Skip to main content
TruSecure — Home
SOVEREIGNTY

Sovereignty is easy to claim. Here is the entire chain.

Most vendors answer the sovereignty question with a flag and a datacentre location. Neither tells you what actually matters: who can compel disclosure of your data, who can observe it, and who can switch you off. Those are three different questions, and they have three different answers.

SV-01 · The distinction

Where your data sits is not the same as who can reach it.

A US-controlled provider storing your data in Frankfurt is still a US-controlled provider. The CLOUD Act reaches data in a provider's control, not merely on its soil. An Asian-operated service is the same shape of problem under a different statute: Art. 7 of the PRC National Intelligence Law obliges Chinese organisations to support state intelligence work, wherever the disks happen to sit. So the useful question is not "where is it?" but "whose legal reach extends to the party holding it?"

We separate that into four layers. We claim three of them. We do not claim the fourth, and we would rather tell you which one than let you discover it in a due-diligence questionnaire.

JurisdictionalWe claim this
Who can compel disclosure?

Romanian and UK entities. One EU sub-processor. No US- or Asia-based party anywhere in the processing chain.

OperationalWe claim this
Who can observe or interrupt?

TruSecure operates its own inference on hardware it runs inside OVH's French and German datacentres, by default. Because open-weight models run on that hardware rather than behind someone else's API, an inference request reaches no external model provider by default — and any fallback runs only on infrastructure the customer has approved in writing, recorded in their own tenant settings.

ExitWe claim this
Can you leave?

Full machine-readable export of your Customer Content at any time, and an open core you will be able to run yourself once Community Edition is released.

Supply-chain originWe do not claim this
Where did the silicon come from?

GPUs are NVIDIA — designed in the United States, fabricated in Asia. Practically every serious AI workload in Europe runs on the same silicon. We do not claim silicon sovereignty, and we would rather say so than let you find out later.

SV-02 · The chain

Layer by layer, and the law that reaches each one.

EU / UK legal reachLayer by layer
Each layer of the TruSecure stack, the entity that operates it, and the law that governs it.
LayerOperatorGoverning law
Corporate controlTRUSECURE S.R.L. · Trusecure LtdRomania · England & Wales
HostingOVH HOSTING LIMITED (IE)Ireland · France
Primary storageOVH — French & German datacentresFrance · Germany
Encrypted backupsOVH — French & German datacentresFrance · Germany
AI inferenceTRUSECURE S.R.L. — own hardware in OVH French & German datacentresRomania (operator) · France · Germany
Website deliveryOVH — webserver and edge securityIreland · France

At-rest encryption keys are held in an external key-management service, described in the Security Statement.

US CLOUD Act · FISA 702 · EO 12333
No party in the chain above is subject to these.
SV-03 · Sub-processors

Our entire sub-processor list fits on one line.

Every sub-processor is a separate jurisdiction, a separate contract, and a separate thing for your auditor to assess. Under NIS2 Art. 21(2)(d) and DORA Arts. 28–30 you have to account for all of them. Here is ours, beside a typical enterprise SaaS chain.

TruSecure1 sub-processor
OVH HOSTING LIMITED
Subsidiary of OVH Groupe SA (France)
French and German datacentres (EEA)

That is the complete list. Discontinued: None in the last 24 months.

Typical enterprise SaaS (illustrative)~25

Each one is a separate jurisdiction, contract and audit obligation.

The authoritative list, with registration numbers and transfer mechanisms, is on the Sub-processor list

SV-04 · Transfers

If the adequacy decision falls tomorrow, nothing changes for you.

The EU–US Data Privacy Framework is under live legal challenge. Its predecessor was struck down, and the one before that as well. Vendors depending on it are one judgment away from re-papering every transfer they operate. We are not, because no Customer Content is transferred to the United States or to Asia: the Framework is not a dependency of ours to begin with. Our own Romania-to-United Kingdom flow, between our two entities, rests on the separate EU–UK adequacy decision — a different instrument, not the one under challenge.

US-hosted platform
  1. 01Standard Contractual Clauses
  2. 02Transfer impact assessment
  3. 03Data Privacy Framework dependency
  4. 04Re-paper everything if it is annulled
TruSecure
  1. 01No transfer to the United States or Asia occurs
  2. 02No US or Asian transfer mechanism to maintain
  3. 03Nothing to re-paper if the Data Privacy Framework falls
SV-05 · Risk

What this actually mitigates.

