AI Executive Office — CXO Assistant Platform (On-Premises)  ·  View 28 of 30  ·  7 · Assurance

Sovereignty and Residency

What stays in country, the short list of what is allowed out, and the constraint that could invalidate the design.

Editable source SVG draw.io All views
In country — the enterprise data centre, customer-held keys Data at rest Object store encrypted · Vault key Decision store encrypted · Vault key Search index encrypted · Vault key Evidence immutable + CMK Logs in-site cluster Processing Model inference on-site GPUs Embedding on-site ML training on-site compute Application compute on-site Key and identity control Vault + HSM customer holds the key Break-glass approval vendor access logged JIT access no standing admin Allowed out — explicitly, and only these Vendor support bundles no customer content Threat intelligence signatures in Mirrored package feeds build time only Never leaves the boundary Prompts and completions Retrieved passages Business data and KPIs Decision and audit records Control framework mapping evidence per control GPU supply is the open risk size and order before signing revoke = unreadable declared Sovereignty — What Stays In Country, and What Is Allowed Out Data store Application we own Security / platform Interface / broker Risk / gap External / third party synchronous batch Residency is a physical property here — the estate has no cloud plane at all. Admission control refuses any workload without a residency label, and the firewall denies every egress that is not on the list. v 1.0 · owner Data & AI Global Practice · date 2026-09

How it is enforced

  • By physics first, then by policy. There is no cloud plane to leak into: every process runs on hardware the customer owns and can point at. Admission control refuses any workload without a residency label, and the perimeter firewall denies egress that is not on the allow-list, so an air-gapped deployment is a configuration rather than a different architecture
  • Per-tenant keys held in the customer’s own HSM and issued through Vault, with no vendor copy anywhere. Revoking the key makes the data unreadable, which is a meaningful sovereignty guarantee rather than a contractual one
  • Break-glass vendor access is requested, approved by the customer, time-boxed and screen-recorded

What never leaves

  • Prompts and completions, retrieved passages, business data and KPIs, decision and audit records
  • What does leave, explicitly: service telemetry with no customer content, inbound threat intelligence, and build-time package feeds
  • Each item maps to a named national information-assurance control with evidence, produced as a control matrix during detailed design

The open risk

  • GPU availability is the constraint most likely to break this architecture: accelerators are ordered months ahead and a dense rack may exceed what the hall can power or cool. Three fallbacks are pre-agreed: run a smaller open-weight model on the accelerators actually available and accept a capability gap; place inference on a customer-approved hosted endpoint under a written data-boundary commitment; or defer the AI capability while the data platform ships. The choice is the customer's and belongs in the contract, not in a diagram