EigenForge AI Labs Talk to us
A fortified perimeter around a self-contained data landscape

Sovereign AI

When the data cannot leave.

If a regulator, a residency rule, a classification or a contract means your data cannot move into a hosted service, most of the market's default answer is already unavailable to you. That is usually discovered late, and expensively.

YOUR SOVEREIGN BOUNDARYSYSTEMS OF RECORD — READ IN PLACEERPCore platformMainframeCRMFiles & streamsGOVERNED LAYERDefinitions · quality · lineage · entitlement evaluated at query timeONTOLOGY GROUNDINGAnswers generated from a model of how yourtables relate — no vector copy, nothing to drift.Nothing is chunked and shipped out.LOCAL MODEL INFERENCEOpen-weights models on your own hardware.Model choice is a configuration, not an architecture.No inference call leaves the boundary.OUTSIDE THE BOUNDARYNothing. No embedding service, no hosted control plane, no telemetry channel, no licence call-home.
Exhibit 01Everything inside the boundary: sources read in place, a governed layer, ontology grounding and local model inference. Nothing outside it.
A fortified perimeter around a self-contained data landscape
The test of a sovereign deployment: everything the system needs is inside the wall, and nothing crosses it.

Why it keeps disappointing

Five failure patterns, and they are all architectural.

The diminished edition

A cloud product, ported. It trails the hosted version by a release cycle or three, and the roadmap belongs to the cloud product.

The AI is still somewhere else

The application runs locally; the intelligence does not. The deployment diagram is sovereign and the data flow is not.

The managed-service dependency

It assumes one cloud provider's managed database, queue and identity. Lift it out and half of it does not run.

Governance follows the data

The audit trail and policy engine live in the vendor's control plane. You can see your data but you cannot prove what happened to it.

Nothing is actually disconnected

"Air-gapped" turns out to mean a periodic sync, a licence check, or a telemetry channel somebody assumed was fine.

The useful question

Not "can this be deployed on premises?" — every vendor says yes. It is: is the on-premises version the same product, and does the AI still work when nothing can leave?

Five topologies

From one codebase, so none of them is a special edition.

01On premisesInside your data centre.Nothing leaves the estate.Defence · public sector ·regulated manufacturing02Private cloudYour tenancy, your keys.Financial services ·healthcare03Public cloudAny provider, standardKubernetes.Cloud-first enterprises04Air-gappedDisconnected, with localmodel inference.Classified · criticalnational infrastructure05FederatedPer jurisdiction, one viewacross them.Multi-country groups underresidency rulesFive topologies from one codebase — not a cut-down edition six months behind.
Exhibit 02The commercial consequence matters as much as the technical one: one deployment story satisfies a defence tender, a risk committee and a cloud-first CIO.
FIG. 3THE SOVEREIGN BOUNDARY — SECTION VIEWTHE BOUNDARYSYSTEMS OF RECORDread in placeGOVERNED LAYERpolicy at query timeONTOLOGYrelationships keptINFERENCElocal modelsLINEAGE ON EVERY FIGURE · THE SAME QUESTION, THE SAME ANSWEREVERYTHING THE ANSWER NEEDS — INSIDENO CALL CROSSESNOTHING CROSSES — NOT TO INDEX,NOT TO INFER, NOT TO PHONE HOME
Exhibit 03The sovereign boundary as an engineering section: everything the answer needs is inside, and no call crosses the wall.

Open-weights models

Model choice is a configuration, not an architecture.

A sovereign deployment runs inference against models you hold. We are deliberately not loyal to any of them: the right model is the smallest one that passes your evaluation, on a licence your legal function has read, measured on your data rather than on a leaderboard.

