AI Hosting & Data Sovereignty
Use AI. Protect data. Keep control.
AI should move companies forward. Where data is processed and who can access it has to match the requirements. Conventic covers the full range: from cloud AI to AI running inside the company.
Local knowledge search
- For mid-sized and large companies
- Security and data sovereignty from the outset
The hosting map
From AI services to an in-house AI infrastructure.
Conventic covers the full range. The approaches show different ways of shaping data processing and operations independently.
1AI services
Use models through an interface. Data processing and retention follow the provider and the service.
2EU cloud (US provider)
Data held in the EU with US corporate providers. Possible US legal access remains a factor.
3European cloud
Choose European infrastructure. The operator chain, access rights and actual data flows remain decisive.
4Dedicated in Germany
Reserved computing capacity at a German hosting partner. Access and operations are governed deliberately.
4.5Hybrid (4 + 5)
Combine local AI with dedicated capacity in Germany. External processing only after explicit release.
5On-premise
Run AI on own infrastructure. Fully local processing requires an overall architecture designed for it.
More data sovereignty. More control over data security.
The illustration shows scope for design decisions, not measured or certified security levels. Actual data security depends on architecture and operations. Hybrid combines 4 and 5 and is not an additional security level.
An EU data centre does not automatically protect against US legal access. What matters is legal jurisdiction and control over the data. Understanding the US CLOUD Act
Five ways to run AI. The right fit, compared.
The approaches differ in where data is processed, how much control remains and how much operational effort they require. An overview for well-founded decisions.
Select hosting approach
AI runs inside the company.
With operations designed to be fully local, models, documents and processing stay on the company’s own infrastructure.
- Where is data processed?
- On site at the company or in its own data centre.
- What control remains?
- Hardware, models, access and network connections remain under the company’s own control.
- Legal access & residual risk
- Purely local operation without external provider access reduces the route by which data could be handed over through cloud providers. It does not create general immunity from lawful access.
- Suits
- Companies whose sensitive data should not leave their own environment.
- What needs weighing up?
- Hardware, updates, resilience and support have to be planned and operated.
Local knowledge search
On-premise AI: With operations designed to be fully local, models, documents and processing stay on the company’s own infrastructure.
Location alone does not determine security or data sovereignty. Access rights, contracts and the actual data flow always belong in the picture.
US CLOUD Act
EU data centre. US provider. A risk remains.
A European storage location does not automatically protect against US disclosure orders. For sensitive company data, who has legal and technical access matters just as much.
US law can reach beyond the location.
The CLOUD Act makes clear that covered providers under US jurisdiction can be required by lawful orders to disclose data in their possession, custody or control, including outside the United States. This is not blanket, suspicionless authority access.
The GDPR continues to apply.
A foreign order alone is not a sufficient basis for a transfer. A legal basis under Article 6 and the conditions of Chapter V of the GDPR remain necessary. Conflicting obligations are possible; region and contract alone do not resolve that conflict.
The architecture is part of the answer.
The operator chain, access rights, key management and processing in the clear have to be examined. Purely local AI without external provider access reduces the disclosure route through cloud providers, but does not create general immunity.
Conventic takes these risks into account when selecting and designing the AI environment.
Zero Data Retention: less storage, clear limits.
Zero Data Retention (ZDR) limits how long inputs and responses are kept at the model service. The data is still processed there. Scope and exceptions depend on provider, model, feature and agreement.
No training does not mean no storage.
With the OpenAI API, content is not used for model training by default. Even so, logs for abuse detection or data from individual features may be stored. ZDR is an additional arrangement.
ZDR applies to released usage.
OpenAI and Anthropic tie ZDR to a release and to specific conditions. Not every model and every feature is covered; security and statutory exceptions have to be examined. A company’s own application logs, chat histories and connected services need separate retention rules.
Less stored data, not the end of all risk.
ZDR can reduce the data later available at the provider. Processing remains external; legal jurisdiction and possible lawful access do not disappear automatically. For particularly sensitive data, fully local processing remains a separate architectural decision.
