HOW IT WORKS / DEPLOYMENT

Engineered to your environment.Sovereignby construction.

The Sovereignty Infinium is delivered in five deployment models — Sovereign On-Premise, Hybrid, Sovereign Cloud, Multi-Region Active-Active, and Air-Gapped. All five deliver the same capabilities. The difference is where the data lives, where the processing happens, and who holds the keys. Sovereignty is a property of the storage layer, the processing layer, and the egress layer — and the platform enforces it at all three.

5 DEPLOYMENT MODELS

BYOK / HYOK

ZERO THIRD-COUNTRY EXPORT

ZERO-TRUST

5-LEVEL CLASSIFICATION

The Five Models

The five deployment models.

All five models deliver the same capabilities. The difference is deployment topology, not capability set.

01 / 05

Sovereign On-Premise

Residency
Client hardware, client jurisdiction
Processing
Client hardware
Egress
None (or tightly controlled)
Best fit
Highest-sensitivity, no internet egress
02 / 05

Hybrid

Residency
Client HSM (sensitive); sovereign cloud (rest)
Processing
Sovereign cloud
Egress
Controlled
Best fit
Sensitive data in-country; GPU burst to approved cloud
03 / 05

Sovereign Cloud

Residency
Sovereign cloud provider, regional
Processing
Sovereign cloud
Egress
Cryptographic enforcement
Best fit
Data residency guaranteed by sovereign provider
04 / 05

Multi-Region Active-Active

Residency
Multi-region sovereign cloud
Processing
Multi-region
Egress
Cross-region encrypted
Best fit
HA/DR, follow-the-sun 24/7
05 / 05

Air-Gapped

Residency
Client hardware, isolated
Processing
Client hardware
Egress
None (physically)
Best fit
Tactical, classified, no network
01 · Sovereign On-Premise

The highest-sovereignty model.

The full platform runs on client hardware, in the client's jurisdiction, with no internet egress. The client owns the hardware, the HSM, the keys, and the data.

Client Datacenter (jurisdiction-controlled)

L1–L5

Compute cluster 1

L1–L5

Compute cluster 2

L1–L5

Compute cluster 3

L1–L5

Compute cluster 4

HSM (BYOK / HYOK)

Master Keys

No internet egress · No third-country export · No vendor reach-in

Capabilities

  • Full platform — all 15+ INTs, all 10 temporal dimensions, all 8 predictive horizons
  • All five classification levels — Public to Top Secret
  • All seven planes — Identity, Security, Observability, Governance, Ethics, DevSecOps, Multi-Tenancy
  • Full DevSecOps — software delivered as signed artifacts; updates via physically-delivered media or controlled update server

Operational considerations

Hardware footprint
Substantial. Compute cluster, storage cluster, network, HSM
Engineering support
High. The client must staff or contract for sovereign deployment engineering
Update cadence
Slower than cloud. Updates delivered as signed bundles on physical media or via approved update channel
Scalability
Limited to on-prem capacity. Capacity planning is the client's responsibility
Disaster recovery
Client's responsibility. The platform supports geo-replicated on-prem configuration
Compliance
Strongest possible. Data never leaves the client's jurisdiction

When to choose this model

  • National intelligence agencies, defense ministries, sovereign clients with the highest sensitivity requirements
  • Environments with regulatory or statutory requirements prohibiting any third-country data export
  • Environments with no acceptable internet egress
  • Environments where the client prefers to own the full stack
02 · Hybrid

Sensitive data sovereign, GPU elastic.

Sensitive data stays in the client's HSM (on-prem or in a sovereign enclave). GPU-intensive processing bursts to an approved sovereign cloud.

Client Enclave (jurisdiction-controlled)

Sensitive Data

HSM (BYOK)

Encrypted payload only (no plaintext egress)

Sovereign Cloud (jurisdiction-controlled)

Burst Compute (GPU)

  • · Training
  • · Large NLP
  • · Vector search at scale
  • · War-gaming simulation

Encrypted result → Client decrypts in enclave

Capabilities

  • Full platform — same as on-prem
  • Sensitive data never leaves the enclave — only encrypted features, embeddings, or task payloads are sent to the cloud
  • Cloud-side processing is stateless — no persistent storage of client data
  • Cryptographic separation — cloud sees ciphertext only; client holds the keys

Operational considerations

Latency
Slightly higher than on-prem (egress to cloud and back)
Engineering support
High. Hybrid configurations require careful cryptographic design
Update cadence
Faster than on-prem. Cloud-side updates are continuous
Scalability
Elastic. GPU burst scales with workload
Compliance
Strong. Data residency enforced cryptographically; processing residency enforced contractually
Cost
Lower than on-prem for GPU-intensive workloads; higher than pure cloud

When to choose this model

  • Sovereign clients with significant GPU/ML workloads that exceed on-prem capacity
  • Environments where the cost of full on-prem is prohibitive but the cost of data exposure is too high
  • Environments where burst capacity (e.g., during a crisis) is a requirement
03 · Sovereign Cloud

Regional, provider-managed, single-tenant.