WORKLOADWHERE WE USUALLY STARTWHYGrounded question answeringMid-size instruction-tuned openweightsAccuracy on your ontology matters more than rawscale; the retrieval does the heavy lifting.Document extractionSmall to mid-size, long-context openweightsContext length and structure-following beat reasoningdepth.Agent planning and tool useLarger open weights, or a hostedmodel where policy allowsTool-calling reliability is the constraint; test itrather than assume it.Coding assistanceCode-specialised open weights, runlocallyLatency and privacy dominate; a smaller specialisedmodel beats a larger general one.Classification and routingSmall open weights, or no model atallMost routing is a rule. Reach for a model only wherea rule genuinely fails.HOW WE CHOOSE✓Smallest model that passes your evaluation, not thelargest you can run✓Permissive licence you have read, and weights you canhold✓Measured on your data, not on a public leaderboard
Exhibit 04Where we usually start, by workload. Specific versions move faster than any document can track, so we confirm the shortlist at design time and record what we tested and rejected.

The four shapes worth holding

ShapeTypical roleWhat to watch
General instruction-tuned, mid-sizeThe workhorse for grounded question answering and summarisation. Runs on a single modern accelerator.Instruction-following under your own prompts, not benchmark scores.
Long-contextDocument extraction, contract and case work, anything where the passage is long.Real performance at the far end of the window, which is often much worse than the headline.
Larger reasoning-capableAgent planning and multi-step tool use, where a wrong plan costs more than a slow one.Tool-calling reliability. Test it; do not assume it.
Small and code-specialisedOn-device work, classification, routing and coding assistance where latency and privacy dominate.Whether a rule would do the job better and cheaper. Very often it would.

How we choose, in order

  1. Your evaluation set, built from your own questions during discovery. Nothing else decides it.
  2. Latency and throughput. Two points better and four times slower is usually the wrong model.
  3. Your hardware — including where the honest answer is that a smaller model is the right call.
  4. The licence, read by someone who will have to defend it.
  5. Cost per answered question, not per token, because per-token is not a number anyone can act on.

Grounding, policy, evidence and cost control live in the platform, not the model. Replacing a model is a configuration change and a re-run of your evaluation — not a migration.

Federation

One view, without one location.

The hardest sovereign requirement is not "keep it in country". It is "keep it in country and let the group see the picture".

Jurisdiction Aown deploymentown data, own rulesJurisdiction Bown deploymentown data, own rulesJurisdiction Cown deploymentown data, own rulesOne federated viewasks each deployment — it never gathers the dataRedaction is applied per jurisdiction on the way out, so a group answer never contains something a jurisdiction would not release.
Exhibit 05Each jurisdiction holds its own data under its own rules. A group question asks each deployment rather than gathering the data.
IdentityYour existing directory. No separatestore.AuthorisationRow and column policy at queryexecution.EncryptionIn transit and at rest, keys under yourcontrol.AuditEvery query, access and agent action.LineageTo source record and version.ResidencyPer jurisdiction, with a federated view.RedactionBy jurisdiction and by entitlement.AI boundaryInference inside your environment.Security and governance enforced at the point of use, in every topology.
Exhibit 06Controls enforced at the point of use, in every topology.

Diligence

Eight questions worth putting to any vendor — including us.

  1. Is the on-premises version the same product and the same release as the hosted one?
  2. Where is content embedded, and does anything leave the boundary to be indexed?
  3. Where does inference run, and can it run against a model we host?
  4. Does the audit trail live in our deployment or in your control plane?
  5. In an air-gapped deployment, which capabilities stop working?
  6. What does the system depend on from one specific cloud provider?
  7. Can policy be evaluated per user at query time, or only at the front door?
  8. Can you reconstruct a decision from the data as it stood on the day it was made?

We will answer all eight in writing. A vendor who cannot answer questions two and three quickly has told you something useful.

Talk about a sovereign deployment

Tell us what the rule actually is — the regulation, the classification, the contract clause — and we will say plainly whether we can work inside it.

hello@eigenforgelabs.ai

Send opens your email client with the note already addressed to us — nothing is stored on this site, and the message goes from your own mailbox, so our reply lands in yours.