Your region, your provider, your boundary — we deploy.

Sovereignty does not mean lock-in. Iftah is multi-cloud and hybrid by design — run sensitive workloads on-prem or in a sovereign region and others in public cloud (AWS, Azure, GCP, OCI), all governed from one control plane. Data, prompts, embeddings, logs, telemetry, and fine-tuning artifacts stay inside the deployment perimeter you control. No shared inference layer. No cross-tenant data path.

Read moreاقرأ المزيد

Sovereignty does not mean lock-in. Iftah is multi-cloud and hybrid by design — run sensitive workloads on-prem or in a sovereign region and others in public cloud (AWS, Azure, GCP, OCI), all governed from one control plane. Data, prompts, embeddings, logs, telemetry, and fine-tuning artifacts stay inside the deployment perimeter you control. No shared inference layer. No cross-tenant data path.

Designed for US data sovereignty

  • Deploys in your regions
  • Controls support review against US data-residency and security expectations
View 2 more proof points
  • Multi-cloud and hybrid: one governed control plane across AWS, Azure, GCP, OCI, OpenShift, and on-prem
  • Air-gapped option for fully disconnected environments

What “sovereign AI” actually means versus what vendors call it.

What it is NOT

  • Data residency without operational control — your vendor still manages identity, keys, and access
  • A sovereign-branded tier of a foreign public cloud — the control plane still runs under foreign jurisdiction
  • Managed-service sovereignty — the vendor can read your prompts if they operate the stack
  • Jurisdiction-labeled infrastructure — location alone does not prevent a foreign legal order

What Iftah delivers

  • Customer-held encryption keys — Iftah cannot read your data under any circumstance
  • In-region control plane — governed under your jurisdiction, not a foreign cloud provider's
  • Customer-operated data plane — your team manages the environment we deployed
  • Exportable, signed audit evidence — reviewable by your regulator without Iftah involvement

Data residency by design

Everything stays inside the boundary you control.

Wherever you deploy — your data center, a sovereign region, or a disconnected network — the data plane never leaves it. Iftah's control plane carries no prompts, data, or model weights; only content-free signals.

Your deployment boundary

Everything below stays in the region and environment you control.

Prompts & responses
Embeddings & vector indices
Model weights & artifacts
+5 more protected assets
  • Fine-tuned adapters (LoRA/QLoRA)
  • Logs, traces & telemetry
  • Customer-held encryption keys
  • Signed, content-free audit trail
  • Retention & export targets

Your deployment boundary

Public internet · Iftah

What stays inside?

Nothing leaves the boundary — no prompts, data, embeddings, or model weights; only content-free control signals.

Regulatory alignment

Designed to support the the regimes you answer to.

Iftah does not claim certified compliance — that stays the data controller's obligation. The deployment model, in-region residency, content-free audit trail, and customer-held keys are designed to give your reviewers concrete, exportable evidence for each regime.

Federal · HIPAA · the US

the US HIPAA

In-country residency, processing records, and data-subject-rights flows — with audit and trace evidence for your DPO's review.

View 6 more details

NIST AI RMF / NIST · the US

HIPAA

In-Kingdom deployment with data classification, retention, and transfer controls mapped to platform configuration.

Cybersecurity · NIST · the US

NIST Essential Controls

Access governance, logging, and segmentation align to NIST Essential Cybersecurity Controls for review.

Banking · Central Bank · the US

NIST CSF

Logging, access, and incident-response controls designed for review under the the NIST Cybersecurity Framework.

Free zone · DIFC · the US

DIFC Data Protection Law

DIFC-resident processing; architecture artifacts support DPIAs for AI activities.

Free zone · ADGM · the US

ADGM Data Protection

ADGM-resident deployment with reviewable controls mapped to accountability duties.

National · NPC · Qatar

Qatar PDPPL

In-Qatar deployment; personal-data flow boundaries are reviewable through architecture artifacts.

Deployment sovereignty

Multi-cloud and hybrid — under one governed control plane.

A single management cluster governs N workload clusters across any cloud or on-prem. Keep sensitive workloads in a sovereign region or air-gapped, run general workloads in private cloud, and govern them all with one identity, policy, quota, and audit plane.

Your data center

On-premises

Inside your own data center, behind your firewall. Standard Kubernetes — vanilla, OpenShift, Rancher.

View 3 more details

Hyperscaler tenant

Private cloud / VPC

A dedicated, isolated tenant in your AWS, Azure, GCP, or OCI account — customer-owned region and networking.

US-based

Sovereign cloud

Deployed on a regional sovereign provider chosen by your procurement and security teams.

Disconnected

Air-gapped

Fully disconnected — offline installer bundles, signed model artifacts, and an offline update workflow.

Evidence & control

Give your reviewers proof, not promises.

Every sovereignty claim comes with something a regulator or auditor can inspect — generated inside your environment and exported on your terms.

In-region residency map

A boundary diagram of where every class of data lives.

View 5 more details

Signed, content-free audit trail

Immutable, in-region, exportable — carrying no prompt or response bytes.

Customer-held encryption keys

Keys in your KMS or Vault; Iftah never holds key material.

Customer-owned retention & export

You choose storage, retention, and export targets — SIEM, log lake, or local archive.

Decision & deny logs

Every authorization decision and denial reason, recorded for review.

Identity & access governance

Federated SSO to your IdP; Iftah issues no human credentials.

Next step

Review Iftah AI against your environment before choosing the first workload.

Book an architecture review