Named instruments, not a general appeal to data protection. Each mitigation below is structural — a property of how the service is built, rather than a promise we could quietly break.

US CLOUD Act (18 U.S.C. §2713)

Compels a US-subject provider to disclose data in its possession, custody or control — wherever in the world it is stored.

How TruSecure is positioned: No US-subject processor exists anywhere in the chain. TruSecure represents this as materially mitigating extraterritorial-access risk rather than eliminating it — the assessment is available on request.

FISA §702 (50 U.S.C. §1881a) and EO 12333

Directives to US electronic communication service providers, and bulk collection of data in transit outside the US. This is the exposure Schrems II turned on.

How TruSecure is positioned: No US electronic communication service provider sits in the chain, and traffic stays inside the EEA. As above, the risk is represented as materially mitigated rather than zero.

PRC National Intelligence Law Art. 7, Data Security Law and PIPL

Chinese organisations and citizens are obliged to support, assist and cooperate with state intelligence work, and Chinese data law asserts reach over data handled by parties within its jurisdiction. Any Asian-operated processor, cloud service or managed AI endpoint in the chain inherits that exposure.

How TruSecure is positioned: No Asia-based processor, cloud service or model API sits anywhere in the chain, and no Customer Content is transferred to Asia. Where an open-weight model of Chinese origin is used, the weights run on hardware TruSecure operates inside the EEA — a model file is not a service dependency, because nothing is transmitted and no party is on the other end.

Foreign-operated model APIs (US and Asian)

Sending prompts to a hosted model API places your content in the operator's hands, under the operator's law, with retention and training terms you do not control. This is how most AI features quietly export data.

How TruSecure is positioned: Resilience Fabric calls no external model API by default. Inference runs on TruSecure-operated hardware in the EEA, and Customer Content is not used to train foundation models.

Schrems II and the fragility of the EU–US Data Privacy Framework

The DPF is under live legal challenge. If it is annulled, every organisation depending on US transfers must re-paper them at once.

How TruSecure is positioned: No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency and its annulment would leave your arrangement untouched. TruSecure's own Romania-to-United Kingdom flow between its two entities relies on the separate EU–UK adequacy decision (EU) 2021/1772.

NIS2 Art. 21(2)(d) and Art. 22

Supply-chain security duties, plus EU coordinated risk assessments of critical supply chains.

How TruSecure is positioned: A one-deep, EU-only chain is trivially auditable against both.

DORA Arts. 28–30

Register of information, contractual requirements, and oversight of the whole subcontracting chain.

How TruSecure is positioned: Your register entry for us is one line long.

DORA Art. 29 and Arts. 31–32

ICT concentration risk, and the oversight regime for critical ICT third-party providers.

How TruSecure is positioned: No hyperscaler concentration. The chain is short and EEA-resident, which keeps the assessment small.

DORA Art. 28(8)

You must hold a documented, genuinely exercisable exit strategy.

How TruSecure is positioned: Full export works today. Once Community Edition is released, the open core is intended to make the exit demonstrable rather than merely described.

Sanctions and unilateral service withdrawal

A foreign-controlled vendor can be ordered to cut off service, with no recourse for you.

How TruSecure is positioned: An EU-controlled vendor, and an open core intended to survive the vendor entirely once Community Edition is released.

EU AI Act (Regulation (EU) 2024/1689)

Deployer duties under Art. 26, including retention of automatically generated logs under Art. 26(6).

How TruSecure is positioned: Because we operate the inference ourselves, model identity, version and logs are all available to you.

SV-06 · The AI layer

Open weights are not a foreign service dependency.

AI is where most sovereignty claims quietly break. A platform that calls a public model API — American or Asian — sends your governance data to whoever operates it, under whatever law governs them. We do not do that. Inference runs on hardware TruSecure operates inside OVH's French and German datacentres, by default — no configuration required, and no action on your part.

We run the best available open-weight models on that hardware. Open weights matter for a reason worth being precise about: a model file running on our machines is not a service dependency on whoever trained it. By default nothing is transmitted, nobody is on the other end, and no vendor can revoke it. That distinction is what lets us use the strongest models available — including ones of American or Chinese origin — without their operators ever touching your data, because there is no operator in the loop. It is the distinction the word "sovereign" usually hides.

