Your code stays in the EU. Under conditions we will name.
For teams whose source cannot flow through US services: execution and storage run on EU bare metal. Whether the whole pipeline is sovereign depends on one more choice — the model you point it at — and we would rather be specific about that than sell you a flag.
- compute: execution and storage on eu bare metal
- model: eu-hosted, or your own token for a us provider
- operator: covered by the condition below
The problem
The most productive agent platforms are operated by US providers. Selecting an EU region in a dropdown changes neither the law the operator is subject to nor who can be compelled to access what — and it evidences nothing to a data protection officer who asks.
What we can state
Execution and storage in the EU
region: eu · bare metal at an eu providerGuardrails, not surveillance
operating policy: guardrails instead of content monitoringA structured event log per session
audit: session event log · export & retention: planned
The condition
Sovereignty holds for the whole pipeline only when the compute, the model and the operator are all in scope.
- An EU-hosted model
Run an EU-hosted model and the prompt never leaves the EU.
- Your own token for a US provider
Bring your own token for a US provider — which you are free to do — and the prompts you send reach that provider under their jurisdiction, whatever our region setting says.
We will tell you which of those two you are in, per route, before you sign anything.
The safe default is the normal state: egress closed, and open only for the destinations resolved when the session was created.
Bring us your actual requirement
If your DPO has a list, send it. We will answer each line with implemented, planned, or not covered — and we will not blur the middle one into the first.