"Sovereign" is now a marketing adjective. These twelve questions separate architectures that keep your data by design from products that keep it by promise. Ask them of every vendor — including us.
Where the data actually goes
1. Where does inference run — physically? Not "in-region", not "dedicated tenancy": which machines, whose racks, whose jurisdiction. If the answer involves a shared endpoint, your prompts transit infrastructure you do not control.
2. Can sovereignty be verified, or only configured? A checkbox that disables telemetry is a setting; a deployment with no outbound path is an architecture. Ask to run the product behind a firewall that blocks all egress and watch what breaks.
3. What leaves the perimeter during RAG ingestion? Embedding is inference too. If documents are vectorised by a cloud API, your knowledge base has already left the building — before anyone asks a question.
4. What happens fully air-gapped? Not "offline-tolerant" — installed, licensed and operated on a network that has never seen the internet. Many products pass a demo and fail an air gap.
Who holds the keys
5. Who holds the trust root for agents and automations? If agents are signed and certified, ask who controls the signing key. If it is the vendor's cloud, your agent supply chain has an external dependency.
6. Does licensing call home? Phone-home licensing is telemetry with a business model. Offline licence files exist; ask why the vendor does not use them.
7. Who can read the audit log — and who can edit it? An audit trail an administrator can rewrite is a liability dressed as a control. Look for append-only, tamper-evident storage.
8. What telemetry, crash reporting or "product analytics" is on by default? Get the full list in writing, with the off switch demonstrated.
Operations and economics
9. How do model updates arrive? If updating means the vendor reaching into your environment, sovereignty ends at the first patch. Look for operator-applied, verifiable update artefacts.
10. Per-seat or compute-based pricing? Per-seat pricing on infrastructure you provide means paying twice for scale. Understand what actually drives cost as usage grows.
11. How long does deployment genuinely take? "Weeks of professional services" usually signals an architecture that was not designed for your perimeter. Ask for a timed, witnessed install.
12. What is the exit path? Your documents, embeddings, automations and audit history — in what format, extracted by whom, at what cost? Sovereignty includes sovereignty from the vendor.
- Insist on demonstrations over attestations: egress-blocked trials, air-gap installs, log-integrity checks.
- Put every answer in the contract. A verbal "yes, on-prem" is not a data-flow diagram.
- Score vendors on how they answer question 12 — it predicts how questions 1–11 were answered.
A vendor confident in its architecture will welcome this list. Evasiveness on any single question is itself the answer.
Put these twelve questions to us →Related guides
Risk
Shadow AI: your biggest leak is a paste-box
Why employees pasting contracts into public chatbots is a legal exposure, not an IT nuisance — and why bans fail where better tools succeed.
7 min read
Read the guide →Economics
Token economics: why your AI bill scales with sloppy context
How RAG and agent context quietly inflate token spend, what compression can and cannot safely remove, and what a 48–79% measured reduction means for a real workload.
8 min read
Read the guide →Compliance
The EU AI Act Article 12 readiness guide
What record-keeping and human-oversight obligations actually require operationally from August 2026 — and the evidence an auditor will ask you to produce.
9 min read
Read the guide →