Engineered to your environment.Sovereignby construction.
The Sovereignty Infinium is delivered in five deployment models — Sovereign On-Premise, Hybrid, Sovereign Cloud, Multi-Region Active-Active, and Air-Gapped. All five deliver the same capabilities. The difference is where the data lives, where the processing happens, and who holds the keys. Sovereignty is a property of the storage layer, the processing layer, and the egress layer — and the platform enforces it at all three.
5 DEPLOYMENT MODELS
BYOK / HYOK
ZERO THIRD-COUNTRY EXPORT
ZERO-TRUST
5-LEVEL CLASSIFICATION
The five deployment models.
All five models deliver the same capabilities. The difference is deployment topology, not capability set.
Sovereign On-Premise
- Residency
- Client hardware, client jurisdiction
- Processing
- Client hardware
- Egress
- None (or tightly controlled)
- Best fit
- Highest-sensitivity, no internet egress
Hybrid
- Residency
- Client HSM (sensitive); sovereign cloud (rest)
- Processing
- Sovereign cloud
- Egress
- Controlled
- Best fit
- Sensitive data in-country; GPU burst to approved cloud
Sovereign Cloud
- Residency
- Sovereign cloud provider, regional
- Processing
- Sovereign cloud
- Egress
- Cryptographic enforcement
- Best fit
- Data residency guaranteed by sovereign provider
Multi-Region Active-Active
- Residency
- Multi-region sovereign cloud
- Processing
- Multi-region
- Egress
- Cross-region encrypted
- Best fit
- HA/DR, follow-the-sun 24/7
Air-Gapped
- Residency
- Client hardware, isolated
- Processing
- Client hardware
- Egress
- None (physically)
- Best fit
- Tactical, classified, no network
The highest-sovereignty model.
The full platform runs on client hardware, in the client's jurisdiction, with no internet egress. The client owns the hardware, the HSM, the keys, and the data.
Client Datacenter (jurisdiction-controlled)
L1–L5
Compute cluster 1
L1–L5
Compute cluster 2
L1–L5
Compute cluster 3
L1–L5
Compute cluster 4
HSM (BYOK / HYOK)
Master Keys
No internet egress · No third-country export · No vendor reach-in
Capabilities
- Full platform — all 15+ INTs, all 10 temporal dimensions, all 8 predictive horizons
- All five classification levels — Public to Top Secret
- All seven planes — Identity, Security, Observability, Governance, Ethics, DevSecOps, Multi-Tenancy
- Full DevSecOps — software delivered as signed artifacts; updates via physically-delivered media or controlled update server
Operational considerations
- Hardware footprint
- Substantial. Compute cluster, storage cluster, network, HSM
- Engineering support
- High. The client must staff or contract for sovereign deployment engineering
- Update cadence
- Slower than cloud. Updates delivered as signed bundles on physical media or via approved update channel
- Scalability
- Limited to on-prem capacity. Capacity planning is the client's responsibility
- Disaster recovery
- Client's responsibility. The platform supports geo-replicated on-prem configuration
- Compliance
- Strongest possible. Data never leaves the client's jurisdiction
When to choose this model
- National intelligence agencies, defense ministries, sovereign clients with the highest sensitivity requirements
- Environments with regulatory or statutory requirements prohibiting any third-country data export
- Environments with no acceptable internet egress
- Environments where the client prefers to own the full stack
Sensitive data sovereign, GPU elastic.
Sensitive data stays in the client's HSM (on-prem or in a sovereign enclave). GPU-intensive processing bursts to an approved sovereign cloud.
Client Enclave (jurisdiction-controlled)
Sensitive Data
HSM (BYOK)
Encrypted payload only (no plaintext egress)
Sovereign Cloud (jurisdiction-controlled)
Burst Compute (GPU)
- · Training
- · Large NLP
- · Vector search at scale
- · War-gaming simulation
Encrypted result → Client decrypts in enclave
Capabilities
- Full platform — same as on-prem
- Sensitive data never leaves the enclave — only encrypted features, embeddings, or task payloads are sent to the cloud
- Cloud-side processing is stateless — no persistent storage of client data
- Cryptographic separation — cloud sees ciphertext only; client holds the keys
Operational considerations
- Latency
- Slightly higher than on-prem (egress to cloud and back)
- Engineering support
- High. Hybrid configurations require careful cryptographic design
- Update cadence
- Faster than on-prem. Cloud-side updates are continuous
- Scalability
- Elastic. GPU burst scales with workload
- Compliance
- Strong. Data residency enforced cryptographically; processing residency enforced contractually
- Cost
- Lower than on-prem for GPU-intensive workloads; higher than pure cloud
When to choose this model
- Sovereign clients with significant GPU/ML workloads that exceed on-prem capacity
- Environments where the cost of full on-prem is prohibitive but the cost of data exposure is too high
- Environments where burst capacity (e.g., during a crisis) is a requirement
Regional, provider-managed, single-tenant.
