Skip to content

Global models

Global models,
if you want them.
And only then.

souveraen.ai works without an external model interface: as delivered, no request leaves your building. Access to global models is the governed exception: per tenant, after explicit approval, after a sovereignty review, and with a log.

  • Default: off
  • Only after approval in the tenant
  • Every outbound request logged
The appliance in the building is sealed off from the outside; a single narrow, locked passage leads to a global model, and only an approval opens it

How an exception comes about

Even the path outside
has a way back.

Your organisation decides, we review, and every step leaves a record. Until step 3 is done, nothing happens.

What stays in the building
  1. 1

    Narrow the task

    You name the single task for which a global model comes into question. Which tasks it may take on and which it may not, we settle together in the offer.

  2. 2

    Review sovereignty

    Before every connection we review data residency, processing under a data processing agreement, sub-processors, custody of credentials and deletion.

  3. 3

    Give approval

    A named, authorised person grants the approval per tenant. Nothing is switched on globally and nothing is switched on quietly.

  4. 4

    In operation: everything sourced

    What leaves the building is recorded: time, tenant, purpose and scope. Documents, search index, vectors and memory stay on the appliance.

  5. 5

    Switch it off again

    The approval is revocable and the withdrawal is logged. After that the as-delivered state applies again: no path outside.

What holds the exception together

An open path is only as good as its control.

If your organisation expressly wants a global model for individual tasks, exactly one controlled path leads there. It opens only when you open it.

Approval per tenant

Access is approved per tenant by a named, authorised person. There is no global switch and no quiet activation.

Sovereignty review before the connection

Data residency, processing under a data processing agreement, sub-processors, custody of credentials and deletion stand on the bench before every connection.

A log of every outbound request

For every outbound request, time, tenant, purpose and scope are recorded. Without a log there is no exception.

Scope in the introduction project

Which tasks a global model may take on we narrow with you and record the result in the offer.

Revocable, not final

An approval that has been granted can be withdrawn. The withdrawal is logged, and the path is closed again afterwards.

The external answer is checked too

An answer produced outside is marked, checked against your permissions and logged like any other.

Without a granted approval this path stays closed, and operation on your appliance remains the default. Which connection applies in your tenant we record in the offer.

The boundary runs at the single request

An excerpt goes out. The collection stays.

Documents, search index, vectors, memory, permissions and logs stay on the appliance, even when an exception has been approved. Only the single request, with selected excerpts, reaches an external model, visibly marked and logged.

  • The collection stays in the building
  • One passage, with approval
  • Every passage logged
The document collection stays behind the boundary; only a marked excerpt passes an approved passage to the global model and is logged as it does

The default

The standard is, and remains: no outflow.

Before we talk about the exception, we record the as-delivered state.

  • As delivered there is no model interface to an external vendor. Answers are composed on the appliance in your building.
  • The product code takes on no outbound data path as a matter of principle. That is a core promise of the enterprise AI, not a configuration recommendation.
  • An approved exception changes nothing about documents, search index, vectors and logs staying local.
  • Every answer carries sources from your stores, and the permission check runs again on every question.

What goes out and what never does

One row decides; the rest stays put.

The decision falls at a clear boundary: the single request to the external model. Everything else stays where it is.

DataWhere it stays
Documents and file storesStay in the building. Even with an approved exception they are not transferred to an external vendor.
Search index, vectors, memoryStay on the appliance. Building and upkeep run entirely locally.
Permissions, logs, approvalsStay in the building. The permission check runs before every answer, including one produced outside.
The request and selected excerptsThe decision point: only this excerpt reaches an external model, visibly marked and logged. Without a granted approval it does not leave your building either.
The answer from the external modelComes back and goes through the same rules as any other answer: sources, permission check, marking.

Three paths, one order

Local first, then Europe, global last.

Most tasks of the enterprise AI need no global model. This table shows what distinguishes the three paths and why the third remains the exception.

Models on the appliance
AspectLocal on the applianceEuropean On DemandGlobal model
What it is forSourced answers from your stores, confidential content, operation without the internet.More compute or larger models, with no hardware of your own.Individual tasks that demonstrably need a global model.
Data locationYour appliance in your building.European data centres; location and operator are confirmed in the offer.Only the approved request is processed at the external vendor. Your collection stays on the appliance.
Who approvesNo one – that is the as-delivered state.Your organisation chooses this operation in the offer; sources are connected after your approval.A named, authorised person per tenant, expressly and revocably.
What goes outNothing. The answer is composed on the appliance.Nothing to external model services: the models run inside the platform.The single request with selected excerpts, marked. Nothing else.
LoggingA source on every answer, a permission check on every question.Identical: the same platform, the same rules.Additionally, for every outbound request: time, tenant, purpose and scope.
DefaultOn. That is the standard, and it stays that way until you approve something else.Applies to the tenant that is set up in European data centres.Off. Without approval there is no external model interface.

European operation runs under a data processing agreement; location, operator and scope we confirm in the offer before anything is provisioned. See the European model paths

Choosing a model

A large model catalogue says nothing about where your data land.

Other platforms list dozens of global models as a catalogue and make the choice the core of the product. We think that is the wrong order.

The data path first, then the model

A model name says nothing about where your request flows. We answer the question of the data path first and only then the question of the model.

A model class, not a brand promise

Whether a task needs a model of the GPT, Claude or Gemini class we review against the use case. There are no partnerships with these vendors, and we advertise none.

The same rules for every answer

An answer produced outside is marked, checked against your permissions and logged too. There is no second, looser path around the platform.

Common questions

The questions that come first with an exception.

Can we use models of the GPT, Claude or Gemini class?

Only as a governed exception: per tenant, after explicit approval and after a sovereignty review. Without that approval there is no external model interface, and souveraen.ai does not switch one on quietly.

Do our documents leave the building?

No. Documents, search index and memory stay on the appliance. The decision point is the single request with selected excerpts alone; it leaves your building only after a granted approval.

Are there partnerships with OpenAI, Anthropic or Google?

No. There are no partnerships, certifications or confirmed compatibilities with these vendors. Whether and how a global vendor is connected is decided by the sovereignty review in your tenant.

Who grants the approval, and can it be withdrawn?

A named, authorised person in your tenant grants the approval. It is revocable and logged; without it the path stays closed.

How can we check this before we decide?

In the trial you see the local default in operation, with no external connection at all. The scope of a global exception we discuss in the introduction project, before you grant an approval.

Global models

Do you really need the exception?

Tell us the tasks for which you are thinking of global models. We will tell you honestly what the appliance in your building does, where a European operation is enough and where an approved exception makes sense.