The ledger, the keys, and the model weights live inside the nation that owns them and are engineered so they cannot be replicated out. Residency is a property of the architecture, not a promise in a contract.
Every component that constitutes sovereign state is placed inside national borders and denied a path to leave them.
Ledger nodes, key stores, and model training run on infrastructure physically located in the owning jurisdiction. Residency starts with where the machines are, before any policy is applied on top.
The system is built without an outbound replication path to foreign regions. Data staying in-country is the absence of an export mechanism, not a rule that has to be continuously enforced against one.
The owning state or institution controls the operators, credentials, and change process for its deployment. No external party can be compelled or required to move data to satisfy another jurisdiction's demand.
The set of locations that hold sovereign state is enumerable and reviewable during audit. Residency claims can be checked against where components actually run, not taken on assertion.
Signing keys and trained model weights are the crown jewels of a sovereign deployment, and they are the assets held most tightly in-nation.
ML-DSA-65 signing keys are generated and used inside in-nation custody and are never transmitted abroad for any operation. Cross-border signing is not offered because it would require the key to travel.
Foundation and specialized models are trained on in-country infrastructure so the resulting weights originate inside the jurisdiction. The nation holds the weights, not a copy licensed from elsewhere.
Serving a sovereign model runs against the in-nation weights rather than a hosted external endpoint. Prompts, context, and outputs never traverse a border to reach the model.
The owner, not the vendor, holds the custody boundary around keys and weights. Sovereignty over these assets does not depend on trusting an operator to refrain from copying them.
Residency is protected by removing the pathways over which sovereign data could be replicated outward.
Ledger and state replication targets are confined to in-jurisdiction infrastructure. High availability is achieved within national borders rather than by mirroring to a foreign region.
Snapshots and archives are written to storage that resides in the same jurisdiction as the live system. A restore never requires pulling data back across a border.
External connections are limited to what an owner explicitly authorizes and are scoped so they cannot become a channel for bulk export. Interfaces exchange what is agreed, not the underlying state.
Any outbound flow that does exist is defined, logged, and reviewable rather than implicit. If data can leave at all, it leaves through a path an owner chose and can watch.
The data centers that host sovereign workloads are part of the residency guarantee, not a neutral commodity underneath it.
Hyperscale and AI/GPU capacity is delivered on facilities built inside the owning nation. The compute that trains models and settles the ledger is subject to national law by virtue of where it stands.
Facilities can be delivered engineer-procure-construct so the owner holds the resulting infrastructure rather than renting foreign capacity. Ownership of the ground reinforces residency of the data.
Deployments can run without dependence on external control planes, so residency does not quietly rely on a service reachable only from abroad. The system can operate as a self-contained national installation.
Operations, monitoring, and incident response are performed by in-country teams under the owner's authority. The people with hands on the system are inside the jurisdiction that governs it.
The architecture is arranged so that only the owning jurisdiction's law reaches the data, closing the gap between where data sits and who can compel it.
Placing storage, keys, and operators in one jurisdiction means one legal regime governs the data. There is no foreign custodian who could be ordered to hand over sovereign records.
Because sovereign state never rests in another country, it is not exposed to that country's disclosure or seizure powers. Residency removes the conflict rather than trying to arbitrate it.
The owner defines which data is sovereign and must remain resident, and the system enforces that classification in placement. Policy and mechanism describe the same boundary.
The hash-chained ledger and operational logs let a regulator verify where records were held and processed. Residency compliance is demonstrable from tamper-evident evidence, not attested by narrative.