Data sovereignty is more than a location.
Three questions show how much control over the AI stays with the company.
Where is data processed?
We look at the whole of the processing: model, documents, logs and backups. What matters is where the data actually ends up.
Who operates the AI?
Providers, subprocessors and contracts shape which dependencies arise and which rules apply.
Who may access what?
Access for staff, administration and support has to be clearly governed. Equally important: who may read, change and delete data.
On-premise AI
Confidential data. A dedicated AI environment.
Analysing internal documents, making knowledge findable, supporting staff: sensitive content does not automatically have to go to an external model service for that. We design AI environments so that processing can take place locally.
Data stays in the company’s own environment.
Documents, search index and model are planned together for local operation.
Access follows clear rules.
Permissions determine who may use which information.
Outbound connections remain controllable.
External interfaces are released deliberately. Depending on the architecture, isolated operation is possible.
Model and hardware match the task.
We choose the environment to fit the use cases and requirements.
Secure operation takes more than a local server: we account for permissions, updates, logging, backups and clear responsibilities. Which tasks Conventic takes on is agreed to fit the environment.
Work locally. Use external capacity deliberately.
On-premise AI is combined with dedicated computing capacity in Germany. Clear rules determine which data and tasks stay local and which may be processed externally.
Two environments increase coordination effort. Hybrid is a combination, not an additional security level.
On-premise AI
Processing in the company’s own environment.
Dedicated GPU in DE
External capacity for released processing.
Data flows according to defined release rules
A clear decision. A traceable path.
Which data may the AI see? How much control is needed? How should operations look? The requirements determine the path.
Understand the requirements
We clarify use cases, data, interfaces and the requirements set by IT.
Compare architectures
The result is a recommendation covering data flows, responsibilities and the relevant trade-offs.
Try it with real tasks
We test the solution against agreed use cases and released data.
Go live in a controlled way
We plan rollout, support and further development together with those responsible.
What companies want to know.
Is “no model training” the same as Zero Data Retention?
No. Forgoing model training governs what content is used for. Zero Data Retention governs retention for certain API usage. Even without training, security logs or stored chat histories may exist. Usage, storage and deletion therefore have to be examined separately.
Does Zero Data Retention make cloud AI as sovereign as on-premise?
No. ZDR can limit retention at the model service, but it does not move processing into the company. Provider access, legal jurisdiction and exceptions remain relevant. The specific models and features in use also have to be released for ZDR. A company’s own application logs and further services are not automatically covered.
Does the US CLOUD Act override the GDPR?
No. The GDPR remains applicable. At the same time, providers under US jurisdiction can be required to disclose data under their control, including in EU data centres. Such an order alone is not a sufficient basis for a transfer under the GDPR. Conflicting obligations can arise as a result. For companies, what matters alongside the location is therefore which provider actually has access to data.
Is on-premise AI automatically secure?
No. Local operation allows direct influence over data and infrastructure. Security comes from the specific implementation: permissions, network separation, maintained software and reliable operations.
Does an EU data centre already mean full data sovereignty?
The data location is an important part. The operator, contractual arrangements, possible access and connected services matter just as much. We look at these points together rather than checking the country label alone.
Can a local AI work without internet access?
With a suitable architecture, models and knowledge search can work locally without a permanent internet connection. External functions, updates and maintenance have to be planned separately for that.
Do we have to commit to one approach permanently?
No. A stepwise start and later extensions can be provided for. On-premise AI and dedicated computing capacity in Germany can also be combined. Which data goes where is defined explicitly in the process.
What is this assessment based on?
The overview compares fundamental operating models. For individual services, the provider’s current terms and the specific configuration are what count. That is why we examine data flows, operators, access and contractual arrangements before making a selection. The linked primary sources help with the assessment.
The right AI environment starts with a conversation.
We examine which architecture fits the company’s goals, its data and its IT. Explained in plain terms, with a clear next step.