The platform is deployed in a regional sovereign cloud provider, with cryptographic enforcement of data residency.
Sovereign Cloud Region (jurisdiction-controlled)
L1–L5 Stack
Single-tenant · Primary
L1–L5 Stack
Single-tenant · Secondary
L1–L5 Stack
Single-tenant · Tertiary
HSM (HYOK)
Client Keys
Cryptographic enforcement · No third-region export
Capabilities
- Full platform — same as on-prem
- Single-tenant regional deployment — the client does not share infrastructure with other tenants
- HSM-anchored client keys — HYOK supported; master keys in client-controlled HSM
- Sovereign provider's regional compliance — provider's regional certifications inherited (FedRAMP, C5, IRAP, etc.)
Operational considerations
- Latency
- Low. Within-region compute and storage
- Engineering support
- Medium. Lower than on-prem; higher than multi-tenant SaaS
- Update cadence
- Fast. Continuous deployment within the region
- Scalability
- High. Provider's elastic capacity
- Compliance
- Strong. Regional provider's certifications + cryptographic enforcement
- Cost
- Higher than multi-tenant SaaS (single-tenant). Lower than on-prem at scale
When to choose this model
- Sovereign clients in jurisdictions with trusted regional cloud providers
- Environments that want cloud elasticity without the data-residency risk of multi-region global cloud
- Environments that want provider-managed infrastructure with sovereign-data control
99.9999% uptime · follow-the-sun 24/7.
Deployed across multiple sovereign cloud regions in active-active configuration, with continuous operations and cryptographic cross-region isolation.
Region A
L1–L5 (active)
- · ingest
- · process
- · serve
HSM (per-region)
Region B
L1–L5 (active)
- · ingest
- · process
- · serve
HSM (per-region)
Region C (optional)
L1–L5 (active)
- · ingest
- · process
- · serve
HSM (per-region)
Active-active · Cross-region encryption · No data replication outside jurisdiction
Capabilities
- Full platform — same as on-prem
- Active-active — multiple regions serve traffic simultaneously
- 99.9999% operational uptime — verified per SLO
- Follow-the-sun 24/7 ops — operators in different time zones use their regional deployment
- Cryptographic cross-region separation — regions do not share plaintext
Operational considerations
- Latency
- Low. Region-local for clients in the region
- Engineering support
- High. Multi-region orchestration is non-trivial
- Update cadence
- Fast. Canary across regions; rollback supported
- Scalability
- Highest. Multi-region elasticity
- Compliance
- Strong. Per-region data residency; cross-region only with cryptographic isolation
- Cost
- Highest of the cloud-based models. Single-tenant per region × multiple regions
When to choose this model
- Sovereign clients with global operations
- Environments with strict uptime requirements (24/7/365)
- Environments that need DR/HA without sacrificing sovereignty
- Environments that need follow-the-sun operations
Absolute sovereignty. No network.
The most restrictive deployment. Updates are delivered via physically-transported signed media. This is the model for tactical, classified, and no-network environments.
Air-Gapped Enclave (no network)
L1–L5
Compute
L1–L5
Storage
HSM
Offline
Updates: physically-delivered signed media
No network egress. No network ingress. Physical isolation.
Capabilities
- Full platform — same as on-prem
- All five classification levels — including Top Secret / compartmented
- All seven planes — including air-gap-aware security
- Updates via signed media — every update bundle is signed, verified on ingest, and logged
- No telemetry egress — by design
Operational considerations
- Latency
- Lowest. No network round-trips
- Engineering support
- Highest. Air-gapped operations are non-trivial
- Update cadence
- Slowest. Updates require physical media transport
- Scalability
- Limited to enclave capacity
- Compliance
- Highest possible. No network, no telemetry, no egress
- Cost
- High. Hardware footprint + air-gap operations
When to choose this model
- Tactical, field, embassy, deployed operations
- Classified environments with statutory no-network requirements
- Environments with absolute sovereignty requirements that preclude even sovereign cloud
Choosing a model, by axis.
