Security Data Sovereignty and Residency
Confidentiality and residency of log and event data
Log and event data is among the most sensitive information an organization holds, so ClearSkies iISOC keeps it confidential by design: stored only in its region of origin, encrypted end to end, reachable only by authorized personnel, and backed by a documented plan for the unlikely event of a breach.
In-region
Data residency by design
Encrypted
In transit and at rest
Least-privilege
Access, fully audited
Why Security Telemetry Requires Data Sovereignty
Security telemetry is uniquely sensitive. Logs and events reveal the structure of a network, the identities of its users and how they behave, the software and versions in use, and the exact signals the defenses generate. That is the same information an attacker would need to plan an intrusion, which is why protecting it is a security control rather than a compliance formality.
Confidentiality
The data is protected by layered technical and organizational controls, and only authorized personnel can reach it.
See the controls →Sovereignty
The data stays within its region of origin, governed by the regulations that apply to the customer's jurisdiction.
See the region model →Accountability
If an incident occurs, a documented and phased response is followed, and affected customers are notified within the timelines their contract and the applicable regulations require.
See the response plan →The platform is built on a sovereign, offline-AI architecture with integrity-protected collection at the edge. Confidentiality is enforced by the architecture rather than promised in a policy.
Where the Data Lives, and Where the AI Runs
Storage and processing are delivered on a regional, onshore basis, which means the data stays in its part of the world rather than being shipped elsewhere for storage or analysis. The difference that matters concerns where the generative and agentic models do their processing.
| Region | Data residency | AI processing |
|---|---|---|
| Europe and the Middle East | In-region data centers | In-region, on locally hosted models |
| North America | Regional cloud, in-region | Performed in Europe |
| South America | Regional cloud, in-region | Performed in Europe |
| Africa | Regional cloud, in-region | Performed in Europe |
| Asia Pacific | Regional cloud, in-region | Performed in Europe |
Protected Before It Leaves You, and at Every Stage After
Confidentiality begins at collection rather than on arrival. Logs and events are gathered through ClearSkies iISOC iCollector, which runs inside the customer's own boundary. Before the data leaves that boundary the collector digitally signs and encrypts it at its original fidelity, capturing each record exactly as generated, with no truncation, downsampling or reformatting that could weaken it as evidence.
Signing gives every record a tamper-evident seal, so what the platform stores and analyzes can be shown to be precisely what the customer's systems produced.

Confidentiality and sovereignty are protected by a layered set of controls. No single measure stands alone, and each reinforces the others.
Approved hosting locations
The data is held only in hosting locations approved for, and sitting within, the appropriate jurisdiction.
Access controls
Access is restricted to authorized personnel on a least-privilege basis, governed by contractual and compliance requirements.
Encryption
The data is encrypted in transit, as it moves to and across the platform, and at rest while it is stored.
Continuous monitoring
The platform is itself monitored continuously for anomalous activity around a customer's data.
Retention policies
Clear retention policies govern how long the data is kept and when it is securely disposed of.
Documented procedures
Documented operational procedures ensure every one of these controls is applied consistently.
If an Incident Occurs, the Response Is Already Written
Strong preventive controls make a breach unlikely, and responsible security means being prepared for one anyway. ClearSkies follows a documented incident-response plan structured around seven phases, so the response is fast, consistent and accountable rather than improvised.
ClearSkies notifies affected customers in line with the timelines set out in their contract and the regulations applicable to them, rather than a single global figure.
One Residency Position, Every Component
What differs between components is the kind of data each one collects, and therefore the question a regulated buyer asks about it.
| Component | The residency question it raises |
|---|---|
| iCollector, the Collection Layer | Where collection happens, inside the customer boundary, and what leaves it: signed and encrypted records at original fidelity. |
| TDIR, the Orchestration Layer, and the Centric-AI Fabric | Where correlation and model processing take place, the distinction between the storage layer and the AI processing layer. |
| DNS Shield | Whether internal names leave the customer environment, and where resolution telemetry is held. |
| Attack Surface Monitoring | How credential material found in external exposure intelligence is handled, and the consent position for monitoring assets and third parties. |
| Endpoint Threat Monitoring and Response | Per-region storage of endpoint telemetry, retention, and the consent position for contractor and third-party devices. |
| Identity Threat Protection | Where identity and authentication metadata is held. |
| Active Defense and the AI-SecOps Autonomous Analysts | Where decoy interaction records and autonomous case records are held, and how long they are retained. |
Control-level mapping to the frameworks a customer reports against is held by the Regulatory Frameworks core function.
From Data Sovereignty Claims to Verifiable Controls
Sovereignty is where a platform either clears procurement or does not.
| The outcome | What produces it |
|---|---|
| Residency can be evidenced rather than asserted | Approved hosting locations per region, with the AI processing layer stated separately from the storage layer. |
| The data is protected before it leaves the customer boundary | Signing and encryption at the point of collection, at original fidelity. |
| A cross-border transfer is never a surprise | Disclosure to the customer and a recognized contractual mechanism, rather than a silent routing decision. |
| The bad day is planned for, not improvised | A documented seven-phase response, with notification in line with the contract and the applicable regulations. |
| Evidence is available for a supervisor without a special exercise | Documented procedures, audited access and defined retention, applied consistently rather than case by case. |
A platform that promises confidentiality asks to be trusted. A platform that enforces it in the architecture can be checked, which is the difference between an assurance and a control.
