SECURITY & COMPLIANCE

Built around the rules European institutions live by

Project Sovereign is positioned around European regulatory review: data minimisation, continuity, auditability, exit strategy, AI governance, and clear deployment boundaries.

CONTROL AREAS

Compliance mapped to document workflows

These are public positioning areas, not certifications. Deployment-specific evidence should be requested during review.

01

GDPR

Reg. (EU) 2016/679. Sovereign is positioned around data minimisation, portability, erasure planning, and deployment boundaries that make processor review easier.

02

NIS2

Dir. (EU) 2022/2555. Document workflows need risk analysis, incident handling, continuity, supply-chain review, and cryptography evidence mapped to Article 21 controls.

03

DORA

Reg. (EU) 2022/2554. Financial entities need ICT vendor review, exit strategy, audit rights, resilience evidence, and clear sub-processor boundaries.

04

EU AI Act

Reg. (EU) 2024/1689. AI is described as optional, provider-controlled, auditable, and off by default rather than embedded as an unavoidable cloud feature.

DATA PATH

Residency, logs, and AI boundaries

01

EEA residency

Production deployments should confirm regions, sub-processors, backups, logs, and support access before handover.

02

Audit logs

The intended posture records actors, actions, timestamps, sessions, and document state without exposing document bodies in logs.

03

AI opt-in

AI features are not described as default cloud behavior. Provider choice and data flow belong to the deploying institution.