Keep AI processing, gateways, telemetry, and evidence within approved environments.
Control where prompts, gateway traffic, telemetry, findings, enforcement, and audit evidence are processed and retained. Select localized regional cloud services, self-hosted components, hybrid data planes, or fully air-gapped deployment according to geographic, regulatory, privacy, connectivity, and security requirements.
Global AI programs must meet different sovereignty requirements without fragmenting security and governance. SaaS-only deployment may be inappropriate when:
PointGuard AI provides a comprehensive solution for placing AI security services and sensitive processing where sovereignty requirements demand:
1. Select approved regions. Run localized services within regional AWS or Azure environments to keep processing inside required geographic boundaries.
2. Self-host required services. Deploy selected capabilities or the complete platform within customer-controlled infrastructure and existing security baselines.
3. Localize sensitive components. Use a hybrid model that self-hosts the data plane, MCP Security Gateway, and other data-sensitive processing while retaining approved centralized management.
4. Operate fully air-gapped. Run platform capabilities without external network dependencies and route telemetry through internal security and audit workflows.
Organizations retain consistent AI security and governance while controlling sensitive processing, evidence, and data location.
Applicable framework risks and controls include: