuditSOC 2 Type II ComplianceOpenAI-compatiAPI compatibilitySource: Plugsky facts table · updated 2026-09-26

Try it yourself

Open the private LLM deployment estimator →

Why Medina organisations need sovereign deployment

Medina is home to Al-Masjid an-Nabawi and is a major centre of pilgrimage, Islamic learning and date agriculture in Saudi Arabia's Hejaz region. The institutions that serve pilgrims and residents need AI that keeps personal data inside the Kingdom.

For Medina organisations in hospitality, education and agriculture, the driver is control: AI that meets data residency, model control, operational sovereignty and compliance at the same time. A storage-region promise alone does not clear that bar.

That means prompts, completions, embeddings, fine-tuned models and logs remain inside your legal jurisdiction and physical perimeter, with local administrators able to run, patch and audit the stack themselves. Plugsky publishes no Medina facility; sovereign deployments are delivered as cloud regions, private environments or customer-owned infrastructure — see the data-residency overview for the current region list.

Sovereign deployment options for Medina

Plugsky ships four deployment patterns for sovereign programmes:

  • Region-locked cloud: a pinned data plane in the region you select; the current region list is published at /data-residency.
  • VPC or private endpoint: the control plane inside your AWS, Azure or GCP account with no public ingress.
  • On-prem: open-weight models on hardware you own, with local operations and patching.
  • Air-gapped: no internet egress, a local model registry and offline update channels for defence, government and critical infrastructure.

BYOK keeps encryption keys with you — AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM — while per-request audit logs record model, tokens, latency, user and region and export to your SIEM, retaining data for up to 7 years.

Evidence and audit for sovereign AI

Procurement and security teams can review documented programs rather than assurances: SOC 2 Type II under NDA, ISO 27001, HIPAA with a BAA, and GDPR/PDPL alignment. FedRAMP Moderate is in process, so treat it as pending. Enterprise contracts add a DPA with EU SCCs, sub-processor terms, right-to-audit clauses and custom SLAs.

For Saudi Arabia-linked programmes, request the current evidence pack and sub-processor list; data-protection expectations vary by sector and regulator.

From pilot to air-gapped production

Start with one workload and a written definition of the sovereignty criteria that apply. Choose the deployment topology — cloud region, private cloud, on-prem or air-gapped — settle key custody, design offline update and model-approval workflows for air-gapped sites, then validate audit fields, SIEM export and retention against policy.

Run the pilot, collect the evidence procurement needs, then move to production once controls are signed off. The API stays OpenAI-compatible and one key reaches 30+ models, so existing SDK code, prompts and evaluations carry over. New accounts start on the free plan with plugsky-micro and plugsky-lite, and a 14-day full-access trial covers higher tiers; see the live pricing page for current plans.

Honest comparison

CapabilityPlugskyTypical public-cloud providerBuilding in-house
Sovereignty scopeData, model, operations and compliance coveredUsually data location onlyYou must build and prove all four
Deployment modelsCloud region, VPC, on-prem, air-gappedShared public cloud onlyYour own infrastructure only
Air-gapped modeNo internet egress, offline updatesNot offeredCustom engineering effort
Key custodyBYOK via KMS or on-prem HSMProvider-managed keysYou operate the HSMs
AuditPer-request logs with region; SIEM export; up to 7 yearsOften limited retentionYou build the pipeline
Local presence in MedinaNo facility claimed; sovereignty is deployment-basedVaries by providerDepends on your own sites

Frequently asked questions

Does Plugsky have a facility in Medina?

No. Plugsky does not claim an office or data centre in Medina; sovereign deployments are delivered as cloud regions, private environments or customer-owned infrastructure. See /data-residency for the current region list.

Who holds the encryption keys?

You can. BYOK is supported through AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM, with per-region envelope encryption for data at rest.

What compliance evidence can we review?

SOC 2 Type II under NDA, ISO 27001/27017/27018 and HIPAA with a BAA; FedRAMP Moderate is in process. Enterprise contracts add a DPA with EU SCCs, sub-processor terms and right-to-audit clauses.

Can we keep using the OpenAI SDK?

Yes. The API is OpenAI-compatible, so you change the base URL and model name and keep your existing SDK, prompts and evaluations.

How do we start a sovereign pilot?

Pick one workload, define the sovereignty criteria in writing, choose the deployment topology and key custody, then run the pilot and collect the evidence procurement needs. Teams in Medina typically start on the free plan and use the 14-day full-access trial for larger models.

Which capabilities are live today?

Chat, streaming, JSON mode, function calling, embeddings, RAG and agents are live. Audio, images, moderation, files, batch, fine-tuning, assistants and responses are coming soon — check the docs before planning those workloads.

Would our data be used to train models?

No — prompts are not used to train models. For strict requirements, use a private, on-prem or air-gapped deployment so data stays inside the contracted environment.

How is pricing structured?

Self-serve plans are flat monthly with unlimited fair-use usage and no per-token billing. See the live pricing page for current plans and fair-use limits.