Security Data Sovereignty and Residency

Confidentiality and residency of log and event data

Log and event data is among the most sensitive information an organization holds, so ClearSkies iISOC keeps it confidential by design: stored only in its region of origin, encrypted end to end, reachable only by authorized personnel, and backed by a documented plan for the unlikely event of a breach.

In-region

Data residency by design

Encrypted

In transit and at rest

Least-privilege

Access, fully audited

Why Security Telemetry Requires Data Sovereignty

Security telemetry is uniquely sensitive. Logs and events reveal the structure of a network, the identities of its users and how they behave, the software and versions in use, and the exact signals the defenses generate. That is the same information an attacker would need to plan an intrusion, which is why protecting it is a security control rather than a compliance formality.

COMMITMENT 01

Confidentiality

The data is protected by layered technical and organizational controls, and only authorized personnel can reach it.

See the controls →
COMMITMENT 02

Sovereignty

The data stays within its region of origin, governed by the regulations that apply to the customer's jurisdiction.

See the region model →
COMMITMENT 03

Accountability

If an incident occurs, a documented and phased response is followed, and affected customers are notified within the timelines their contract and the applicable regulations require.

See the response plan →

The platform is built on a sovereign, offline-AI architecture with integrity-protected collection at the edge. Confidentiality is enforced by the architecture rather than promised in a policy.

Where the Data Lives, and Where the AI Runs

Storage and processing are delivered on a regional, onshore basis, which means the data stays in its part of the world rather than being shipped elsewhere for storage or analysis. The difference that matters concerns where the generative and agentic models do their processing.

The data layer is onshore in every region.Held in an approved hosting location inside the region it came from.
The AI layer is in-region in Europe and the Middle East.For the other four regions it is performed in Europe, disclosed and contractually safeguarded.
RegionData residencyAI processing
Europe and the Middle EastIn-region data centersIn-region, on locally hosted models
North AmericaRegional cloud, in-regionPerformed in Europe
South AmericaRegional cloud, in-regionPerformed in Europe
AfricaRegional cloud, in-regionPerformed in Europe
Asia PacificRegional cloud, in-regionPerformed in Europe
The cross-border transfer is never silent. Where AI processing is routed to the European data center, the applicable customer data is transferred to Europe solely for generative and agentic functionality. It is disclosed to the customer, and it is governed by contractual cross-border safeguards such as Standard Contractual Clauses or an equivalent recognized mechanism, so the data remains protected to the same standard while it is processed.

Protected Before It Leaves You, and at Every Stage After

Confidentiality begins at collection rather than on arrival. Logs and events are gathered through ClearSkies iISOC iCollector, which runs inside the customer's own boundary. Before the data leaves that boundary the collector digitally signs and encrypts it at its original fidelity, capturing each record exactly as generated, with no truncation, downsampling or reformatting that could weaken it as evidence.

Signing gives every record a tamper-evident seal, so what the platform stores and analyzes can be shown to be precisely what the customer's systems produced.

Protected Before It Leaves You, and at Every Stage After graph

Confidentiality and sovereignty are protected by a layered set of controls. No single measure stands alone, and each reinforces the others.

01

Approved hosting locations

The data is held only in hosting locations approved for, and sitting within, the appropriate jurisdiction.

02

Access controls

Access is restricted to authorized personnel on a least-privilege basis, governed by contractual and compliance requirements.

03

Encryption

The data is encrypted in transit, as it moves to and across the platform, and at rest while it is stored.

04

Continuous monitoring

The platform is itself monitored continuously for anomalous activity around a customer's data.

05

Retention policies

Clear retention policies govern how long the data is kept and when it is securely disposed of.

06

Documented procedures

Documented operational procedures ensure every one of these controls is applied consistently.

If an Incident Occurs, the Response Is Already Written

Strong preventive controls make a breach unlikely, and responsible security means being prepared for one anyway. ClearSkies follows a documented incident-response plan structured around seven phases, so the response is fast, consistent and accountable rather than improvised.

1Detection
2Containment
3Investigation
4Eradication
5Recovery
6Customer notification
7Post-incident review

ClearSkies notifies affected customers in line with the timelines set out in their contract and the regulations applicable to them, rather than a single global figure.

One Residency Position, Every Component

What differs between components is the kind of data each one collects, and therefore the question a regulated buyer asks about it.

ComponentThe residency question it raises
iCollector, the Collection LayerWhere collection happens, inside the customer boundary, and what leaves it: signed and encrypted records at original fidelity.
TDIR, the Orchestration Layer, and the Centric-AI FabricWhere correlation and model processing take place, the distinction between the storage layer and the AI processing layer.
DNS ShieldWhether internal names leave the customer environment, and where resolution telemetry is held.
Attack Surface MonitoringHow credential material found in external exposure intelligence is handled, and the consent position for monitoring assets and third parties.
Endpoint Threat Monitoring and ResponsePer-region storage of endpoint telemetry, retention, and the consent position for contractor and third-party devices.
Identity Threat ProtectionWhere identity and authentication metadata is held.
Active Defense and the AI-SecOps Autonomous AnalystsWhere decoy interaction records and autonomous case records are held, and how long they are retained.

Control-level mapping to the frameworks a customer reports against is held by the Regulatory Frameworks core function.

From Data Sovereignty Claims to Verifiable Controls

Sovereignty is where a platform either clears procurement or does not.

The outcomeWhat produces it
Residency can be evidenced rather than assertedApproved hosting locations per region, with the AI processing layer stated separately from the storage layer.
The data is protected before it leaves the customer boundarySigning and encryption at the point of collection, at original fidelity.
A cross-border transfer is never a surpriseDisclosure to the customer and a recognized contractual mechanism, rather than a silent routing decision.
The bad day is planned for, not improvisedA documented seven-phase response, with notification in line with the contract and the applicable regulations.
Evidence is available for a supervisor without a special exerciseDocumented procedures, audited access and defined retention, applied consistently rather than case by case.

A platform that promises confidentiality asks to be trusted. A platform that enforces it in the architecture can be checked, which is the difference between an assurance and a control.