We do not offer you a definition of sovereignty to agree with. We look at whether a specific set of practices is in place, and whether there is evidence that they are:
- No-train and no-retention terms — contractual limits on what a provider may do with your prompts, uploads, and outputs.
- Redaction at the model boundary — personal and confidential data detected and masked by a control, not by an instruction in a policy document.
- A call-level audit trail — a record of what was sent, what came back, how long it is kept, and who can review it.
- Key management — control of the encryption keys that ultimately decide who can read your data.
- Exit and portability — the ability to retrieve your data on the way out, and to have the provider's copy deleted.
Where processing happens, and under which jurisdiction, is one recorded and rationalized factor in a data-handling decision. It is a real factor. It is not the whole question, and treating it as the whole question is how organizations end up confident and exposed at the same time.