The platform is deployed in a regional sovereign cloud provider, with cryptographic enforcement of data residency.

Sovereign Cloud Region (jurisdiction-controlled)

L1–L5 Stack

Single-tenant · Primary

L1–L5 Stack

Single-tenant · Secondary

L1–L5 Stack

Single-tenant · Tertiary

HSM (HYOK)

Client Keys

Cryptographic enforcement · No third-region export

Capabilities

  • Full platform — same as on-prem
  • Single-tenant regional deployment — the client does not share infrastructure with other tenants
  • HSM-anchored client keys — HYOK supported; master keys in client-controlled HSM
  • Sovereign provider's regional compliance — provider's regional certifications inherited (FedRAMP, C5, IRAP, etc.)

Operational considerations

Latency
Low. Within-region compute and storage
Engineering support
Medium. Lower than on-prem; higher than multi-tenant SaaS
Update cadence
Fast. Continuous deployment within the region
Scalability
High. Provider's elastic capacity
Compliance
Strong. Regional provider's certifications + cryptographic enforcement
Cost
Higher than multi-tenant SaaS (single-tenant). Lower than on-prem at scale

When to choose this model

  • Sovereign clients in jurisdictions with trusted regional cloud providers
  • Environments that want cloud elasticity without the data-residency risk of multi-region global cloud
  • Environments that want provider-managed infrastructure with sovereign-data control
04 · Multi-Region Active-Active

99.9999% uptime · follow-the-sun 24/7.

Deployed across multiple sovereign cloud regions in active-active configuration, with continuous operations and cryptographic cross-region isolation.

Region A

L1–L5 (active)

  • · ingest
  • · process
  • · serve

HSM (per-region)

Region B

L1–L5 (active)

  • · ingest
  • · process
  • · serve

HSM (per-region)

Region C (optional)

L1–L5 (active)

  • · ingest
  • · process
  • · serve

HSM (per-region)

Active-active · Cross-region encryption · No data replication outside jurisdiction

Capabilities

  • Full platform — same as on-prem
  • Active-active — multiple regions serve traffic simultaneously
  • 99.9999% operational uptime — verified per SLO
  • Follow-the-sun 24/7 ops — operators in different time zones use their regional deployment
  • Cryptographic cross-region separation — regions do not share plaintext

Operational considerations

Latency
Low. Region-local for clients in the region
Engineering support
High. Multi-region orchestration is non-trivial
Update cadence
Fast. Canary across regions; rollback supported
Scalability
Highest. Multi-region elasticity
Compliance
Strong. Per-region data residency; cross-region only with cryptographic isolation
Cost
Highest of the cloud-based models. Single-tenant per region × multiple regions

When to choose this model

  • Sovereign clients with global operations
  • Environments with strict uptime requirements (24/7/365)
  • Environments that need DR/HA without sacrificing sovereignty
  • Environments that need follow-the-sun operations
05 · Air-Gapped

Absolute sovereignty. No network.

The most restrictive deployment. Updates are delivered via physically-transported signed media. This is the model for tactical, classified, and no-network environments.

Air-Gapped Enclave (no network)

L1–L5

Compute

L1–L5

Storage

HSM

Offline

Updates: physically-delivered signed media
No network egress. No network ingress. Physical isolation.

Capabilities

  • Full platform — same as on-prem
  • All five classification levels — including Top Secret / compartmented
  • All seven planes — including air-gap-aware security
  • Updates via signed media — every update bundle is signed, verified on ingest, and logged
  • No telemetry egress — by design

Operational considerations

Latency
Lowest. No network round-trips
Engineering support
Highest. Air-gapped operations are non-trivial
Update cadence
Slowest. Updates require physical media transport
Scalability
Limited to enclave capacity
Compliance
Highest possible. No network, no telemetry, no egress
Cost
High. Hardware footprint + air-gap operations

When to choose this model

  • Tactical, field, embassy, deployed operations
  • Classified environments with statutory no-network requirements
  • Environments with absolute sovereignty requirements that preclude even sovereign cloud
Decision Framework

Choosing a model, by axis.

