Data location
You choose the boundary your data lives in, and it stays there. Not a region preference — a boundary the system will not cross.
Most “sovereign” offerings are someone else’s platform with a location dropdown. These are the specific commitments S32 designs to — the ones you can write into a contract and hold us to.
Not “is it sovereign?” — everyone says yes. Ask instead: who holds the keys, whose identity provider is authoritative, what happens to my data during routine support, and what exactly do I get on the day I ask you to leave.
Those four answers separate sovereignty as a property of the system from sovereignty as a line in a brochure. Ours are below.
Customer-controlled by default. Each of these is a decision that stays yours after the contract is signed.
You choose the boundary your data lives in, and it stays there. Not a region preference — a boundary the system will not cross.
Held by you. S32 operating a deployment does not require S32 holding the keys to it.
Your identity provider, your directory, your joiners and leavers process. No parallel S32-owned user population.
Authorisation rules are yours to define and yours to change, and they are enforced by the platform rather than assumed by it.
Which models run, where they run, and on what — including running none at all. AI is a component you govern, not a dependency you inherit.
Retention periods are your policy. Expiry is enforced and evidenced, not left to a background job nobody audits.
S32 access to your environment is requested, scoped, time-bounded, revocable by you at any moment, and logged.
Your data does not move across a border because it was convenient for us. Where cross-border processing is genuinely required, it is explicit, logged, time-bounded, revocable and policy-gated — never implicit.
From collection or assessment through analysis, action, evidence, reporting and sustainment, the chain is continuous. An action can be traced to the authority that permitted it and the person who took it.
Managed, sovereign cloud, on-premises and air-gapped are delivery choices, not capability tiers. Disconnected estates are not sold a lesser product.
Documented contracts and export formats. Integration does not depend on a private interface that only S32 understands.
Add, remove, replace, self-host or independently operate a module without forfeiting your data, your audit continuity, or the rest of the platform.
Export your data, revoke our access, and continue independently or with another provider. We test this rather than assert it.
A capability you cannot leave is a capability that owns you. Transition is a defined stage of our delivery lifecycle, not a clause nobody has tested: your data exported in a documented format, our access revoked and evidenced, knowledge transferred to your team, and a replacement provider supported into place if that is what you want.
We would rather you stay because leaving was possible than because it was not.
S32 builds to CALEA, CJIS, CMMC, NIST 800-53, ISO 27001, GDPR and CCPA/CPRA. Building to a framework is not the same as being certified against it, and we do not blur the two. Our SOC 2 programme is in progress and we will say so until it is not.
We also do not name our customers. If that makes a reference call harder, so be it — client confidentiality is not something we suspend for our own marketing.
If any commitment on this page matters to your programme, raise it in procurement. It should survive contact with your legal team, and it is designed to.