SOVEREIGNTY FRAMEWORK
Data sovereignty is a decision
Sovereignty comes not from a single product but from the decisions you make across the technology stack. This framework gives a regulated institution a decision tree and the levels of assurance to route every workload to the right rung.
Decision tree
Sovereignty is a series of decisions across the technology stack. The tree below routes each workload to the right assurance tier by its data class.
- 01
What data does this workload run on?
Public / non-sensitive informationCommercial cloud is enough Not Sur For tasks that need no sovereignty, standard cloud is cost-effective; Sur is not required.Personal, customer, or regulated dataKeep evaluating - 02
Might you have to defend the answer later?
Credit/underwriting decision, AML investigation, regulator correspondence
Yes — it must be auditableSur · Mühür + Mizan Sur A sealed, sourced, verifiable answer and a timestamped evidence pack.No — still regulated dataKeep evaluating - 03
Can the data leave the institution’s boundary?
No / air-gap requiredSur · on-prem, air-gapped Sur Owned hardware — Tier 1 structural assurance, zero egress.Low sensitivity, contractual assurance acceptedZDR cloud (Tier 3) Not advised Contract-based assurance; not recommended for regulated core data.
Every path for classified and regulated data ends at Sur — at structural assurance. Public work is deliberately ceded to commercial cloud.
Levels of assurance
The assurance that protects your data comes in two forms: structural (physical or technical isolation of the hardware) and contractual (a promise). Structural is stronger. In a regulated institution, classified and regulated data requires the top rung.
Owned hardware
Sur sits hereAir-gapped, on-prem, institution-owned GPUs. Zero egress; the assurance is the physical boundary itself.
Attested compute
Dedicated or confidential computing with hardware attestation: the workload runs in a verifiable enclave.
ZDR cloud
A closed model under a zero-data-retention contract. Assurance rests on a contract, not on isolation.
Standard third-party
Consumer or default API. Prompts and outputs may be retained or trained on; treat as extraction-prone.
This framework summarizes the industry’s levels of assurance. Sur sits at the top — structural — rung for classified and regulated data.
National strategy & standards alignment
Sur is designed in line with the principles of Türkiye's national AI direction: domestic and national production, data sovereignty, and human-supervised, trustworthy AI. Governance and information security are built to support ISO/IEC 42001 and 27001 requirements. For detail and regulatory mappings, see the Trust Center.