Sovereign Deployment
You operate the infrastructure. You hold the root of trust.
Sovereign Deployment is for organizations whose requirement is not confidentiality alone but control: control of the infrastructure, the enrollment authority, the audit domain and the process by which software changes. There is no universal Tunnel master key.
- Customer-operated
- Customer-held roots
- Air-gap capable
- HSM integration
What comes under your control
Sovereignty is a list of specific things, not an adjective.
Each item below moves from the vendor's domain into the customer's. That is what the word is being used to mean here.
Customer-controlled infrastructure
Customer-held enrollment authority
Dedicated or isolated deployment
On-premises deployment
Private-cloud deployment
Approved sovereign hosting
Air-gapped installation
Offline signed updates
Customer-managed HSM integration
Customer-controlled logging and retention
Role separation
No permanent vendor access
The consequence
What sovereignty actually buys.
The practical value of a sovereign deployment is that questions about trust have answers that live inside your organization.
- Jurisdiction
- The infrastructure carrying your traffic sits where you put it, under the legal framework you selected.
- Compulsion
- There is no third-party operator holding a position from which they could be compelled to act on your deployment's infrastructure.
- Continuity
- Operation does not depend on a commercial relationship remaining in place, or on a vendor's infrastructure remaining available.
- Accreditation
- Because the deployment is customer-operated, the applicable authorization path is your own accreditation process rather than a vendor's cloud authorization.
- Attestation
- You can state, on your own authority, who is trusted in your deployment, because you hold the authority that makes the statement.
Customer-controlled deployment reduces third-party infrastructure dependency. In a sovereign deployment there is no universal Tunnel master key and no permanent vendor access capable of decrypting customer content.
In context
Where Sovereign sits
Sovereign is a separate trust domain from Managed, established at build and deployment time.
- A sovereign build accepts no commercial credential, endpoint or account.
- A sovereign deployment does not fall back to commercial infrastructure.
- The complete Tactical Profile posture belongs with sovereign deployment, where the customer holds the enrollment authority it depends on.
- Sovereign deployment is scoped as a program, with the customer's operations and security teams involved from the start.
Next step
Scope a sovereign deployment against your accreditation path.
A private briefing covers infrastructure, key ceremony and HSM custody, the offline update process, role separation and the evidence your own authorizing process will need.