TRUST CENTER
Security and data sovereignty
This page summarizes Sur's security architecture, data-sovereignty commitments, and control-mapped controls.
Data-sovereignty commitments
- Zero default data egress: the appliance makes no outbound calls by default.
- Air-gap capable: fully functional offline.
- Customer ownership: all indexes, logs, and evidence packs belong to your institution.
- No default remote access: support access is customer-initiated, logged, and time-boxed.
Control mappings
We present our controls designed to support KVKK, BDDK, TCMB, SPK, and MASAK obligations, mapped to each regulation.
Controls are also designed to support international AI-management (ISO/IEC 42001) and information-security (ISO/IEC 27001) requirements.
Levels of assurance
The assurance that protects your data comes in two forms: structural (physical or technical isolation of the hardware) and contractual (a promise). Structural is stronger. In a regulated institution, classified and regulated data requires the top rung.
Owned hardware
Sur sits hereAir-gapped, on-prem, institution-owned GPUs. Zero egress; the assurance is the physical boundary itself.
Attested compute
Dedicated or confidential computing with hardware attestation: the workload runs in a verifiable enclave.
ZDR cloud
A closed model under a zero-data-retention contract. Assurance rests on a contract, not on isolation.
Standard third-party
Consumer or default API. Prompts and outputs may be retained or trained on; treat as extraction-prone.
This framework summarizes the industry’s levels of assurance. Sur sits at the top — structural — rung for classified and regulated data.
National strategy & standards alignment
Sur is designed in line with the principles of Türkiye's national AI direction: domestic and national production, data sovereignty, and human-supervised, trustworthy AI. Human oversight and final approval are essential in decisions (Vezir, Muhafız); data stays within the institution's boundary (KVKK, Law 6698); governance and information security are built to support ISO/IEC 42001 and 27001 requirements (Divan, Mizan, Mühür).
Sur is an independent product aligned with the direction of these documents; it makes no claim of official approval, certification, or selection.
Documents & policies