Sovereign by design.
For public bodies, tribunals, and regulated institutions that cannot compromise on where their data lives or who can reach it: your region, your keys, and governed AI inside a single-tenant cluster — up to and including air-gapped.
Real sovereignty, not a checkbox.
The guarantees that distinguish sovereign from “hosted in a nearby region.”
Founder-led, not a US enterprise vendor
LexSteward is built and run by a practising attorney rather than a US-headquartered vendor. Which country’s courts and disclosure laws reach your data depends on where the deployment lives — that is settled per engagement, in writing, not asserted on a web page.
You hold the key
Bring-your-own-KMS: the design is that your encryption key lives in your control, so that we would be technically unable to read your protected content — a design goal, not a shipped configuration today. Delivered by engagement.
Residency, by engagement
Your data region is fixed at signup — in-region storage down to backups is on the roadmap. Sovereign is designed to hold that region through every copy, including backups, and, once Canadian residency ships (not live today), to keep Canadian data in Canada. Delivered by engagement.
No US operator in the path (by engagement)
Designed to be deployed customer-operated with your own keys. Which providers sit in the path, and under whose jurisdiction, is settled by engagement and put in writing. We do not make blanket jurisdictional promises on a web page.
AI in your environment (by engagement)
Sovereign is designed to run governed AI within your own environment, so protected content is processed there rather than by a shared service. Delivered by engagement; not a shipped configuration today.
What real sovereignty requires.
We’re specific about this on purpose. Sovereignty is a property of how a deployment is operated and who holds the keys — not of a hardware brand or a Canadian postal code. It holds when all of these are true:
“Sovereign” means outside US reach — Canadian lawful access and PIPEDA still apply, and it isn’t immunity from all government. We map every claim to your specific deployment and confirm it with counsel before we make it. Residency on our standard cloud tiers keeps your data in-region, but sovereignty in this full sense is the dedicated, customer-operated deployment described here.
Deploy it where your rules require.
The same platform, in the posture your mandate demands.
Sovereign, on-prem, and air-gapped deployments are delivered with our infrastructure partners and scoped per engagement. Timelines and available certifications are confirmed during procurement.
Assurance & procurement.
Compliance, honestly stated
SOC 2 and sector frameworks (HIPAA / PIPEDA as relevant) are on our roadmap. We will never claim a certification we haven’t earned.
Provable confidentiality
The confidentiality report — routing metadata, model used, opt-in log and a signed boundary assertion for any matter — is in preview and not switched on yet. The audit log underneath it is live.
Audit everywhere
Comprehensive audit trails across access, actions, and AI routing — the evidence public-sector oversight requires.
Enterprise SLAs & support
Tiered support and service levels, backed by our infrastructure partners, sized to your obligations.
Built for procurement. Per-seat or per-node licensing, contracting through our infrastructure partners where required, and enterprise SLAs — the terms public-sector and regulated buyers expect.
Start a sovereign scoping conversation.
Tell us your residency, security, and procurement requirements. We’ll design a deployment that meets them — and be candid about what’s available today versus on the roadmap.