AxisSovereign On-PremiseHybridSovereign CloudMulti-Region Active-ActiveAir-Gapped
SovereigntyHighestHighHighHighHighest
ElasticityLowestHighHighHighestLowest
Uptime99.99% (single site)99.99%99.99%99.9999%99.99% (single site)
Update cadenceSlowestFastFastFastestSlowest
Engineering burdenHighestHighMediumHighHighest
CostHighest at scaleMediumMedium-highHighHigh
Compliance inheritanceSelf-managedSelf-managed + cloudProvider-managedProvider-managed + per-regionSelf-managed
Crisis readinessSite-dependentStrongStrongStrongestSite-dependent
Multi-jurisdictionNoPossiblePer-regionYesNo

Top-secret, no-network, single-jurisdiction

Air-Gapped or Sovereign On-Premise

Top-secret, multi-jurisdiction, sovereignty-per-region

Multi-Region Active-Active

High-sensitivity, GPU-intensive, multi-jurisdiction

Hybrid

Standard sovereign, elastic, regional

Sovereign Cloud

Tactical, deployed, classified

Air-Gapped (forward-deployed variant)

Global, 24/7/365, sovereign

Multi-Region Active-Active

Operational Considerations

Common across all five models.

Customer-controlled keys (BYOK / HYOK)

All five models support customer-controlled keys. The master keys never leave the client's HSM. The platform uses envelope encryption; the client holds the key-encryption key. Zero-knowledge architecture is supported.

Identity and access

All five models use the same identity and access model: SSO, MFA, RBAC, ABAC, PBAC, JIT, PAM. The integration with the client's identity provider (IdP) is supported and recommended.

Observability

All five models expose the same observability surface: metrics, logs, traces, audit, SLO/SLI. The client owns the observability data; the platform's observability is delivered to the client's monitoring stack.

DevSecOps

All five models support the same DevSecOps workflow: CI/CD, SBOM, SAST/DAST, signed artifacts, blue/green deployment, canary release. The deployment topology is per-model; the workflow is uniform.

Multi-tenancy

In all five models, the platform is single-tenant per client. For internal multi-tenancy within a client organization, the platform supports tenant-aware isolation at the application layer.

Compliance Inheritance

Per compliance × model.

ComplianceOn-PremHybridSovereign CloudMulti-RegionAir-Gapped
GDPRSelfSelfProviderProviderSelf
CCPA/CPRASelfSelfProviderProviderSelf
HIPAASelfSelfProviderProviderSelf
SOXSelfSelfProviderProviderSelf
PCI-DSSSelfSelfProviderProviderSelf
FedRAMPSelfSelfProviderProviderSelf
ISO 27001SelfSelfProviderProviderSelf
SOC 2 Type IISelfSelfProviderProviderSelf
FIPS 140-3Client HSMClient HSMClient HSMClient HSMClient HSM
Common Criteria EAL5+Client HSMClient HSMClient HSMClient HSMClient HSM
Regional equivalentsSelfSelfProviderProviderSelf
Update Mechanics

Updates, per model.

Sovereign On-Prem

Channel

Physically-delivered signed media

Cadence

Quarterly or per-release

Hybrid

Channel

Encrypted channel to client enclave

Cadence

Monthly or per-release

Sovereign Cloud

Channel

In-region deployment pipeline

Cadence

Continuous (canary)

Multi-Region

Channel

Per-region pipeline

Cadence

Continuous (canary per region)

Air-Gapped

Channel

Physically-delivered signed media

Cadence

Quarterly or per-release

Limits

The deployment models are candid about their limits.

On-Prem and Air-Gapped scale with the client's hardware. Capacity planning is the client's responsibility.

Hybrid requires careful cryptographic design. The cryptographic separation is the security boundary; misconfiguration compromises the model.

Sovereign Cloud depends on the provider's sovereignty. If the provider's sovereignty is compromised, the deployment's sovereignty is compromised. The platform mitigates through HSM-anchored keys and zero-knowledge architecture.

Multi-Region requires multi-jurisdiction contractual arrangements. The client must hold sovereign-cloud contracts in each region.

Air-Gapped is the slowest to update. This is by design. Adversaries do evolve; the platform supports scheduled, validated update windows.

Cost varies widely. A full Sovereign On-Premise deployment is a multi-year capital project. A Multi-Region Active-Active deployment is a multi-year operating expense.

Outcomes

Operational properties, per model.

On-Prem

Highest sovereignty

Highest engineering burden

Hybrid

Sensitive data sovereign

GPU elastic

Sovereign Cloud

Regional provider-managed

Single-tenant

Multi-Region

99.9999% uptime

Follow-the-sun

Air-Gapped

Absolute sovereignty

No network

Closing

An integrated intelligence infrastructure — five layers, seven planes, five deployment models, fifteen INTs, ten temporal dimensions.

One commitment: deliver decision-grade intelligence to sovereign clients faster, deeper, and with greater foresight than their adversaries. A confidential briefing is the first step.

Request a Confidential Briefing

The briefing is free · The conversation is confidential · The work is sovereign

Sovereignty Infinium is built for sovereign clients · All engagements operate under mutual non-disclosure · Some capabilities subject to national export controls

SOC 2 Type IIISO 27001GDPRFedRAMPFIPS 140-3Common Criteria EAL5+