European Sovereign AI

Built in Europe. Designed for strategic industries.

Compass is engineered, hosted and operated in Europe — for organizations that cannot afford to put their commercial data, or their decisions, in someone else's jurisdiction.

European architecture

Designed and engineered in Europe. Hosted on sovereign infrastructure. Operated by European teams.

Data sovereignty

Your data stays in your jurisdiction. Private deployment available. No training on customer data without explicit consent.

Compliance by design

GDPR and AI Act compliant from day one. SOC 2 roadmap. Built for regulated industries from the start.

Sovereign deployment

Cloud, private cloud, or on-premise. Configurable to the security posture your sector requires.

Operating principles

How we operate, by default.

Sovereignty is not a deployment toggle — it is how the platform is designed, hosted and operated end-to-end.

European jurisdiction

The company, the engineering team and the operations team are based in the European Union. Contracts, governance and accountability sit under European law.

EU-resident infrastructure

Production workloads run on infrastructure located in the European Union. Data residency is configurable per customer and per workload.

No training on customer data

Customer data is never used to train shared or third-party models. Models that operate on your data are scoped to your tenant, with explicit consent required for anything beyond that.

Human-in-the-loop by default

Compass recommends; people decide. Every consequential action carries an evidence trail and a named reviewer — designed to be defensible in front of audit, regulators and your own governance.

Open and portable

Your ontology, your data and your decisions are exportable. No proprietary lock-in on the artifacts that describe your business.

Auditable by design

Every recommendation carries its sources, signals, model version and reviewer. Logs are retained per your policy and exportable to your SIEM.

Deployment options

Four deployment modes. One platform.

Compass adapts to the security posture of the workload — from shared multi-tenant SaaS to fully isolated sovereign environments.

Multi-tenant, EU-resident

EU SaaS

Shared infrastructure operated in the EU. Fastest path to value for commercial workloads that do not require isolation.

Single-tenant, EU-resident

Dedicated tenant

Dedicated environment for your organization. Same managed operations, isolated data plane and isolated model invocations.

Your VPC, your region

Private cloud

Deployed into your cloud account in a region you choose. You keep network, identity and key control; we operate the platform.

Isolated environment

Sovereign / on-prem

Air-gapped or sovereign-cloud deployment for sensitive public, defence and regulated workloads. No outbound data flow by default.

Shared responsibility

What we operate. What stays with you.

Sovereignty works when the boundaries are explicit. This is how responsibility is split between Compass and your organization.

Compass operates

  • Platform, services and underlying models
  • EU-resident hosting and patching
  • Encryption in transit and at rest
  • Tenant isolation and access controls
  • Continuous monitoring of the platform
  • Vulnerability management and incident response

You control

  • Your data, your ontology and your decisions
  • User accounts, roles and permissions
  • Which sources and integrations you connect
  • Retention windows and deletion requests
  • Approval and review of consequential actions
  • Export of logs and artifacts to your systems

For the full security architecture, see the security page.

Designed for sectors where sovereignty matters.

  • Defence
  • Banking
  • Telecom
  • Utilities
  • Critical infrastructure
Common questions

Sovereignty, in practice.

Where is our data stored?
In the European Union by default. You choose the region within the EU; for private-cloud and sovereign deployments, you choose the account and the jurisdiction.
Do you train your models on our data?
No. Customer data is not used to train shared or third-party models. Any tenant-scoped tuning happens only with your explicit written consent and stays inside your tenant.
Can Compass be deployed without internet egress?
Yes. Sovereign and on-prem deployments support fully isolated environments with no outbound data flow. Model invocations and data processing happen inside the boundary you define.
How is sub-processor and supply-chain risk managed?
Sub-processors are kept to a minimum, listed publicly, and reviewed before being introduced. For sovereign deployments, the sub-processor surface is reduced to what runs inside the boundary.
How does Compass align with GDPR and the EU AI Act?
Compass is designed around the principles both require: lawful basis, data minimization, purpose limitation, transparency, human oversight, traceability and risk management. The combination of evidence trail, human-in-the-loop and EU operations is intentional.
Who can we talk to about security and compliance?
Our security and compliance team responds to questionnaires, supports DPIAs and can review architecture under NDA. Start with security@marketlabs.tech or contact us through the form.

Talk to us about sovereign deployment.

Architecture, hosting, compliance, deployment — your questions, our team.