Local / City

Which sovereign AI deployment option fits Zurich?

Sovereign AI for Zurich is about four things at once: data residency, model control, operational sovereignty and compliance alignment. Plugsky delivers them through region-locked cloud planes, a VPC private endpoint, on-prem or fully air-gapped deployment, with BYOK key custody and per-request audit logs. Plugsky claims no Zurich facility — see /data-residency for the current region list.

Key facts

Sovereignty criteriaData residency, model control, operational sovereignty and compliance alignment
Deployment modelsPlugsky cloud region, VPC/private endpoint, on-prem and fully air-gapped
Air-gapped modeNo internet egress, local model registry and offline update channels
Key custodyBYOK via AWS KMS, Azure Key Vault, HashiCorp Vault or on-prem HSM
AuditPer-request logs with region; SIEM export; retention up to 7 years
ComplianceSOC 2 Type II under NDA, ISO 27001, HIPAA with BAA; FedRAMP Moderate in process
API compatibilityOpenAI-compatible /v1/chat/completions; change the base URL
Local presenceNo Zurich office or facility claimed; sovereignty is delivered by deployment model

TL;DR

  • Plugsky publishes no Zurich facility; sovereignty comes from deployment topology.
  • Air-gapped sites run with no internet egress, a local model registry and offline updates.
  • SOC 2 Type II, ISO 27001 and HIPAA evidence support review; FedRAMP Moderate is in process.
  • Start on the free plan with plugsky-micro and plugsky-lite, or a 14-day full-access trial.

How it works, step by step

  1. Write down the sovereignty criteria first: residency, model control, operations and compliance.
  2. Pick the topology that matches those criteria — cloud region, VPC, on-prem or air-gapped.
  3. Settle key custody and rotation with AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM.
  4. Document how patches, model updates and approvals reach an air-gapped site.
  5. Confirm what your audit logs record and how long they are retained.
  6. Pilot one workload and hand procurement the evidence it asks for.
  7. Expand to production after security and compliance sign-off.
1Write down thesovereigntycriteria first:2Pick the topologythat matches thosecriteria — cloud3Settle key custodyand rotation withAWS KMS, Azure Key4Document howpatches, modelupdates and5Confirm what youraudit logs recordand how long they6Pilot one workloadand handprocurement the

Original data

Per-request loAuditSOC 2 Type II ComplianceOpenAI-compatiAPI compatibilitySource: Plugsky facts table · updated 2026-09-26

Try it yourself

Open the EU AI Act compliance checker →

The Zurich case for sovereign AI

Zurich is Switzerland's largest city and its banking and insurance centre, with a strong privacy culture and a growing fintech scene. Organisations here — banks and insurers, fintech firms and legal and professional-services companies — need AI that passes four tests at once: data residency, model control, operational sovereignty and compliance alignment.

Sovereign AI means prompts, completions, embeddings, models and logs stay inside your jurisdiction and perimeter, with local administrators able to run, patch and audit the stack. Plugsky publishes no Zurich facility; deployments ship as cloud regions, private environments or customer-owned infrastructure — see the data-residency overview.

Cloud, VPC, on-prem or air-gapped: options for Zurich

Plugsky ships four deployment patterns for sovereign programmes:

  • Region-locked cloud: a pinned plane in the EU (Frankfurt), GCC (UAE and KSA), APAC (Singapore) or US (Virginia and Oregon). Plugsky does not publish a Swiss plane; the nearest documented option is EU (Frankfurt), and where Swiss residency is mandatory use a VPC, on-prem or air-gapped deployment.
  • VPC or private endpoint: the control plane inside your AWS, Azure or GCP account with no public ingress.
  • On-prem: open-weight models on hardware you own, with local operations and patching.
  • Air-gapped: no internet egress, a local model registry and offline update channels.

Keys stay with you through BYOK in AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM; per-request audit logs capture model, tokens, latency, user and region, and export to your SIEM with retention up to 7 years.

What procurement can verify

Procurement and security teams can review documented programmes rather than assurances: SOC 2 Type II under NDA, ISO 27001, HIPAA with a BAA, and GDPR/PDPL alignment, with a DPA, EU SCCs, sub-processor terms and right-to-audit clauses in enterprise contracts. FedRAMP Moderate is in process, so treat it as pending for US federal work.

For Swiss programmes, FADP expectations apply; a DPA with EU SCCs is available, and where Swiss residency is mandatory choose a private deployment.

From sovereign pilot to production

Start with one workload and a written definition of the sovereignty criteria. Choose the deployment topology and key custody, design offline update and model-approval workflows for air-gapped sites, and validate audit fields, SIEM export and retention against policy. Run the pilot, collect the evidence procurement needs, then move to production once controls are signed off.

The API stays OpenAI-compatible and one key reaches 30+ models, so existing SDK code, prompts and evaluations carry over. New accounts start on the free plan with plugsky-micro and plugsky-lite and a 14-day full-access trial; see the live pricing page for plans.

Honest comparison

CapabilityPlugskyTypical public-cloud AIBuilding in-house
Sovereignty scopeData, model, operations and compliance coveredUsually data location onlyYou must build and prove all four
Deployment modelsCloud region, VPC, on-prem, air-gappedShared public cloud onlyYour own infrastructure only
Air-gapped modeNo internet egress, offline updatesNot offeredCustom engineering effort
Key custodyBYOK via KMS or on-prem HSMProvider-managed keysYou operate the HSMs
AuditPer-request logs with region; SIEM export; up to 7 yearsOften limited retentionYou build the pipeline
Local presence in ZurichNo facility claimed; sovereignty is deployment-basedVaries by providerDepends on your own sites

Frequently asked questions

Does Plugsky have a facility in Zurich?

No. Plugsky does not claim an office or data centre in Zurich; sovereign deployments are delivered as cloud regions, private environments or customer-owned infrastructure. See /data-residency for the current region list.

What makes a deployment sovereign?

Four criteria at once: data residency, model control, operational sovereignty and compliance alignment. A deployment that only pins storage to a region does not satisfy the full set.

Can Plugsky run fully air-gapped?

Yes. Air-gapped deployments run with no internet egress, a local model registry and offline update channels, which suits defence, government and critical infrastructure programmes.

Who holds the encryption keys?

You can. BYOK is supported through AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM, with per-region envelope encryption for data at rest.

What compliance evidence can we review?

SOC 2 Type II under NDA, ISO 27001/27017/27018 and HIPAA with a BAA; FedRAMP Moderate is in process. Enterprise contracts add a DPA with EU SCCs, sub-processor terms and right-to-audit clauses.

Can we keep using the OpenAI SDK?

Yes. The API is OpenAI-compatible, so you change the base URL and model name and keep your existing SDK, prompts and evaluations.

Which endpoints are still coming soon?

Audio, images, moderation, files, batch and fine-tuning are coming soon; chat, streaming, JSON mode, function calling, embeddings and RAG are live.

Would our data be used to train models?

No — prompts are not used to train models. For strict requirements, use a private, on-prem or air-gapped deployment so data stays inside the contracted environment.