:: Sovereign Vault

Sovereign retention,
immutable and auditable
for the age of AI.

Your models, datasets and regulatory evidence — under your physical control, in your territory, ready for inspection. Sovereign cloud in your territory with proven immutability — and a dedicated physical, air-gapped golden copy as the last line of defence. Delivered as a managed service by heimr.

WORM
provable immutability
Physical air-gap
dedicated golden copy
RTO
contracted and tested
:: The evidence liability

Every regulated organisation carries a growing retention liability.

AI has created a new class of evidence: model versions, training datasets, model cards, decision logs. Retaining, indexing and proving them is an obligation — not an option.

Legal obligation.

Retain and prove.

PRA, FCA, DORA, GDPR, BACEN, CVM. Regulators require you to prove, years later, which model decided, on what data and when — with no tamperable trail.

Sovereignty.

Data that cannot leave the country.

Sensitive information that cannot — legally or strategically — live outside your national territory. Foreign cloud removes that data from your control and your jurisdiction.

Ransomware.

Last line of defence.

A genuinely offline, immutable copy is virtually impossible to reproduce online. Physical air-gap is not a luxury: it is what remains when everything else fails.

“We do not sell cheap storage. We sell the ability to survive a regulatory inspection without panic.”

:: Portfolio

One platform.
Three offers.

All three offers share the same custody foundation and combine as your needs evolve — start where the pressure is greatest and expand without changing provider.

Cyber Recovery Vault

Air-gapped golden copy with recovery drills tested and documented every cycle.

  • Genuinely offline, immutable copy
  • Periodic drills with documented evidence
  • Last line against ransomware and corruption
For when ransomware is your primary threat.

Regulatory Vault

Auditable immutable retention with cryptographic attestation and chain of custody, mapped to sector requirements.

  • WORM + signable attestation for the auditor
  • Searchable catalogue with mapped policies
  • MRM Evidence Vault tier for models and datasets
For when the regulator will demand proof.

Sovereign Archive

Long-term cold archiving with guaranteed physical sovereignty and contracted RTO, on national territory.

  • Data retained for years, in your country
  • Fixed RTO, no variable egress invoice
  • Managed media cycle and monitoring
For when data cannot cross the border.
:: Service tiers

From storing to proving.

Subscription by protected capacity and governance tier. Onboarding includes data classification and retention-policy design.

Custody

Managed capacity.

  • Managed WORM capacity
  • Media cycle & monitoring
  • Ingestion SLA
  • Periodic reporting

Sovereign+

Inspection-ready.

  • Everything in Assurance
  • Tested recovery drills
  • Evidence documented every cycle
  • Alignment with MRM frameworks
  • Regulatory inspection support
:: How offers and tiers combine

Choose the offer by the use case.
Choose the tier by the level of proof.

The three offers are use cases — what you need to retain and why. The three tiers are governance levels — how far you go in proving it. Each offer is delivered in one of the three tiers.

Offer \ TierCustodyAssuranceSovereign+
Cyber Recovery Vault
Available
Recommended
Typical delivery
Regulatory Vault
Available
Typical delivery
Recommended
Sovereign Archive
Typical delivery
Available
Available
Typical delivery
Recommended
Available
:: Target sectors

Sectors where sovereignty is not optional.

Vertical
Needs
Offer
Financial services
PRA/FCA/BACEN retention, audit trail, desk communications, KYC/AML
Regulatory Vault (MRM tier)
Healthcare
Patient records (long retention), DICOM imaging, sovereign handling of sensitive data
Sovereign Archive + Regulatory Vault
Legal / Compliance
Legal hold, evidence preservation, chain of custody
Regulatory Vault
Public sector / Judiciary
Sovereignty as a legal requirement, archives, case-file retention
Sovereign Archive
Cyber-resilience (horizontal)
Immutable golden copy against ransomware — any regulated sector
Cyber Recovery Vault
:: Why heimr, not the cloud

The public cloud does not sell physical sovereignty, genuine air-gap or managed immutability proof.

Dimension
Self-managed public cloud
heimr Sovereign Vault
Physical sovereignty
Outside your control
Sovereign region + physical copy in territory
Genuine air-gap
Logical only
Physical, via dedicated golden copy
Recovery cost
Variable + egress
Fixed, contracted RTO
MRM attestation
Not native
Included
Chain of custody
Manual
Managed
:: Qualification check

Is the vault for you?

Four honest questions. If the answer to any is no, the vault is probably not the right fit for you — and we say so before you spend time on it.

“If the data goes into a GPU or answers a query, it is not for the vault. If it is large, cold, must last for years and requires air-gap or regulatory proof — it is exactly the case.”

  1. 01

    Is there a regulatory or sovereignty reason that PREVENTS using public cloud?

  2. 02

    Is the data cold (rarely accessed) and long-retained (years)?

  3. 03

    Do you value immutability proof and chain of custody — not just storage?

  4. 04

    Significant volume (typically hundreds of TB to multiple PB) and willingness to enter long-term contracts?

:: 30-minute conversation

We map your retention liability and design the vault to fit.

You leave the conversation with a clear diagnosis: what must be retained, for how long, under which framework — and the vault design that meets the obligation without waste.

On submission, your request is routed to the commercial team at [email protected].

Talk to us
Explore our solutions

LONDON

LEVEL39, One Canada Square, Canary Wharf, 39th floor
London, E14 5AB
UNITED KINGDOM

SAO PAULO

WTC, Av. das Nações Unidas, 12551, 24o andar
Brooklin, São Paulo
BRAZIL