Skip to content
The Sovereign Standard · Technical Substance

Capability inside your environment. Not access to someone else's.

Most AI tools deliver capability through a third-party API. Your data leaves your environment, is processed on overseas servers, and returns with no audit trail you control. For an organisation handling regulated data, that is an unauthorised disclosure waiting to be found.

BlackVault™ inverts the model. We deploy verified open-source large language models inside your own AWS, Azure, GCP, private cloud, or on-premise environment. The model runs where your data lives. Nothing is sent out. Nothing is shared. Every inference is logged, retained, and auditable.

And it does not stand still. We fine-tune the model continuously against your proprietary systems and data, and operate the environment — architecture, security, and monitoring — for as long as you run it. The capability stays current, and stays inside your boundary, permanently.

The Three Layers

One architecture, layered from the infrastructure up.

Layer 01 · Sovereign Infrastructure

Your environment, locked down

Your own environment — AWS, Azure, GCP, private cloud, or on-premise — region-locked by policy, network-isolated with no outbound path at inference, AES-256 at rest and TLS 1.3 in transit. The verified open-source model runs here, where your data lives.

Layer 02 · Compliance Governance

Twelve documents, kept alive

Twelve version-controlled governance documents — the evidence a regulator asks for, prepared before they ask and kept current by the managed service, not filed away after go-live.

Layer 03 · Sector Compliance Module

Matched to your regulator

The regulatory obligations specific to your sector — one module matched to your regulator, layered on top of the baseline framework.

Security Baseline

Every claim is verifiable.

The controls below are implemented, documented, and maintained on every deployment — for the life of the engagement, not a roadmap.

Dedicated isolated environment — no shared tenancy.
RBAC access control · AES-256 encryption at rest · TLS 1.3 in transit.
Full inference audit trail, retained and version-controlled.
Continuous fine-tuning on your proprietary data, version-controlled and logged.
Annual independent penetration testing by a certified third party.
ACSC Essential Eight controls implemented; Maturity Level uplift included in scope.
ISO/IEC 42001:2023 AI management system aligned — governance for the model lifecycle.
ISO/IEC 27001:2022 certified information security management system.

See what sovereign deployment looks like in your environment.