TRUST CENTER

Security and data sovereignty

This page summarizes Sur's security architecture, data-sovereignty commitments, and control-mapped controls.

Sovereignty Framework — workload decision tree + levels of assurance

Data-sovereignty commitments

  • Zero default data egress: the appliance makes no outbound calls by default.
  • Air-gap capable: fully functional offline.
  • Customer ownership: all indexes, logs, and evidence packs belong to your institution.
  • No default remote access: support access is customer-initiated, logged, and time-boxed.

Control mappings

We present our controls designed to support KVKK, BDDK, TCMB, SPK, and MASAK obligations, mapped to each regulation.

Controls are also designed to support international AI-management (ISO/IEC 42001) and information-security (ISO/IEC 27001) requirements.

Levels of assurance

The assurance that protects your data comes in two forms: structural (physical or technical isolation of the hardware) and contractual (a promise). Structural is stronger. In a regulated institution, classified and regulated data requires the top rung.

Structural Contractual
01 Structural

Owned hardware

Sur sits here

Air-gapped, on-prem, institution-owned GPUs. Zero egress; the assurance is the physical boundary itself.

Workload class Classified / regulated core data
02 Structural

Attested compute

Dedicated or confidential computing with hardware attestation: the workload runs in a verifiable enclave.

Workload class Sensitive workflows
03 Contractual

ZDR cloud

A closed model under a zero-data-retention contract. Assurance rests on a contract, not on isolation.

Workload class Low-sensitivity tasks
04 Contractual

Standard third-party

Consumer or default API. Prompts and outputs may be retained or trained on; treat as extraction-prone.

Workload class Public / non-sensitive info
Strongest Weakest

This framework summarizes the industry’s levels of assurance. Sur sits at the top — structural — rung for classified and regulated data.

National strategy & standards alignment

Sur is designed in line with the principles of Türkiye's national AI direction: domestic and national production, data sovereignty, and human-supervised, trustworthy AI. Human oversight and final approval are essential in decisions (Vezir, Muhafız); data stays within the institution's boundary (KVKK, Law 6698); governance and information security are built to support ISO/IEC 42001 and 27001 requirements (Divan, Mizan, Mühür).

Sur is an independent product aligned with the direction of these documents; it makes no claim of official approval, certification, or selection.

Documents & policies