Where the data lives, and who can reach it
Sovereignty is a set of concrete properties, not an adjective. These are ours, stated per deployment model so you can check the one you would actually run.
What changes between deployment models
The capability is the same in all four. What differs is where it runs, who holds the keys, and whether an outbound path exists at all.
| Model | Data location | Key custody | Egress |
|---|---|---|---|
| Managed For customers who want the capability without operating it. | S32 Technologies infrastructure | S32 Technologies, customer-scoped | Within the managed boundary |
| Sovereign cloud Jurisdiction chosen by you, including national-cloud providers. | Customer-nominated region and provider | Customer | None by default |
| On-premises Your racks, your network, your physical control. | Customer data center | Customer | None by default |
| Air-gapped Full capability. No outbound path exists. Updates by signed package. | Disconnected customer environment | Customer | None. No outbound path exists |
Support access is requested, not standing
The question a security team wants answered is not whether we have access. It is what shape that access takes, and who ends it.
- Access is requested, not standing. There is no permanent support account waiting in your environment.
- You approve it, unless a separately agreed emergency rule applies, and that rule is written before it is needed.
- It is purpose-bound and time-bounded, and it expires on its own rather than on someone remembering.
- It is least-privilege: scoped to the system and the task, not to the estate.
- Sessions are attributable to a named individual and recorded where required.
- You can revoke it immediately, without contacting us first.
- Routine support does not require your mission data to leave the boundary you chose.
Cross-boundary support or processing is never a silent convenience. It requires explicit purpose, authority, a time limit, access control, and auditable completion, return or deletion as applicable.
Third parties in the data path
For sovereign, on-premises and air-gapped deployments the answer is none: no third party sits in the path of your mission data. For the managed model and for this website, the list is short and it is published here, not available on request.
| Provider | Purpose | Applies to |
|---|---|---|
| Cloudflare, Inc. | Bot protection and network security | s32.io only |
| Hosting and email providers | Serving this website, delivering our replies and newsletter | s32.io only |
Where a managed deployment introduces an infrastructure provider, it is named in the agreement before signature, and the customer chooses the region.
Controls that hold whether or not we are watching
Authorization before retrieval
Search, graph traversal, ranking and AI context are filtered on effective entitlement before content enters the computation, not after a result exists.
Server-authoritative enforcement
Hiding something in the interface is not a control. Entitlement is enforced at the API, the data and the policy layer, so a crafted request gets the same answer.
Append-only audit
Consequential actions are recorded as they happen, attributable to a named user, with the reason for access captured rather than optional.
Marking travels with the data
Classification, compartment and caveat propagate through every transformation, so a derived product cannot quietly lose the handling rules of its sources.
No dormant outbound calls
Air-gapped operation does not depend on remote fonts, hosted models, cloud license checks or external telemetry. If it did, it would not be air-gapped.
Documented exit
Export formats are documented and supported, so the data you accumulate stays portable and leaving remains possible.
Reporting a security issue.
If you believe you have found a vulnerability in this website or another S32 Technologies system, tell us before disclosing it publicly. Our contact details and disclosure preferences are published at /.well-known/security.txt.
We will not pursue action against a researcher acting in good faith who avoids privacy violations and data destruction and gives us a reasonable opportunity to remediate.