Approval per tenant
Access is approved per tenant by a named, authorised person. There is no global switch and no quiet activation.
Global models
souveraen.ai works without an external model interface: as delivered, no request leaves your building. Access to global models is the governed exception: per tenant, after explicit approval, after a sovereignty review, and with a log.

How an exception comes about
Your organisation decides, we review, and every step leaves a record. Until step 3 is done, nothing happens.
You name the single task for which a global model comes into question. Which tasks it may take on and which it may not, we settle together in the offer.
Before every connection we review data residency, processing under a data processing agreement, sub-processors, custody of credentials and deletion.
A named, authorised person grants the approval per tenant. Nothing is switched on globally and nothing is switched on quietly.
What leaves the building is recorded: time, tenant, purpose and scope. Documents, search index, vectors and memory stay on the appliance.
The approval is revocable and the withdrawal is logged. After that the as-delivered state applies again: no path outside.
What holds the exception together
If your organisation expressly wants a global model for individual tasks, exactly one controlled path leads there. It opens only when you open it.
Access is approved per tenant by a named, authorised person. There is no global switch and no quiet activation.
Data residency, processing under a data processing agreement, sub-processors, custody of credentials and deletion stand on the bench before every connection.
For every outbound request, time, tenant, purpose and scope are recorded. Without a log there is no exception.
Which tasks a global model may take on we narrow with you and record the result in the offer.
An approval that has been granted can be withdrawn. The withdrawal is logged, and the path is closed again afterwards.
An answer produced outside is marked, checked against your permissions and logged like any other.
Without a granted approval this path stays closed, and operation on your appliance remains the default. Which connection applies in your tenant we record in the offer.
The boundary runs at the single request
Documents, search index, vectors, memory, permissions and logs stay on the appliance, even when an exception has been approved. Only the single request, with selected excerpts, reaches an external model, visibly marked and logged.

The default
Before we talk about the exception, we record the as-delivered state.
What goes out and what never does
The decision falls at a clear boundary: the single request to the external model. Everything else stays where it is.
| Data | Where it stays |
|---|---|
| Documents and file stores | Stay in the building. Even with an approved exception they are not transferred to an external vendor. |
| Search index, vectors, memory | Stay on the appliance. Building and upkeep run entirely locally. |
| Permissions, logs, approvals | Stay in the building. The permission check runs before every answer, including one produced outside. |
| The request and selected excerpts | The decision point: only this excerpt reaches an external model, visibly marked and logged. Without a granted approval it does not leave your building either. |
| The answer from the external model | Comes back and goes through the same rules as any other answer: sources, permission check, marking. |
Three paths, one order
Most tasks of the enterprise AI need no global model. This table shows what distinguishes the three paths and why the third remains the exception.
| Aspect | Local on the appliance | European On Demand | Global model |
|---|---|---|---|
| What it is for | Sourced answers from your stores, confidential content, operation without the internet. | More compute or larger models, with no hardware of your own. | Individual tasks that demonstrably need a global model. |
| Data location | Your appliance in your building. | European data centres; location and operator are confirmed in the offer. | Only the approved request is processed at the external vendor. Your collection stays on the appliance. |
| Who approves | No one – that is the as-delivered state. | Your organisation chooses this operation in the offer; sources are connected after your approval. | A named, authorised person per tenant, expressly and revocably. |
| What goes out | Nothing. The answer is composed on the appliance. | Nothing to external model services: the models run inside the platform. | The single request with selected excerpts, marked. Nothing else. |
| Logging | A source on every answer, a permission check on every question. | Identical: the same platform, the same rules. | Additionally, for every outbound request: time, tenant, purpose and scope. |
| Default | On. That is the standard, and it stays that way until you approve something else. | Applies to the tenant that is set up in European data centres. | Off. Without approval there is no external model interface. |
European operation runs under a data processing agreement; location, operator and scope we confirm in the offer before anything is provisioned. See the European model paths
Choosing a model
Other platforms list dozens of global models as a catalogue and make the choice the core of the product. We think that is the wrong order.
A model name says nothing about where your request flows. We answer the question of the data path first and only then the question of the model.
Whether a task needs a model of the GPT, Claude or Gemini class we review against the use case. There are no partnerships with these vendors, and we advertise none.
An answer produced outside is marked, checked against your permissions and logged too. There is no second, looser path around the platform.
Common questions
Only as a governed exception: per tenant, after explicit approval and after a sovereignty review. Without that approval there is no external model interface, and souveraen.ai does not switch one on quietly.
No. Documents, search index and memory stay on the appliance. The decision point is the single request with selected excerpts alone; it leaves your building only after a granted approval.
No. There are no partnerships, certifications or confirmed compatibilities with these vendors. Whether and how a global vendor is connected is decided by the sovereignty review in your tenant.
A named, authorised person in your tenant grants the approval. It is revocable and logged; without it the path stays closed.
In the trial you see the local default in operation, with no external connection at all. The scope of a global exception we discuss in the introduction project, before you grant an approval.
Global models
Tell us the tasks for which you are thinking of global models. We will tell you honestly what the appliance in your building does, where a European operation is enough and where an approved exception makes sense.