AI Executive Office — CXO Assistant Platform · View 28 of 30 · 7 · Assurance
How it is enforced
- By policy and network, not by intent. Azure Policy at the management-group level denies resource creation outside the permitted region; the firewall denies egress that is not on the allow-list. A developer cannot accidentally deploy out of country
- Customer-managed keys in a managed HSM, with the customer holding them. Revoking the key makes the data unreadable, which is a meaningful sovereignty guarantee rather than a contractual one
- Customer Lockbox so vendor support access requires the customer's approval
What never leaves
- Prompts and completions, retrieved passages, business data and KPIs, decision and audit records
- What does leave, explicitly: service telemetry with no customer content, inbound threat intelligence, and build-time package feeds
- Each item maps to a named national information-assurance control with evidence, produced as a control matrix during detailed design
The open risk
- AI service and model SKU availability in a sovereign region is the constraint most likely to break this architecture, and it moves. Three fallbacks are pre-agreed: deploy the models the region has and accept a capability gap; place inference in a customer-approved alternative region under a data-boundary commitment; or defer the AI capability while the data platform ships. The choice is the customer's and belongs in the contract, not in a diagram