| Axis | Sovereign On-Premise | Hybrid | Sovereign Cloud | Multi-Region Active-Active | Air-Gapped |
|---|---|---|---|---|---|
| Sovereignty | Highest | High | High | High | Highest |
| Elasticity | Lowest | High | High | Highest | Lowest |
| Uptime | 99.99% (single site) | 99.99% | 99.99% | 99.9999% | 99.99% (single site) |
| Update cadence | Slowest | Fast | Fast | Fastest | Slowest |
| Engineering burden | Highest | High | Medium | High | Highest |
| Cost | Highest at scale | Medium | Medium-high | High | High |
| Compliance inheritance | Self-managed | Self-managed + cloud | Provider-managed | Provider-managed + per-region | Self-managed |
| Crisis readiness | Site-dependent | Strong | Strong | Strongest | Site-dependent |
| Multi-jurisdiction | No | Possible | Per-region | Yes | No |
Top-secret, no-network, single-jurisdiction
→ Air-Gapped or Sovereign On-Premise
Top-secret, multi-jurisdiction, sovereignty-per-region
→ Multi-Region Active-Active
High-sensitivity, GPU-intensive, multi-jurisdiction
→ Hybrid
Standard sovereign, elastic, regional
→ Sovereign Cloud
Tactical, deployed, classified
→ Air-Gapped (forward-deployed variant)
Global, 24/7/365, sovereign
→ Multi-Region Active-Active
Common across all five models.
Customer-controlled keys (BYOK / HYOK)
All five models support customer-controlled keys. The master keys never leave the client's HSM. The platform uses envelope encryption; the client holds the key-encryption key. Zero-knowledge architecture is supported.
Identity and access
All five models use the same identity and access model: SSO, MFA, RBAC, ABAC, PBAC, JIT, PAM. The integration with the client's identity provider (IdP) is supported and recommended.
Observability
All five models expose the same observability surface: metrics, logs, traces, audit, SLO/SLI. The client owns the observability data; the platform's observability is delivered to the client's monitoring stack.
DevSecOps
All five models support the same DevSecOps workflow: CI/CD, SBOM, SAST/DAST, signed artifacts, blue/green deployment, canary release. The deployment topology is per-model; the workflow is uniform.
Multi-tenancy
In all five models, the platform is single-tenant per client. For internal multi-tenancy within a client organization, the platform supports tenant-aware isolation at the application layer.
Per compliance × model.
| Compliance | On-Prem | Hybrid | Sovereign Cloud | Multi-Region | Air-Gapped |
|---|---|---|---|---|---|
| GDPR | Self | Self | Provider | Provider | Self |
| CCPA/CPRA | Self | Self | Provider | Provider | Self |
| HIPAA | Self | Self | Provider | Provider | Self |
| SOX | Self | Self | Provider | Provider | Self |
| PCI-DSS | Self | Self | Provider | Provider | Self |
| FedRAMP | Self | Self | Provider | Provider | Self |
| ISO 27001 | Self | Self | Provider | Provider | Self |
| SOC 2 Type II | Self | Self | Provider | Provider | Self |
| FIPS 140-3 | Client HSM | Client HSM | Client HSM | Client HSM | Client HSM |
| Common Criteria EAL5+ | Client HSM | Client HSM | Client HSM | Client HSM | Client HSM |
| Regional equivalents | Self | Self | Provider | Provider | Self |
Updates, per model.
Sovereign On-Prem
Channel
Physically-delivered signed media
Cadence
Quarterly or per-release
Hybrid
Channel
Encrypted channel to client enclave
Cadence
Monthly or per-release
Sovereign Cloud
Channel
In-region deployment pipeline
Cadence
Continuous (canary)
Multi-Region
Channel
Per-region pipeline
Cadence
Continuous (canary per region)
Air-Gapped
Channel
Physically-delivered signed media
Cadence
Quarterly or per-release
The deployment models are candid about their limits.
On-Prem and Air-Gapped scale with the client's hardware. Capacity planning is the client's responsibility.
Hybrid requires careful cryptographic design. The cryptographic separation is the security boundary; misconfiguration compromises the model.
Sovereign Cloud depends on the provider's sovereignty. If the provider's sovereignty is compromised, the deployment's sovereignty is compromised. The platform mitigates through HSM-anchored keys and zero-knowledge architecture.
Multi-Region requires multi-jurisdiction contractual arrangements. The client must hold sovereign-cloud contracts in each region.
Air-Gapped is the slowest to update. This is by design. Adversaries do evolve; the platform supports scheduled, validated update windows.
Cost varies widely. A full Sovereign On-Premise deployment is a multi-year capital project. A Multi-Region Active-Active deployment is a multi-year operating expense.
Operational properties, per model.
On-Prem
Highest sovereignty
Highest engineering burden
Hybrid
Sensitive data sovereign
GPU elastic
Sovereign Cloud
Regional provider-managed
Single-tenant
Multi-Region
99.9999% uptime
Follow-the-sun
Air-Gapped
Absolute sovereignty
No network
An integrated intelligence infrastructure — five layers, seven planes, five deployment models, fifteen INTs, ten temporal dimensions.
One commitment: deliver decision-grade intelligence to sovereign clients faster, deeper, and with greater foresight than their adversaries. A confidential briefing is the first step.
Request a Confidential BriefingThe briefing is free · The conversation is confidential · The work is sovereign