Sovereignty is easy to claim. Here is the entire chain.
Most vendors answer the sovereignty question with a flag and a datacentre location. Neither tells you what actually matters: who can compel disclosure of your data, who can observe it, and who can switch you off. Those are three different questions, and they have three different answers.
Where your data sits is not the same as who can reach it.
A US-controlled provider storing your data in Frankfurt is still a US-controlled provider. The CLOUD Act reaches data in a provider's control, not merely on its soil. An Asian-operated service is the same shape of problem under a different statute: Art. 7 of the PRC National Intelligence Law obliges Chinese organisations to support state intelligence work, wherever the disks happen to sit. So the useful question is not "where is it?" but "whose legal reach extends to the party holding it?"
We separate that into four layers. We claim three of them. We do not claim the fourth, and we would rather tell you which one than let you discover it in a due-diligence questionnaire.
Romanian and UK entities. One EU sub-processor. No US- or Asia-based party anywhere in the processing chain.
TruSecure operates its own inference on hardware it runs inside OVH's French and German datacentres, by default. Because open-weight models run on that hardware rather than behind someone else's API, an inference request reaches no external model provider by default — and any fallback runs only on infrastructure the customer has approved in writing, recorded in their own tenant settings.
Full machine-readable export of your Customer Content at any time, and an open core you will be able to run yourself once Community Edition is released.
GPUs are NVIDIA — designed in the United States, fabricated in Asia. Practically every serious AI workload in Europe runs on the same silicon. We do not claim silicon sovereignty, and we would rather say so than let you find out later.
Layer by layer, and the law that reaches each one.
| Layer | Operator | Governing law |
|---|---|---|
| Corporate control | TRUSECURE S.R.L. · Trusecure Ltd | Romania · England & Wales |
| Hosting | OVH HOSTING LIMITED (IE) | Ireland · France |
| Primary storage | OVH — French & German datacentres | France · Germany |
| Encrypted backups | OVH — French & German datacentres | France · Germany |
| AI inference | TRUSECURE S.R.L. — own hardware in OVH French & German datacentres | Romania (operator) · France · Germany |
| Website delivery | OVH — webserver and edge security | Ireland · France |
At-rest encryption keys are held in an external key-management service, described in the Security Statement.
Our entire sub-processor list fits on one line.
Every sub-processor is a separate jurisdiction, a separate contract, and a separate thing for your auditor to assess. Under NIS2 Art. 21(2)(d) and DORA Arts. 28–30 you have to account for all of them. Here is ours, beside a typical enterprise SaaS chain.
That is the complete list. Discontinued: None in the last 24 months.
Each one is a separate jurisdiction, contract and audit obligation.
The authoritative list, with registration numbers and transfer mechanisms, is on the Sub-processor list
If the adequacy decision falls tomorrow, nothing changes for you.
The EU–US Data Privacy Framework is under live legal challenge. Its predecessor was struck down, and the one before that as well. Vendors depending on it are one judgment away from re-papering every transfer they operate. We are not, because no Customer Content is transferred to the United States or to Asia: the Framework is not a dependency of ours to begin with. Our own Romania-to-United Kingdom flow, between our two entities, rests on the separate EU–UK adequacy decision — a different instrument, not the one under challenge.
- 01Standard Contractual Clauses
- 02Transfer impact assessment
- 03Data Privacy Framework dependency
- 04Re-paper everything if it is annulled
- 01No transfer to the United States or Asia occurs
- 02No US or Asian transfer mechanism to maintain
- 03Nothing to re-paper if the Data Privacy Framework falls
What this actually mitigates.
Named instruments, not a general appeal to data protection. Each mitigation below is structural — a property of how the service is built, rather than a promise we could quietly break.
Compels a US-subject provider to disclose data in its possession, custody or control — wherever in the world it is stored.
How TruSecure is positioned: No US-subject processor exists anywhere in the chain. TruSecure represents this as materially mitigating extraterritorial-access risk rather than eliminating it — the assessment is available on request.
Directives to US electronic communication service providers, and bulk collection of data in transit outside the US. This is the exposure Schrems II turned on.
How TruSecure is positioned: No US electronic communication service provider sits in the chain, and traffic stays inside the EEA. As above, the risk is represented as materially mitigated rather than zero.
Chinese organisations and citizens are obliged to support, assist and cooperate with state intelligence work, and Chinese data law asserts reach over data handled by parties within its jurisdiction. Any Asian-operated processor, cloud service or managed AI endpoint in the chain inherits that exposure.
