:: Sovereign Vault

Sovereign retention,
immutable and auditable
for the age of AI.

Your models, datasets and regulatory evidence — under your physical control, in your territory, ready for inspection. Sovereign cloud in your territory with proven immutability — and a dedicated physical, air-gapped golden copy as the last line of defence. Delivered as a managed service by heimr.

WORM
provable immutability
Physical air-gap
dedicated golden copy
RTO
contracted and tested
:: The evidence liability

Every regulated organisation carries a growing retention liability.

AI has created a new class of evidence: model versions, training datasets, model cards, decision logs. Retaining, indexing and proving them is an obligation — not an option.

Legal obligation.

Retain and prove.

PRA, FCA, DORA, GDPR, BACEN, CVM. Regulators require you to prove, years later, which model decided, on what data and when — with no tamperable trail.

Sovereignty.

Data that cannot leave the country.

Sensitive information that cannot — legally or strategically — live outside your national territory. Foreign cloud removes that data from your control and your jurisdiction.

Ransomware.

Last line of defence.

A genuinely offline, immutable copy is virtually impossible to reproduce online. Physical air-gap is not a luxury: it is what remains when everything else fails.

“We do not sell cheap storage. We sell the ability to survive a regulatory inspection without panic.”

:: Portfolio

One platform.
Three offers.

All three offers share the same custody foundation and combine as your needs evolve — start where the pressure is greatest and expand without changing provider.

Cyber Recovery Vault

Air-gapped golden copy with recovery drills tested and documented every cycle.

  • Genuinely offline, immutable copy
  • Periodic drills with documented evidence
  • Last line against ransomware and corruption
For when ransomware is your primary threat.

Regulatory Vault

Auditable immutable retention with cryptographic attestation and chain of custody, mapped to sector requirements.

  • WORM + signable attestation for the auditor
  • Searchable catalogue with mapped policies
  • MRM Evidence Vault tier for models and datasets
For when the regulator will demand proof.

Sovereign Archive

Long-term cold archiving with guaranteed physical sovereignty and contracted RTO, on national territory.

  • Data retained for years, in your country
  • Fixed RTO, no variable egress invoice
  • Managed media cycle and monitoring
For when data cannot cross the border.
:: Service tiers

From storing to proving.

Subscription by protected capacity and governance tier. Onboarding includes data classification and retention-policy design.

Custody

Managed capacity.

  • Managed WORM capacity
  • Media cycle & monitoring
  • Ingestion SLA
  • Periodic reporting
Recommended

Assurance

Auditable proof.

  • Everything in Custody
  • Signable immutability attestation
  • Searchable catalogue
  • Mapped retention policies
  • Contracted RTO

Sovereign+

Inspection-ready.

  • Everything in Assurance
  • Tested recovery drills
  • Evidence documented every cycle
  • Alignment with MRM frameworks
  • Regulatory inspection support
:: How offers and tiers combine

Choose the offer by the use case.
Choose the tier by the level of proof.

The three offers are use cases — what you need to retain and why. The three tiers are governance levels — how far you go in proving it. Each offer is delivered in one of the three tiers.

Offer \ TierCustodyAssuranceSovereign+
Cyber Recovery Vault
Available
Recommended
Typical delivery
Regulatory Vault
Available
Typical delivery
Recommended
Sovereign Archive
Typical delivery
Available
Available
Typical delivery
Recommended
Available
:: Target sectors

Sectors where sovereignty is not optional.

Financial services
PRA/FCA/BACEN retention, audit trail, desk communications, KYC/AML
Regulatory Vault (MRM tier)
Healthcare
Patient records (long retention), DICOM imaging, sovereign handling of sensitive data
Sovereign Archive + Regulatory Vault
Legal / Compliance
Legal hold, evidence preservation, chain of custody
Regulatory Vault
Public sector / Judiciary
Sovereignty as a legal requirement, archives, case-file retention
Sovereign Archive
Cyber-resilience (horizontal)
Immutable golden copy against ransomware — any regulated sector
Cyber Recovery Vault
:: Why heimr, not the cloud

The public cloud does not sell physical sovereignty, genuine air-gap or managed immutability proof.

Dimension
Self-managed public cloud
heimr Sovereign Vault
Physical sovereignty
Outside your control
Sovereign region + physical copy in territory
Genuine air-gap
Logical only
Physical, via dedicated golden copy
Recovery cost
Variable + egress
Fixed, contracted RTO
MRM attestation
Not native
Included
Chain of custody
Manual
Managed

heimr does not compete on £/TB. We compete where the cloud cannot deliver: regulatory proof, physical sovereignty and jurisdictional control, and guaranteed recovery.

:: Qualification check

Is the vault for you?

Four honest questions. If the answer to any is no, the vault is probably not the right fit for you — and we say so before you spend time on it.

“If the data goes into a GPU or answers a query, it is not for the vault. If it is large, cold, must last for years and requires air-gap or regulatory proof — it is exactly the case.”

  1. 01

    Is there a regulatory or sovereignty reason that PREVENTS using public cloud?

  2. 02

    Is the data cold (rarely accessed) and long-retained (years)?

  3. 03

    Do you value immutability proof and chain of custody — not just storage?

  4. 04

    Significant volume (typically hundreds of TB to multiple PB) and willingness to enter long-term contracts?

:: 30-minute conversation

We map your retention liability and design the vault to fit.

You leave the conversation with a clear diagnosis: what must be retained, for how long, under which framework — and the vault design that meets the obligation without waste.

On submission, your request is routed to the commercial team at sales@heimr.co.