Skip to main content

Documentation Index

Fetch the complete documentation index at: https://docs.rootkey.ai/llms.txt

Use this file to discover all available pages before exploring further.

This is the highest-sovereignty variant of RKP-2 (Off-Chain). Unlike RKP-2 Enhanced EU, which uses OVH-hosted infrastructure, RKP-2 Sovereign EU runs entirely within the customer’s own on-premise EU environment - with optional EBSI anchoring for audit-grade proofs.

Sovereignty Profile

ComponentProviderJurisdictionNotes
Off-chain storageCustomer on-premiseCustomer EU facilityData never leaves the organisation’s infrastructure
API processingCustomer on-premiseCustomer EU facilityROOTKey deployed as a containerised workload
Blockchain (optional)EBSIEUSelective elevation of critical records to EBSI for audit-grade proofs
Sovereignty levelFull EU - Air-gapped capable100% customer infrastructureMaximum data control; no dependency on ROOTKey cloud
When to choose this variant: Your organisation cannot allow operational data to leave its own infrastructure perimeter - whether for national security, sector regulation, or contractual reasons - while still needing cryptographic integrity verification for audit and compliance purposes.

How It Differs Across the RKP-2 Variants

PropertyRKP-2 StandardRKP-2 Enhanced EURKP-2 Sovereign EU
Cloud providerAzure / AWSOVHNone - on-premise
Data leaves organisationYesYes (to OVH)No
API processing locationROOTKey cloudROOTKey OVHCustomer infrastructure
BlockchainNoneNoneEBSI (optional, selective)
Full sovereigntyNoCloud sovereignYes - air-gap capable
Deployment modelSaaSSaaS on OVHContainer / On-Premise
AvailabilityStandardContact teamContact team

Architecture


Selective EBSI Anchoring

RKP-2 Sovereign EU processes high-frequency data entirely on-premise. For records that require the highest level of audit defensibility - regulatory measurements, safety events, incident records, threshold breaches - the on-premise ROOTKey deployment can selectively elevate those records to EBSI:
Record typeRecommended anchoring
Routine sensor readingsOff-chain only (on-premise)
Threshold breach eventsSelective EBSI anchor
Alarm and safety eventsSelective EBSI anchor
Regulatory measurement recordsSelective EBSI anchor
Incident recordsSelective EBSI anchor
This pattern preserves throughput and cost efficiency for bulk telemetry while ensuring that the records most likely to face regulatory scrutiny have the highest possible evidentiary standing.

Regulatory Frameworks Addressed

FrameworkHow RKP-2 Sovereign EU helps
NIS2 - Critical Infrastructure (highest tier)On-premise deployment satisfies national sovereignty requirements where cloud infrastructure (even EU) is restricted
IEC 62443 - SL 3/SL 4Highest Security Level data integrity for IACS environments with strict perimeter requirements
EU Energy (classified measurements)Regulatory measurement data never leaves the operator’s infrastructure
Defence-adjacent OTOT integrity anchoring without any external data dependency
Air-gapped environmentsEBSI anchoring can be configured for batched outbound-only connectivity - no inbound connection required
Healthcare (on-premise ICU/operating)Patient monitoring data stays within hospital infrastructure

Deployment Requirements

RKP-2 Sovereign EU is deployed as a containerised workload within the customer’s infrastructure:
  • Docker or Kubernetes environment on customer-controlled EU infrastructure
  • MQTT broker accessible within the customer network
  • Optional outbound HTTPS connection to EBSI for selective anchoring (no inbound required)
  • Customer-managed storage for off-chain records
Container Deployment Guide · On-Premise Deployment

Availability

RKP-2 Sovereign EU is available on request. Deployment involves a sizing assessment, container configuration, and optionally a EBSI node or gateway configuration for selective anchoring. Request RKP-2 Sovereign EU deployment