Sovereignty is not a stricter firewall. It is a different set of first principles: every capability the platform offers must be explainable, reproducible and operable by the organisation that owns it — indefinitely, without permission from anyone outside the border.
Sovereignty requirements, made concrete
- Data never leaves the jurisdiction — including embeddings, logs and telemetry, which are data wearing disguises.
- Models are owned artefacts: importable, signable, reproducible — never a dependency on someone else's API staying up.
- Every operational skill required to run the platform exists in-house or is contractually transferable.
- The audit story is self-contained: evidence is produced by the platform, not requested from a vendor.
The offline model lifecycle
Models move through the same lifecycle as any controlled artefact: acquisition through a supervised transfer zone, verification of provenance and signature, internal registry, staged promotion with evaluation gates, and retirement with records. Fine-tuning happens inside the border, on governed corpora, producing weights with the same custody chain as their base model.
Network and trust boundaries
The architecture assumes three zones: the transfer zone (the only place outside artefacts appear), the platform core (registries, reconciliation, policy, observability), and the inference planes serving workloads. Trust flows one way — inward artefacts are verified at the boundary, and nothing in the core ever initiates outward.
Transfer zone
The only place outside artefacts appear.
- Supervised import
- Checksums and signatures
- Provenance record
- Named accountable human
Platform core
Reconciles from internal Git; never initiates outward.
- Internal registry
- Reconciliation
- Policy
- Observability
- Model lifecycle and retirement
Inference planes
Serving and fine-tuning inside the border, on governed corpora.
- Serving per team
- Fine-tuning inside the border
- Governed corpora
- Audit: which model, which version, which team, since when
RuleModel weights are controlled material: known origin, sealed transport, chain of custody, and no unaccounted copies.
Operations and audit
Everything reconciles from internal Git, so operations inside the gap feel identical to operations anywhere else — declare, commit, converge. The audit surface is a byproduct: which model, which version, serving which team, on which data, since when. When the regulator asks, the answer is a query, not a project.
Sovereign constraints are usually framed as a tax. Built this way, they become the pitch: a platform whose every capability is owned, explained and provable — which is what 'enterprise-grade AI' should have meant all along.