European Sovereign AI
Built in Europe. Designed for strategic industries.
Compass is engineered, hosted and operated in Europe — for organizations that cannot afford to put their commercial data, or their decisions, in someone else's jurisdiction.
European Sovereign AI
European architecture
Designed and engineered in Europe. Hosted on sovereign infrastructure. Operated by European teams.
Data sovereignty
Your data stays in your jurisdiction. Private deployment available. No training on customer data without explicit consent.
Compliance by design
GDPR and AI Act compliant from day one. SOC 2 roadmap. Built for regulated industries from the start.
Sovereign deployment
Cloud, private cloud, or on-premise. Configurable to the security posture your sector requires.
Operating principles
How we operate, by default.
Sovereignty is not a deployment toggle — it is how the platform is designed, hosted and operated end-to-end.
European jurisdiction
The company, the engineering team and the operations team are based in the European Union. Contracts, governance and accountability sit under European law.
EU-resident infrastructure
Production workloads run on infrastructure located in the European Union. Data residency is configurable per customer and per workload.
No training on customer data
Customer data is never used to train shared or third-party models. Models that operate on your data are scoped to your tenant, with explicit consent required for anything beyond that.
Human-in-the-loop by default
Compass recommends; people decide. Every consequential action carries an evidence trail and a named reviewer — designed to be defensible in front of audit, regulators and your own governance.
Open and portable
Your ontology, your data and your decisions are exportable. No proprietary lock-in on the artifacts that describe your business.
Auditable by design
Every recommendation carries its sources, signals, model version and reviewer. Logs are retained per your policy and exportable to your SIEM.
Deployment options
Four deployment modes. One platform.
Compass adapts to the security posture of the workload — from shared multi-tenant SaaS to fully isolated sovereign environments.
EU SaaS
Shared infrastructure operated in the EU. Fastest path to value for commercial workloads that do not require isolation.
Dedicated tenant
Dedicated environment for your organization. Same managed operations, isolated data plane and isolated model invocations.
Private cloud
Deployed into your cloud account in a region you choose. You keep network, identity and key control; we operate the platform.
Sovereign / on-prem
Air-gapped or sovereign-cloud deployment for sensitive public, defence and regulated workloads. No outbound data flow by default.
Shared responsibility
What we operate. What stays with you.
Sovereignty works when the boundaries are explicit. This is how responsibility is split between Compass and your organization.
Compass operates
- Platform, services and underlying models
- EU-resident hosting and patching
- Encryption in transit and at rest
- Tenant isolation and access controls
- Continuous monitoring of the platform
- Vulnerability management and incident response
You control
- Your data, your ontology and your decisions
- User accounts, roles and permissions
- Which sources and integrations you connect
- Retention windows and deletion requests
- Approval and review of consequential actions
- Export of logs and artifacts to your systems
For the full security architecture, see the security page.
Designed for sectors where sovereignty matters.
- Defence
- Banking
- Telecom
- Utilities
- Critical infrastructure
Common questions
Sovereignty, in practice.
- Where is our data stored?
- In the European Union by default. You choose the region within the EU; for private-cloud and sovereign deployments, you choose the account and the jurisdiction.
- Do you train your models on our data?
- No. Customer data is not used to train shared or third-party models. Any tenant-scoped tuning happens only with your explicit written consent and stays inside your tenant.
- Can Compass be deployed without internet egress?
- Yes. Sovereign and on-prem deployments support fully isolated environments with no outbound data flow. Model invocations and data processing happen inside the boundary you define.
- How is sub-processor and supply-chain risk managed?
- Sub-processors are kept to a minimum, listed publicly, and reviewed before being introduced. For sovereign deployments, the sub-processor surface is reduced to what runs inside the boundary.
- How does Compass align with GDPR and the EU AI Act?
- Compass is designed around the principles both require: lawful basis, data minimization, purpose limitation, transparency, human oversight, traceability and risk management. The combination of evidence trail, human-in-the-loop and EU operations is intentional.
- Who can we talk to about security and compliance?
- Our security and compliance team responds to questionnaires, supports DPIAs and can review architecture under NDA. Start with security@marketlabs.tech or contact us through the form.
Talk to us about sovereign deployment.
Architecture, hosting, compliance, deployment — your questions, our team.