SOVEREIGNTY FRAMEWORK

Data sovereignty is a decision

Sovereignty comes not from a single product but from the decisions you make across the technology stack. This framework gives a regulated institution a decision tree and the levels of assurance to route every workload to the right rung.

Decision tree

Sovereignty is a series of decisions across the technology stack. The tree below routes each workload to the right assurance tier by its data class.

  1. 01

    What data does this workload run on?

    Public / non-sensitive information
    Commercial cloud is enough Not Sur For tasks that need no sovereignty, standard cloud is cost-effective; Sur is not required.
    Personal, customer, or regulated data
    Keep evaluating
  2. 02

    Might you have to defend the answer later?

    Credit/underwriting decision, AML investigation, regulator correspondence

    Yes — it must be auditable
    Sur · Mühür + Mizan Sur A sealed, sourced, verifiable answer and a timestamped evidence pack.
    No — still regulated data
    Keep evaluating
  3. 03

    Can the data leave the institution’s boundary?

    No / air-gap required
    Sur · on-prem, air-gapped Sur Owned hardware — Tier 1 structural assurance, zero egress.
    Low sensitivity, contractual assurance accepted
    ZDR cloud (Tier 3) Not advised Contract-based assurance; not recommended for regulated core data.

Every path for classified and regulated data ends at Sur — at structural assurance. Public work is deliberately ceded to commercial cloud.

Levels of assurance

The assurance that protects your data comes in two forms: structural (physical or technical isolation of the hardware) and contractual (a promise). Structural is stronger. In a regulated institution, classified and regulated data requires the top rung.

Structural Contractual
01 Structural

Owned hardware

Sur sits here

Air-gapped, on-prem, institution-owned GPUs. Zero egress; the assurance is the physical boundary itself.

Workload class Classified / regulated core data
02 Structural

Attested compute

Dedicated or confidential computing with hardware attestation: the workload runs in a verifiable enclave.

Workload class Sensitive workflows
03 Contractual

ZDR cloud

A closed model under a zero-data-retention contract. Assurance rests on a contract, not on isolation.

Workload class Low-sensitivity tasks
04 Contractual

Standard third-party

Consumer or default API. Prompts and outputs may be retained or trained on; treat as extraction-prone.

Workload class Public / non-sensitive info
Strongest Weakest

This framework summarizes the industry’s levels of assurance. Sur sits at the top — structural — rung for classified and regulated data.

National strategy & standards alignment

Sur is designed in line with the principles of Türkiye's national AI direction: domestic and national production, data sovereignty, and human-supervised, trustworthy AI. Governance and information security are built to support ISO/IEC 42001 and 27001 requirements. For detail and regulatory mappings, see the Trust Center.