[ Legal ]
Data Sovereignty
Last updated · 18 September 2026
Data sovereignty is the first question we answer on any engagement. Inference Systems deployments keep your data in your jurisdiction, on infrastructure under your control, and out of vendor training pipelines.
1. Deployment options
- UK private VPC — isolated virtual networks hosted by UK-based cloud providers, with regional pinning enforced at the infrastructure layer.
- Local bare-metal — models and pipelines run on hardware inside your own facilities or a chosen colocation partner.
- Edge routing — requests are routed to the nearest approved region; traffic never transits jurisdictions you have not approved.
2. What never happens
- Your data is never stored in public multi-tenant pools.
- Your inputs are never used to train or fine-tune vendor models.
- Inferences are not retained after execution unless you opt into audit-log retention (and if you do, logs live in your region).
3. GDPR posture
We operate as a data processor under instruction from our customers (the controllers). Standard contracts include Data Processing Agreements reflecting UK GDPR and the EU GDPR, with sub-processor lists kept current and approved in writing.
4. Verification
Customers receive evidence of data residency — architecture diagrams, region pinning configurations, and access audit trails — as part of every deployment hand-off.