OPENLOCK YOUR KNOWLEDGE. YOUR CHOICE.

Data sovereignty and model-neutral AI, by design.

More useful information. More deliberate control.

Data sovereignty and model-neutral AI start with deliberate control over your business information: the relationships, operating knowledge, and decisions behind your competitive advantage. OpenLock’s approach makes those boundaries part of the foundation.

01 COMPLEMENTARY PRINCIPLES

Control the foundation.
Choose what uses it.

Data sovereignty

Decide where the foundation is deployed, who administers it, who and what may access it, what may leave, and how it is retained, recovered, or removed. Preserve approved business definitions and relationship decisions, with clear exports and transition arrangements.

Agentic sovereignty

Choose approved open-source, open-weight, closed-source, internally developed, or third-party models and agents. The internal model organizing data does not dictate the model serving your users. Each connection still needs compatibility checks and validation.

Customer data ownership, platform licensing, third-party rights, and operating responsibilities are documented separately in the engagement.

02 PROCESSING BOUNDARIES

Private and external processing
are different choices.

WITHIN THE APPROVED BOUNDARY

Private processing

Customer foundationQualified private AI

A qualified private deployment can keep model work inside the defined customer environment. Support access, logs, backups, and recovery must also respect that boundary.

EXPLICITLY PERMITTED DISCLOSURE

Approved external processing

Selected informationExternal provider

A hosted external model receives the information permitted for the task. The transfer, purpose, provider terms, retention, logging, and training arrangements need review.

Model-neutral does not mean every model is automatically approved to receive all your data.

03 DESIGN REQUIREMENTS

Make the boundaries visible.

01

Customer separation

Keep customer information and configuration within the approved environment.

02

Permissions before retrieval

Check access before restricted information becomes model context, including joined records and derived answers.

03

Protected operations

Define storage protection, credentials, support access, administration, and key responsibilities.

04

Reviewable changes

Validate consequential mappings and preserve evidence of approved decisions. Business content is data, not authority to change access or execute transactions.

05

Retention & recovery

Address source copies, derived records, indexes, logs, and backups in the operating policies.

These are requirements to implement and test. No certification or guaranteed compliance outcome is implied.

04 DEPLOYMENT DIRECTION

Your environment.
An agreed operating model.

CUSTOMER CLOUD

Your cloud account

An approved customer environment, with region, access, control, and operating responsibilities agreed with your team.

PRIVATE HOSTING

Dedicated infrastructure

A separately governed hosting arrangement operated with your authorization and defined administration and disclosure boundaries.

ON PREMISES

Qualified local deployment

Infrastructure where hardware, model runtime, storage, support access, and recovery have been qualified for the workload.

05 CONTROL QUESTIONS

Choice with clear boundaries.

Can we use a closed-source model?

Yes, within the intended model-neutral approach, subject to approval and compatibility. Hosted external processing sends selected information to that provider, so data handling and permitted disclosure must be reviewed.

Can processing remain private?

That is an intended option in a qualified private deployment. The environment, model runtime, support access, logs, backups, and recovery design must respect the agreed boundary.

Can the system change production records on its own?

The starting approach is approved, read-only ingestion. Transactional actions and source-system write-back require separate authorization, workflow design, and testing.

What does the customer retain?

The objective is customer control of data and approved business meaning. Specific ownership, exports, administrative access, licensing, third-party rights, and transition responsibilities are documented in the engagement.

NEXT START WITH A REAL QUESTION

Your data remains the asset.

Start with the environment, access rules, and business boundaries that matter to your organization.

Start a conversation