Deployed into your Azure tenant, under your subscription. UK-South by default, customer-managed keys, egress to vetted endpoints only. Built for sovereign deployment - not retrofitted.
US CLOUD Act exposure. US-hosted multi-tenant SaaS is hard to reconcile with OFFICIAL-SENSITIVE supply-chain data - data residency, customer-managed keys and audit-host obligations put most TPRM platforms out of scope. This was built sovereign from day one.
For OFFICIAL-SENSITIVE supply-chain data, where the platform runs and who holds the keys is the deciding factor, not a footnote. The two columns below set the problem with US-hosted multi-tenant SaaS against the sovereign deployment model that was designed for this work from the start.
US-hosted multi-tenant SaaS is hard to reconcile with OFFICIAL-SENSITIVE supply-chain data. Data residency, customer-managed keys and audit-host obligations put most TPRM platforms out of scope.
Deployed into your Azure tenant, under your subscription. UK-South by default. Customer-managed Key Vault keys. Egress to vetted endpoints only. Auditable on request.
Sovereign deployment is the sum of several controls working together, not a single hosting choice. The capabilities below - customer-tenant deployment, customer-managed keys, UK data residency, air-gap capability and HMG/NCSC alignment - are what put supplier assurance inside your own boundary rather than someone else's cloud.
Single-tenant in YOUR Azure subscription - never shared infrastructure.
Encryption keys stay in your Key Vault. We never see them. Rotate at will.
Default UK-South. No US CLOUD Act exposure. No transatlantic transfer.
Signed corpus bundles for nuclear, classified or zero-egress deployments.
Built against CAF v4.0. Crown Marketplace ready. G-Cloud listed.
Sovereignty turns on a few figures that an accreditor will ask about first. The four below - 13 CNI sectors covered, UK data residency, no US CLOUD Act exposure and 256-bit customer-managed keys - are the ones that decide whether a platform is in scope for sensitive work.
Standing the platform up in your own tenant follows a clear path from classification to independent audit. The five stages below - classify, provision, assess, operate and audit - keep the data inside your subscription throughout, with NCSC CAF v4.0 assessment running against your supplier base once it is live.
A sovereign deployment has to answer to the regimes UK public-sector and CNI organisations are actually held to. The six below - NCSC CAF v4.0, Government Security handling caveats, ISO 27001:2022, Cyber Essentials Plus, the NIS Regulations 2018 and UK GDPR/DPA 2018 - are mapped at the control level rather than claimed in the abstract.
One product fits the full classification spectrum rather than forcing a choice between platforms. The three patterns below - managed SaaS for OFFICIAL, your own Azure tenant with customer-managed keys for OFFICIAL-SENSITIVE, and a fully air-gapped build for classified work - are the same platform deployed to match the sensitivity of your data.
UK-South hosted, multi-tenant. For OFFICIAL only.
Deployed to YOUR Azure tenant, CMKs. Recommended default.
No network egress. Signed corpus bundles on schedule.
We’ll walk OFFICIAL-SENSITIVE handling against your specific deployment.