Training corpora and model weights are born, live, and die inside the owner's borders. No data crosses a frontier to become intelligence, and no intelligence leaves once it is made.
In-nation training is enforced by where the silicon physically sits, not by a clause in an agreement.
Training runs execute on accelerators installed in owner-operated or owner-designated data centers inside national territory. There is no cross-border burst capacity and no fallback region abroad.
Corpus storage, feature stores, and checkpoint buckets bind to in-nation networks and object stores. Egress to external endpoints is denied at the network layer rather than merely discouraged by policy.
The stack deploys into a fully air-gapped enclave or a sovereign cloud region under national jurisdiction. The same pipeline runs in both, so residency does not force a weaker architecture.
Disks, backup media, and decommissioned accelerators remain under owner custody through their full lifecycle, including secure erase and destruction, without third-party removal.
A trained model encodes the nation's data; it is governed with the same seriousness as the data itself.
Weights are encrypted at rest under keys the owner controls in national HSMs. Sovex operates the pipeline but cannot exfiltrate or decrypt weights without owner-held key material.
Every intermediate checkpoint, optimizer state, and fine-tune delta is written to in-nation storage. No training artifact is synchronized to an external registry for convenience or backup.
Weight releases are signed with ML-DSA-65 (FIPS 204) so that a distributed model can be verified as the exact artifact the owner authorized, resistant to forgery under quantum adversaries.
Moving a model out of the country is never a side effect of operations. It requires an owner-signed authorization recorded on the ledger, not a default of the deployment.
Residency holds because three independent layers would each have to fail for data to leave.
The training and serving VPCs carry no route to the public internet for data planes. Package mirrors, base images, and dependencies are staged in-nation before an air-gap is sealed.
Operational telemetry and orchestration metadata are separated from raw corpus and weights. Sovex can observe pipeline health without any path to the sensitive tensors themselves.
Where hardware supports it, training executes inside attested trusted execution environments, so even the operator's host OS cannot read plaintext corpus or weights in memory.
The location and identity of every node handling regulated data is attested and re-checked. A node that cannot prove in-nation placement is evicted from the pool.
Updates, debugging, and vendor support are designed so none of them punches a hole in residency.
Model and dependency updates are packaged, signed, and imported through a controlled one-way path. Nothing phones home and no update requires opening an outbound channel.
Logs, traces, and evaluation results that touch sensitive data stay resident. Aggregate, non-sensitive operational metrics can be shared only under owner-defined redaction rules.
Support sessions occur through owner-mediated access with recorded, revocable sessions. No standing remote path exists into the enclave for Sovex or any subcontractor.
Replication and backup targets are additional in-nation sites, not foreign regions. Resilience is achieved without ever treating another jurisdiction as a safety net.
Talk to us about data never leaves the country in a sovereign deployment.