Skip to main content
Sovereignty

Sovereignty isn't a location. It's who holds the keys.

1331's computational reasoning substrate deploys in three postures — Owned, Controlled, Governed. Same substrate, same audit trail, same agent runtime. Pick the posture that matches your regulator, your audit obligation, and your boundary — and move between them when those change.

Private by architecture, not by promise No third-party model provider in the path Move postures without re-pricing
/ Three postures, one control plane

The same substrate runs anywhere your control demands.

/ Audit & Controls

The admin surface every posture ships with.

See the audit & controls surface →
Audit log

Append-only, signed, queryable. Exports to your SIEM in structured formats.

Keys & secrets

BYO-KMS in Controlled / Governed. Hardware-rooted keys in Owned.

Policies

Per-workload routing, retention, redaction, and BYO-key burst rules.

Budgets

Hard caps per workload, per team, per matter — enforced before inference.

/ Compliance Clause Map

The clauses regulated buyers can't get past.

/ The data boundary, drawn explicitly

What lives inside your boundary — and what stays at 1331.

Inside your boundary
  • Reasoning substrate and agent runtime
  • Model weights (open-weight, quantized for your hardware or VPC)
  • Vector stores, embeddings, and RAG indexes
  • Prompts, completions, tool calls, and intermediate state
  • Append-only audit log (signed, queryable, SIEM-exportable)
What stays at 1331
  • License + entitlements
  • Substrate version updates and security patches (signed bundles)
  • Anonymized health telemetry (opt-out in Owned and Governed)
  • Optional support tunnel — off by default, audited when on
  • Nothing else — no prompts, no logs, no training data, ever
Frontier Model Bridge

Burst to GPT-5, Claude, or Gemini — on your terms.

Sovereignty doesn't mean isolation. Any agent can route a single step to a frontier provider when the job genuinely demands it — long-context synthesis, deep multi-step reasoning, vision, or live web grounding — while everything else stays inside your posture. You bring the key, you set the policy, every call lands in the same audit trail as local inference.

OpenAI
GPT-5 / GPT-5 mini

General reasoning, tool use, structured output.

Anthropic
Claude 4.5 Sonnet / Opus

Long context, careful drafting, code review.

Google
Gemini 2.5 Pro

Native multimodal, 2M-token context, grounded search.

Your keys, your contract

BYO API keys with per-provider quotas. We never proxy through 1331 infrastructure.

Policy-driven routing

Per-workload, per-step rules: keep PII local, allow frontier for public synthesis, fall back on failure.

One unified audit trail

Same SDK call, same signed log entry — whether the token came from your appliance or a frontier endpoint.

/ Compliance posture

The frameworks our buyers are audited against.

SOC 2 Type II
In progress — controls map available under NDA
HIPAA
BAAs available on Controlled and Owned postures
GDPR
EU data residency via Controlled; EU rep on request
ISO 27001
Control mappings published; certification roadmap shared with buyers
CMMC / ITAR
Air-gappable Owned deployments for CUI and export-controlled workloads
State privacy laws
CCPA / CPA / VCDPA / NJDPA / TDPSA aligned

Compliance is a function of posture + policy + audit, not a logo. Pick the posture, we'll send the packet.

Request a BriefingHow We Engage