Local operation, no external model API
On Private Spark and Air-Gap Enterprise the models run on the appliance in your own building. There is no model API at an external provider and no outbound data path in the product.
Security and sovereignty
souveraen.ai is built for organisations whose knowledge must not leave the building. The same rules hold in every operating model: on the appliance in your own building just as they do in European hosting.

How security works day to day
Security sits in the path every question already takes.
You decide where your knowledge is processed: on the appliance in your own building, fully isolated, or in European data centres.
The integration reads the stores you already have and takes on their permissions. The documents stay where they are.
Every query is checked against the source's permissions and current group membership. Content you are not entitled to see does not appear at all.
Every answer names the passage it rests on. Where sources are missing or contradict each other, the answer says so.
Learning happens only after a subject-matter approval, and a change in your systems only after yours. What happened is in the log.
Six principles
Whether it runs on the appliance in your own building or in European hosting: the place of operation changes nothing about these six points.
On Private Spark and Air-Gap Enterprise the models run on the appliance in your own building. There is no model API at an external provider and no outbound data path in the product.
Every passage carries the permissions of its source. Every question is checked against current group membership, not just once at ingest.
Tenant, workspace and personal content stay strictly apart. A role sees only what has been approved for it. Content you are not entitled to see does not appear at all.
Activity, approvals and tool calls are logged. What happened can be read back; nobody has to take it on trust.
Only what has been approved by a subject-matter owner is learned. Every step that changes something in your systems is tied to an approval.
Every answer shows the passage it rests on. Missing or contradictory sources stay visible as well.
Protection sits inside, not at the edge
The boundary does not sit at the company network. It sits around every tenant and every workspace. What comes in passes a permissions check. What takes effect needs an approval. The product has no outbound data path.

Permissions apply on every query
Permissions are enforced at the moment of the question, not written down once at ingest.
Three operating models, one security model
The six principles hold in every model. What differs is where it runs, and what that means for the network and where the data stays.
| Operating model | Where it runs | Network | Outbound data |
|---|---|---|---|
| Private Spark | Appliance in your infrastructure, in your own building. | No internet connection needed; reviewed MCP servers sit in the signed offline package. | No outbound data path in the product, no external model API. |
| Air-Gap Enterprise | Isolated installation, hardware sized to what you need. | Fully isolated, with no connection to the outside; nothing is fetched at runtime. | Ruled out, because there is no path to the outside. |
| European On Demand | Runs in European data centres, without hardware of your own. | Reached over the network; connections to your sources only after your approval. | Processed in Europe; location and operator are confirmed before anything is provisioned. |
For Private Spark and Air-Gap Enterprise, reviewed MCP servers sit in the signed offline package; nothing is fetched at runtime.
What the platform enforces
The table lists every rule, from the permissions check through to approval before every change. Beside it sits how you can verify each one.
| Area | Rule | How you can verify it |
|---|---|---|
| Sourced answers | Every answer names the passage it rests on. | Missing or contradictory sources are marked, rather than papered over. |
| Permissions check | Every query is checked against the source's permissions and current group membership. | Content you are not entitled to see appears neither as a hit nor as a title, a preview or a hit count. |
| Separated tenants and workspaces | Tenant, workspace and personal content stay apart. | Role-based permissions decide what a person is allowed to see at all. |
| Logged activity | Activity and reading tool calls are logged. | Who retrieved what, and when, can be traced later. |
| Learning only after approval | Only what a person with subject-matter responsibility has reviewed and approved enters the shared knowledge. | Without approval, feedback does not change any answers. |
| Changes only after your approval | Tools that make changes are tied to an approval; an execution agent takes on a task only after that as well. | You see the preview beforehand; the record lands in the approval inbox afterwards. |
| Curated tool catalogue | Which tools and integrations are available is managed and documented centrally. | Nothing is added unnoticed. |
What sits on your appliance as delivered is written down in the quote.
Common questions
Not on Private Spark or Air-Gap Enterprise: extraction, embedding and answering run on the appliance in your infrastructure, with no external model API. On European On Demand your knowledge is processed in European data centres; location and operator are confirmed before anything is provisioned.
Only those entitled to it under the source's permissions. Every query checks current group membership; content you are not entitled to see does not appear at all, not even as a title or a hit count.
Only from feedback that has been approved by a subject-matter owner. That stays traceable and separated per tenant; without approval, feedback does not change any answers.
No. Reading tools fetch and report. Every step that makes a change is tied to an approval: you see beforehand what is meant to happen, you decide, and the record lands in the approval inbox afterwards.
Every indexing run produces a report on wide-ranging read permissions and flags file stores that have been shared unusually widely. That shows you where the source system needs tidying. The permissions themselves stay in your hands.
We do not advertise certifications or attestations we do not have. What counts is what can be shown technically: the permissions check, tenant separation, logging, and where the data remains in your operating model. In the introduction project we lay that open to your IT and data-protection teams.
Security and sovereignty
Send us the requirements catalogue from your IT security and data-protection teams. We will go through it point by point and show you what the platform enforces technically and what remains organisationally with you.