SOVEX
CBDC Data Centers Sovereign AI Tokenization Deep Tech Architecture About Team Request access
Data Centers / Sovereign deployment / In-nation and data residency

In-nation and data residency.

Sovereign finance runs on infrastructure the state can point to on a map. Facilities, keys, weights, and ledgers stay inside the jurisdiction — data never crosses a border it wasn't authorized to cross.

The infrastructure lives where the jurisdiction begins and ends

Residency starts with steel, power, and land inside sovereign territory — not a contractual promise about a foreign region.

01

On-territory facilities

Compute, storage, and settlement nodes are sited on land inside the host state's borders and under its legal authority. There is no dependence on an offshore region, availability zone, or foreign colocation for primary operation.

02

National grid and power

Facilities draw from in-nation power and are engineered to survive its failure modes with local generation and storage. Continuity does not require a cross-border interconnect or a foreign operator's control plane.

03

Sovereign network paths

Traffic between CBDC nodes, ledger replicas, and settlement services is routed over paths that terminate inside the jurisdiction. Egress to external networks is an explicit, governed exception rather than a default.

04

No foreign control plane

Orchestration, key management, and administrative access originate from within the state's operational perimeter. The system does not phone home to a vendor's global management fabric to function.

Data has a defined perimeter and cannot silently leave it

Every class of data — ledger, model weights, telemetry, backups — is bound to the territory by policy that is enforced in the plumbing, not just written in a contract.

01

Ledger and settlement data

The hash-chained ledger and delivery-versus-payment settlement records are stored and replicated only within in-nation facilities. Replication targets are enumerated and geofenced; an out-of-jurisdiction replica cannot be provisioned by default.

02

Model weights stay resident

Foundation and specialized model weights trained in-nation remain in-nation. Training checkpoints, gradients, and final weights are treated as sovereign assets and never shipped to an external training or inference cloud.

03

Telemetry and logs

Operational telemetry, audit logs, and metrics are retained inside the boundary. Diagnostics needed by external parties are exported only through a reviewed, minimized channel — never as a raw firehose to a vendor.

04

Backups and cold copies

Disaster-recovery copies are held at secondary sites that are themselves inside the jurisdiction. Geographic redundancy is achieved without geographic export.

Residency is enforced technically, not merely promised

The design assumes that a policy nobody can verify is a policy that will eventually be broken.

01

Geofenced replication

Storage and replication layers are configured against an explicit allowlist of in-territory destinations. Attempts to write or stream to an unlisted location fail closed rather than proceeding quietly.

02

Egress as an exception

Data leaving the boundary requires a named policy, an authorized approver, and a logged event. Cross-border movement is an auditable action with an owner, not an ambient property of the network.

03

Cryptographic residency proof

The tamper-evident ledger lets the state demonstrate that records existed inside the boundary and were not altered. Residency claims are backed by hash-chain evidence rather than a vendor's assurance.

04

Post-quantum protection in transit

Data that must move between in-nation sites is protected with ML-DSA-65 (FIPS 204) signatures and post-quantum-safe channels. Interception of a domestic link does not yield forgeable or future-decryptable traffic.

Residency without ownership is a longer leash, not sovereignty

The state holds the material that makes the system sovereign — keys and weights — inside the same boundary as the data.

01

Owner holds the keys

Signing and settlement keys are generated and held by the state or its designated institution inside the boundary. The operator cannot transact or settle on the owner's behalf without the owner's keys.

02

Owner holds the weights

Sovereign AI weights are the property of the nation that trained them. Access to run, fine-tune, or export a model is governed by the owner, not by the party that supplied the training stack.

03

Custody of infrastructure

Physical and administrative custody of the facilities can transfer to the state under defined terms. The architecture is designed so that operation does not depend on a foreign entity retaining root.

04

Exit without hostage data

Because keys, weights, and data are already in-territory, a change of operator does not require repatriating assets from abroad. There is no offshore copy to negotiate back.

The boundary is something an auditor can walk and verify

In-nation regulators and auditors can inspect the residency claim directly rather than reading a data-processing addendum.

01

Auditable boundary map

The set of facilities, replicas, and network egress points is documented and inspectable. An auditor can enumerate exactly where sovereign data can and cannot reside.

02

Immutable movement record

Every authorized cross-boundary event is recorded in the hash-chained ledger. Reviewers reconstruct what left, when, and under whose authority without trusting operator recollection.

03

Independent inspection

External audit of the residency controls is part of the production-hardening path now underway. The design intent is that a regulator verifies enforcement rather than accepting attestation.

04

Standing to enforce

Because the infrastructure sits under the host state's law, the jurisdiction retains legal standing over the data and facilities. Residency is backed by enforceable sovereignty, not only by configuration.

Build it sovereign.

Talk to us about in-nation and data residency in a sovereign deployment.