Sovereign Deployment
You operate the infrastructure. You hold the root of trust.
Sovereign Deployment is for organizations whose requirement is not confidentiality alone but control: control of the infrastructure, the enrollment authority, the audit domain and the process by which software changes. There is no universal Tunnel master key.
- Customer-operated
- Customer-held roots
- Air-gap capable
- HSM integration
What comes under your control
Sovereignty is a list of specific things, not an adjective.
Each item below moves from the vendor's domain into the customer's. That is what the word is being used to mean here.
Customer-controlled infrastructure
Customer-held enrollment authority
Dedicated or isolated deployment
On-premises deployment
Private-cloud deployment
Approved sovereign hosting
Air-gapped installation
Offline signed updates
Customer-managed HSM integration
Customer-controlled logging and retention
Role separation
No permanent vendor access
The consequence
What sovereignty actually buys.
The practical value of a sovereign deployment is that questions about trust have answers that live inside your organization.
- Jurisdiction
- The infrastructure carrying your traffic sits where you put it, under the legal framework you selected.
- Compulsion
- There is no third-party operator holding a position from which they could be compelled to act on your deployment's infrastructure.
- Continuity
- Operation does not depend on a commercial relationship remaining in place, or on a vendor's infrastructure remaining available.
- Accreditation
- Because the deployment is customer-operated, the applicable authorization path is your own accreditation process rather than a vendor's cloud authorization.
- Attestation
- You can state, on your own authority, who is trusted in your deployment, because you hold the authority that makes the statement.
Customer-controlled deployment reduces third-party infrastructure dependency. In a sovereign deployment there is no universal Tunnel master key and no permanent vendor access capable of decrypting customer content.
In context
Where Sovereign sits
Sovereign is a separate trust domain from Managed, established at build and deployment time.
- A sovereign build accepts no commercial credential, endpoint or account.
- A sovereign deployment does not fall back to commercial infrastructure.
- The complete Tactical Profile posture belongs with sovereign deployment, where the customer holds the enrollment authority it depends on.
- Sovereign deployment is scoped as a program, with the customer's operations and security teams involved from the start.
Next step
Scope a sovereign deployment against your accreditation path.
An executive briefing covers infrastructure, key ceremony and HSM custody, the offline update process, role separation and the evidence your own authorizing process will need.