Inference stays local
Prompts, model weights, and generated responses for core assistant flows are processed entirely on the device you deployed — no request leaves the hardware to reach a Sovra or third-party API.
Most vendors ask you to trust a data-handling policy. Sovra's core design makes the question mostly moot — inference happens on hardware you control, so there's no cloud data flow to write a policy about in the first place. Here's exactly how that works, and where the limits are.
No summary, the actual path.
Prompts, model weights, and generated responses for core assistant flows are processed entirely on the device you deployed — no request leaves the hardware to reach a Sovra or third-party API.
RAG embeddings, retrieval indexes, and operational logs are written to storage on your own hardware, not a Sovra-hosted database.
If you explicitly enable an optional integration that calls an external service, you choose the provider and region. Nothing is silently routed off-device.
There is no default pipeline that sends your prompts, documents, or logs anywhere to train a model. See the Privacy Policy for the full terms.
Because inference doesn't require outbound network access, devices can run in fully air-gapped environments — facilities that cannot have any external connectivity.
Since data doesn't leave the device, it never needs to cross a border in the first place — the strongest form of data residency is data that stays put.
Core assistant, retrieval, and validated command execution all function with no internet connection once a device is deployed and configured.
Trust means telling you what isn't true yet, too.
Sovra does not currently hold formal certifications like ISO 27001 or SOC 2. Our privacy posture today is architectural (data locality by design), not certified. If your procurement process requires a specific certification, tell us — info@sovraai.de.
Sovra doesn't replace standard device security practice — disk encryption, physical access control, and OS patching on your hardware remain your responsibility, same as any on-prem system.
If you wire Sovra to an external system, that system's own security posture applies to that integration — we can't retroactively secure a third party.
Talk to us directly about your regulatory environment and deployment constraints.