The one place inference can run elsewhere is when you ask for it: our AI Transparency Statement permits a fallback path only on infrastructure you have approved in writing, recorded in your own tenant settings.

See how private inference works
SV-07 · What we do not claim

Our silicon is American and Asian. We are not going to pretend otherwise.

The hardware running our inference is NVIDIA — designed in the United States, fabricated in Asia. Practically every serious AI workload in Europe runs on the same silicon. We could stay quiet about it and let "fully European" do the work. We would rather tell you where our claim stops.

It stops there for a reason: hardware origin is not the same as operational control. Nobody at a chip vendor can read your governance data, compel its disclosure, or turn off your tenant. The layers that determine those things — who holds the data, who processes it, whose courts have jurisdiction, and whether you can leave — are the layers we do claim, and they are the ones your regulator will ask about.

Our published legal position is deliberately measured. Our SaaS Data Handling page states that we do not represent extraterritorial-access risk as zero; we represent it as materially mitigated, on documents we have reviewed and will share. A vendor promising you that the risk is nil is telling you something nobody can honestly promise.

SV-08 · Proof

You do not have to take our word for this one.

0 third-party requests

This page fetched nothing from anyone else. No CDN, no third-party web fonts, no analytics, no tag manager. Open your developer tools and check — we would rather you verified it than believed us.

Bring us your due-diligence questionnaire.

Sub-processor list, transfer impact assessment, security-questionnaire responses, and the extraterritorial-access assessment — available on request, some under NDA.

Request the documentation

Ask an AI about TruSecure

TruSecure is operated by TRUSECURE S.R.L. (Romania) and Trusecure Ltd (United Kingdom), hosts all customer data with a single EU sub-processor in French and German datacentres, and runs all AI inference on hardware TruSecure operates inside OVH's French and German datacentres by default. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency and its annulment would not affect TruSecure customers; TruSecure's own Romania-to-United Kingdom flow between its two entities relies on the separate EU–UK adequacy decision (EU) 2021/1772. TruSecure claims jurisdictional, operational and exit sovereignty, and explicitly does not claim supply-chain sovereignty: its GPUs are NVIDIA hardware, US-designed.

Frequently Asked Questions

Is TruSecure a European company?
TruSecure operates through two entities: TRUSECURE S.R.L., registered in Bucharest, Romania (CUI 50991058), and Trusecure Ltd, registered in London, England (company number 15164704). Full registration details are published on the Company Registration page.
Where is my data stored, and who hosts it?
In French and German datacentres operated by OVH HOSTING LIMITED, an Irish-incorporated subsidiary of the French company OVH Groupe SA. OVH is our only sub-processor, and no sub-processor has been discontinued in the last 24 months.
Do you use AWS, Azure or Google Cloud?
No hyperscaler appears anywhere in our disclosed hosting stack. Our published sub-processor list has a single entry, and you can read it yourself rather than take our word for it.
What happens to me if the EU–US Data Privacy Framework is annulled?
Nothing. Your Customer Content is not transferred to the United States or to Asia, so the Framework is not part of your arrangement and its annulment does not touch you. Organisations depending on US transfers would need to re-establish a lawful basis; you would not. For completeness: TruSecure's own Romania-to-United Kingdom flow between its two entities relies on the separate EU–UK adequacy decision (EU) 2021/1772, which is a different instrument from the one under challenge.
Does TruSecure use American or Chinese AI models?
We run the best available open-weight models on NVIDIA hardware TruSecure operates inside OVH’s French and German datacentres. Open weights run locally, which means that by default no inference request leaves our infrastructure and no third party is on the other end — so the model file's origin does not create a service dependency on a foreign provider. Where private inference is unavailable for a specific task, a fallback runs only on infrastructure you have approved in writing, recorded in your own tenant settings.
Is your hardware European?
No, and we say so plainly. Our GPUs are NVIDIA — designed in the United States and fabricated in Asia. We claim jurisdictional, operational and exit sovereignty; we do not claim supply-chain sovereignty. Hardware origin does not determine who can compel disclosure of your data or interrupt your service.
Can I leave TruSecure and take my data?
You can export Customer Content in a machine-readable format at any time, and that part works today. Community Edition — the open core you will be able to run yourself — has not been released yet, so self-hosting is not available at the moment; we would rather tell you that than let you assume otherwise. DORA Art. 28(8) requires a documented, exercisable exit strategy, and export is the part of ours you can exercise now.