SEAL-4
Transparent. Under EU law. Ownable.
SEAL-4 requires full EU control over technology and operations, subject to EU law, with no critical non-EU dependency in the path that creates, isolates, encrypts or recovers a tenant.
Foundix applies the same test to every component: does this create a critical non-EU dependency? Can EU operators fully own and evolve it? Are keys customer-controlled? Is the chain auditable? Is there an exit?
Where pure SEAL-4 is currently impractical
Some firmware, CPU microcode, optional GPU drivers and upstream security feeds originate outside the EU. That is residual risk. Compensation: pin and verify artifacts, minimise runtime contact, document the chain, keep a replacement path. Foundix does not hide this behind ‘100% sovereign’.
Exit statement
The foundation is open. Configuration is documentable. Backups are independently restorable. Products (SOVNC, SOVGO, SovTooling, Cloud Spawn) must not trap you in a closed control plane. When you leave, you take the stack — not only an export file.