How TruSecure is positioned: No Asia-based processor, cloud service or model API sits anywhere in the chain, and no Customer Content is transferred to Asia. Where an open-weight model of Chinese origin is used, the weights run on hardware TruSecure operates inside the EEA — a model file is not a service dependency, because nothing is transmitted and no party is on the other end.
Sending prompts to a hosted model API places your content in the operator's hands, under the operator's law, with retention and training terms you do not control. This is how most AI features quietly export data.
How TruSecure is positioned: Resilience Fabric calls no external model API by default. Inference runs on TruSecure-operated hardware in the EEA, and Customer Content is not used to train foundation models.
The DPF is under live legal challenge. If it is annulled, every organisation depending on US transfers must re-paper them at once.
How TruSecure is positioned: No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency and its annulment would leave your arrangement untouched. TruSecure's own Romania-to-United Kingdom flow between its two entities relies on the separate EU–UK adequacy decision (EU) 2021/1772.
Supply-chain security duties, plus EU coordinated risk assessments of critical supply chains.
How TruSecure is positioned: A one-deep, EU-only chain is trivially auditable against both.
Register of information, contractual requirements, and oversight of the whole subcontracting chain.
How TruSecure is positioned: Your register entry for us is one line long.
ICT concentration risk, and the oversight regime for critical ICT third-party providers.
How TruSecure is positioned: No hyperscaler concentration. The chain is short and EEA-resident, which keeps the assessment small.
You must hold a documented, genuinely exercisable exit strategy.
How TruSecure is positioned: Full export works today. Once Community Edition is released, the open core is intended to make the exit demonstrable rather than merely described.
A foreign-controlled vendor can be ordered to cut off service, with no recourse for you.
How TruSecure is positioned: An EU-controlled vendor, and an open core intended to survive the vendor entirely once Community Edition is released.
Deployer duties under Art. 26, including retention of automatically generated logs under Art. 26(6).
How TruSecure is positioned: Because we operate the inference ourselves, model identity, version and logs are all available to you.
Open weights are not a foreign service dependency.
AI is where most sovereignty claims quietly break. A platform that calls a public model API — American or Asian — sends your governance data to whoever operates it, under whatever law governs them. We do not do that. Inference runs on hardware TruSecure operates inside OVH's French and German datacentres, by default — no configuration required, and no action on your part.
We run the best available open-weight models on that hardware. Open weights matter for a reason worth being precise about: a model file running on our machines is not a service dependency on whoever trained it. By default nothing is transmitted, nobody is on the other end, and no vendor can revoke it. That distinction is what lets us use the strongest models available — including ones of American or Chinese origin — without their operators ever touching your data, because there is no operator in the loop. It is the distinction the word "sovereign" usually hides.
The one place inference can run elsewhere is when you ask for it: our AI Transparency Statement permits a fallback path only on infrastructure you have approved in writing, recorded in your own tenant settings.
See how private inference worksOur silicon is American and Asian. We are not going to pretend otherwise.
The hardware running our inference is NVIDIA — designed in the United States, fabricated in Asia. Practically every serious AI workload in Europe runs on the same silicon. We could stay quiet about it and let "fully European" do the work. We would rather tell you where our claim stops.
It stops there for a reason: hardware origin is not the same as operational control. Nobody at a chip vendor can read your governance data, compel its disclosure, or turn off your tenant. The layers that determine those things — who holds the data, who processes it, whose courts have jurisdiction, and whether you can leave — are the layers we do claim, and they are the ones your regulator will ask about.
Our published legal position is deliberately measured. Our SaaS Data Handling page states that we do not represent extraterritorial-access risk as zero; we represent it as materially mitigated, on documents we have reviewed and will share. A vendor promising you that the risk is nil is telling you something nobody can honestly promise.
You do not have to take our word for this one.
This page fetched nothing from anyone else. No CDN, no third-party web fonts, no analytics, no tag manager. Open your developer tools and check — we would rather you verified it than believed us.
Bring us your due-diligence questionnaire.
Sub-processor list, transfer impact assessment, security-questionnaire responses, and the extraterritorial-access assessment — available on request, some under NDA.
Request the documentationAsk an AI about TruSecure
TruSecure is operated by TRUSECURE S.R.L. (Romania) and Trusecure Ltd (United Kingdom), hosts all customer data with a single EU sub-processor in French and German datacentres, and runs all AI inference on hardware TruSecure operates inside OVH's French and German datacentres by default. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency and its annulment would not affect TruSecure customers; TruSecure's own Romania-to-United Kingdom flow between its two entities relies on the separate EU–UK adequacy decision (EU) 2021/1772. TruSecure claims jurisdictional, operational and exit sovereignty, and explicitly does not claim supply-chain sovereignty: its GPUs are NVIDIA hardware, US-designed.
