LOADING…
Platform  /  Datasheets  /  Sovereign Supplier Assurance
UK public sector & CNI

Your tenant.Your keys. Your data.

Deployed into your Azure tenant, under your subscription. UK-South by default, customer-managed keys, egress to vetted endpoints only. Built for sovereign deployment - not retrofitted.

All datasheets
13 CNI sectors100% UK residency256-bit customer keys
0

US CLOUD Act exposure. US-hosted multi-tenant SaaS is hard to reconcile with OFFICIAL-SENSITIVE supply-chain data - data residency, customer-managed keys and audit-host obligations put most TPRM platforms out of scope. This was built sovereign from day one.

The challenge

Off-the-shelf SaaS is not OFFICIAL-SENSITIVE.

For OFFICIAL-SENSITIVE supply-chain data, where the platform runs and who holds the keys is the deciding factor, not a footnote. The two columns below set the problem with US-hosted multi-tenant SaaS against the sovereign deployment model that was designed for this work from the start.

The problem
Off-the-shelf SaaS is not OFFICIAL-SENSITIVE.

US-hosted multi-tenant SaaS is hard to reconcile with OFFICIAL-SENSITIVE supply-chain data. Data residency, customer-managed keys and audit-host obligations put most TPRM platforms out of scope.

The approach
Sovereign by design.

Deployed into your Azure tenant, under your subscription. UK-South by default. Customer-managed Key Vault keys. Egress to vetted endpoints only. Auditable on request.

Why E2ERisk

Why teams choose us.

Sovereign deployment is the sum of several controls working together, not a single hosting choice. The capabilities below - customer-tenant deployment, customer-managed keys, UK data residency, air-gap capability and HMG/NCSC alignment - are what put supplier assurance inside your own boundary rather than someone else's cloud.

Customer-tenant deployment

Single-tenant in YOUR Azure subscription - never shared infrastructure.

Customer-managed keys

Encryption keys stay in your Key Vault. We never see them. Rotate at will.

UK data residency

Default UK-South. No US CLOUD Act exposure. No transatlantic transfer.

Air-gap capable

Signed corpus bundles for nuclear, classified or zero-egress deployments.

HMG / NCSC alignment

Built against CAF v4.0. Crown Marketplace ready. G-Cloud listed.

At a glance

The numbers that matter.

Sovereignty turns on a few figures that an accreditor will ask about first. The four below - 13 CNI sectors covered, UK data residency, no US CLOUD Act exposure and 256-bit customer-managed keys - are the ones that decide whether a platform is in scope for sensitive work.

13
CNI sectors covered
100%
UK data residency
0
US CLOUD Act exposure
256-bit
customer-managed keys
How it works

Five steps, evidence underneath.

Standing the platform up in your own tenant follows a clear path from classification to independent audit. The five stages below - classify, provision, assess, operate and audit - keep the data inside your subscription throughout, with NCSC CAF v4.0 assessment running against your supplier base once it is live.

01
Classify
Confirm OFFICIAL / OFFICIAL-SENSITIVE + scope
02
Provision
Deploy to your Azure subscription, CMKs configured
03
Assess
NCSC CAF v4.0 against your supplier base
04
Operate
Continuous posture monitoring in your tenant only
05
Audit
NCSC-cleared review + customer-led external audit
Framework alignment

Mapped at the control level.

A sovereign deployment has to answer to the regimes UK public-sector and CNI organisations are actually held to. The six below - NCSC CAF v4.0, Government Security handling caveats, ISO 27001:2022, Cyber Essentials Plus, the NIS Regulations 2018 and UK GDPR/DPA 2018 - are mapped at the control level rather than claimed in the abstract.

NCSC CAF v4.0Mandatory for OES + CNI + gov tier. Outcome-based scoring.
Government SecurityOFFICIAL / OFFICIAL-SENSITIVE handling caveats
ISO 27001:2022Required for HMG suppliers handling sensitive data
Cyber Essentials +Mandatory for HMG contracts above £100k
NIS Regulations 2018Operators of essential services obligations
UK GDPR / DPA 2018Data-processor obligations within the UK boundary only
Deployment

Run it your way.

One product fits the full classification spectrum rather than forcing a choice between platforms. The three patterns below - managed SaaS for OFFICIAL, your own Azure tenant with customer-managed keys for OFFICIAL-SENSITIVE, and a fully air-gapped build for classified work - are the same platform deployed to match the sensitivity of your data.

OFFICIAL - managed SaaS

UK-South hosted, multi-tenant. For OFFICIAL only.

OFFICIAL-SENSITIVE - your Azure

Deployed to YOUR Azure tenant, CMKs. Recommended default.

CLASSIFIED - air-gapped

No network egress. Signed corpus bundles on schedule.

Next step

Book a sovereignty review.

We’ll walk OFFICIAL-SENSITIVE handling against your specific deployment.

All datasheets