Exfiltration is architecturally impossible.
The sovereign foundation every other Regnant system runs on. No data, query, weight, or result ever crosses the institution's perimeter. Enforced at hardware, firmware, OS, and application level, from a hardware root of trust to a client-verifiable, Merkle-chained audit log.
- TPM 2.0 attestation and Secure Boot: containment enforced in hardware, not policy
- AMD SEV-SNP, Intel SGX v2, or ARM TrustZone: inference runs in memory no operator can inspect
- AES-256-GCM weights under a key hierarchy the institution alone holds. The vendor cannot decrypt
- Ed25519-signed Merkle audit chain, verifiable by the client with no internet connection
“Our AI cannot touch the public cloud. What do we run?”
