Sovereign by Default

Sovereignty is architecture, not a region setting.

Most “sovereign” offerings are someone else’s platform with a location dropdown. These are the specific commitments S32 designs to — the ones you can write into a contract and hold us to.

Contact SalesTrust & compliance

The question worth asking a vendor.

Not “is it sovereign?” — everyone says yes. Ask instead: who holds the keys, whose identity provider is authoritative, what happens to my data during routine support, and what exactly do I get on the day I ask you to leave.

Those four answers separate sovereignty as a property of the system from sovereignty as a line in a brochure. Ours are below.

What you control

Customer-controlled by default. Each of these is a decision that stays yours after the contract is signed.

Data location

You choose the boundary your data lives in, and it stays there. Not a region preference — a boundary the system will not cross.

Encryption keys

Held by you. S32 operating a deployment does not require S32 holding the keys to it.

Identity

Your identity provider, your directory, your joiners and leavers process. No parallel S32-owned user population.

Policy

Authorisation rules are yours to define and yours to change, and they are enforced by the platform rather than assumed by it.

Models and runtime

Which models run, where they run, and on what — including running none at all. AI is a component you govern, not a dependency you inherit.

Retention

Retention periods are your policy. Expiry is enforced and evidenced, not left to a background job nobody audits.

Support access

S32 access to your environment is requested, scoped, time-bounded, revocable by you at any moment, and logged.

What we commit to

No cross-border processing by default

Your data does not move across a border because it was convenient for us. Where cross-border processing is genuinely required, it is explicit, logged, time-bounded, revocable and policy-gated — never implicit.

One authority and audit lineage

From collection or assessment through analysis, action, evidence, reporting and sustainment, the chain is continuous. An action can be traced to the authority that permitted it and the person who took it.

No feature reduction by deployment model

Managed, sovereign cloud, on-premises and air-gapped are delivery choices, not capability tiers. Disconnected estates are not sold a lesser product.

Open, documented interfaces

Documented contracts and export formats. Integration does not depend on a private interface that only S32 understands.

Modular replacement

Add, remove, replace, self-host or independently operate a module without forfeiting your data, your audit continuity, or the rest of the platform.

A documented way out

Export your data, revoke our access, and continue independently or with another provider. We test this rather than assert it.

Exit is a feature.

A capability you cannot leave is a capability that owns you. Transition is a defined stage of our delivery lifecycle, not a clause nobody has tested: your data exported in a documented format, our access revoked and evidenced, knowledge transferred to your team, and a replacement provider supported into place if that is what you want.

We would rather you stay because leaving was possible than because it was not.

What we do not claim.

S32 builds to CALEA, CJIS, CMMC, NIST 800-53, ISO 27001, GDPR and CCPA/CPRA. Building to a framework is not the same as being certified against it, and we do not blur the two. Our SOC 2 programme is in progress and we will say so until it is not.

We also do not name our customers. If that makes a reference call harder, so be it — client confidentiality is not something we suspend for our own marketing.

Put it in the contract.

If any commitment on this page matters to your programme, raise it in procurement. It should survive contact with your legal team, and it is designed to.

Contact Sales