What deployment models are available for data sovereignty? Short answer: Two. A fully air-gapped on-premises model where nothing leaves your network, and a hosted or hybrid cloud-assisted model with JWE-encrypted TLS communications to regionally staged servers. Both provide the same sub-200-millisecond local prevention. Comparison Sovereign On-Premises (Air-Gapped) Hosted / Hybrid Cloud-Assisted Data transit boundary 100% contained within customer physically secured server racks JWE-encrypted TLS communications to regional application servers Cross-border flow Zero external network flow; zero outbound telemetry Geographically localized staging to match regional boundaries Regulatory alignment Supports strict national data residency and sovereignty requirements Designed to align with global privacy directives (GDPR, PDPL, and others) Choosing between them The air-gapped model suits government, defense, critical infrastructure, and any organization under strict national residency mandates or operating disconnected environments. The hybrid model suits organizations that want centralized management and cross-fleet reporting while still keeping data within a regional boundary. Prevention is identical in both. The local Detect–Decide–Respond loop runs in the kernel on the endpoint regardless of deployment model — the difference is only where management and reporting infrastructure lives.